Binance warns users as phishing texts increase

by Trevor Jones
0 comments



Binance warned cryptocurrency users on Sept. 3 about an increase in phishing attacks involving text messages disguised as account security alerts.

Summary

  • Binance warned users about phishing texts disguised as urgent security alerts containing shortened malicious links.
  • The exchange said it never asks customers to verify or secure accounts through text links.
  • Users can check suspicious communications through Binance Verify before responding or entering any account information.
  • Withdrawal address whitelists restrict transfers to destinations approved by account holders before any withdrawal request.
  • Binance disclosed no victim count or financial losses connected specifically to its latest phishing warning.

The exchange said scammers were sending messages claiming that account settings had changed or that suspicious login activity had occurred. The messages include shortened links and direct recipients to “verify” or “secure” their accounts.

Binance did not disclose how many users received the messages. It also provided no figure for losses connected specifically to the latest campaign.

Binance phishing texts create false urgency

The fraudulent messages are designed to resemble official Binance notifications. They commonly warn about an unexpected login, changed account settings or another supposed security issue requiring immediate action.

The links may direct recipients to websites created to imitate Binance’s login or account verification pages. Scammers can then attempt to collect passwords, authentication codes or other information needed to access the victim’s account.

“We’ve recently observed an increase in phishing attacks targeting crypto users,” Binance said, without quantifying the increase.

The warning follows earlier campaigns using the exchange’s name. In 2025, the Australian Federal Police said scammers sent spoofed messages that appeared within existing Binance message threads. As previously reported, those messages falsely claimed that customer accounts had been compromised.

Binance says text links should not be trusted

Binance said it will never ask customers to click a link in a text message to verify or secure an account. Users who receive unexpected messages should instead open the official Binance application or enter the exchange’s address directly.

Customers can also use Binance Verify to check whether a website address, email address, phone number, social media account or other contact belongs to the exchange. Verification should take place before users enter account information or contact anyone presented as customer support.

Anyone who has already followed a suspicious link should contact Binance customer support through the official application. Users should avoid communicating further with the sender or providing passwords, recovery phrases and authentication codes.

Three account controls can limit phishing losses

Binance advised users to enable its withdrawal address whitelist. The feature limits withdrawals to wallet addresses approved by the account holder, creating another barrier if an attacker obtains login credentials.

The exchange published a separate guide explaining how customers can activate and manage the whitelist. Users should secure access to the email account and authentication method used to approve changes because attackers may target those services as well.

Binance also recommended activating its anti-phishing code. Once configured, legitimate Binance emails include a personalized code selected by the user. An email without the correct code may be fraudulent, although customers should still check its sender and destination links.

The protection applies to email rather than ordinary text messages. Binance’s instructions explain how users can create and update the code through their account security settings.

Binance also uses automated systems to detect suspicious behavior during logins, trading and withdrawals. The exchange previously said more than 100 artificial intelligence models support its fraud controls. According to related crypto.news reporting, Binance attributed an eightfold reduction in phishing success rates to those systems.

Platform controls cannot prevent every loss when customers voluntarily provide credentials or approve transfers after receiving deceptive instructions. Withdrawal whitelists, passkeys and application-based authentication can add barriers, but users still need to verify unexpected communications independently. Binance recommends contacting support only through its official application or website, particularly after opening a suspicious link.

Earlier scams show how impersonation causes losses

Binance impersonation through text messages is not new. Hong Kong police said 11 users lost approximately $446,000 in a 2023 campaign after receiving messages that threatened to deactivate their accounts unless they completed verification. The victims followed links contained in fraudulent messages.

In July 2026, Hong Kong’s Securities and Futures Commission ordered licensed crypto platforms and brokers to replace authentication based on SMS, email or app-generated one-time codes. The new standards require phishing-resistant authentication methods within 12 months.

Binance’s latest warning does not identify a deadline, investigation or regulatory action. The campaign remains an account-security matter, with users advised to verify communications and contact official support if they disclosed information or followed a suspicious link.



Source link

You may also like

Latest News

© 2025 blockchainecho.xyz. All rights reserved.