EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Binance warns users: phishing text messages surge

2026-09-04 15:35:33
Bookmark

Binance Warning: SMS phishing attacks against cryptocurrency users surge

On September 3, Binance issued a warning pointing out that a large number of phishing attacks disguised as account security alerts have recently occurred. The exchange emphasizes that it will never ask customers to verify or protect their accounts via SMS links. Users should not reply or enter any account information before using the Binance Verification feature to confirm suspicious communications.

Fraud Methods and Characteristics

According to Binance, fraudsters sent text messages claiming that account settings had been changed or that there was suspicious login activity. These messages often contain shortened malicious links and induce recipients to click to "verify" or "protect" their accounts. Such fraudulent information is designed to mimic official currency security notices, and common excuses include abnormal logins, changes in account settings, or other security issues that need to be addressed immediately.

Although phishing messages often create the illusion of urgency, their core purpose is only one: to trick users into clicking on links without thinking. These links may direct users to websites on counterfeit coin login or account verification pages, stealing passwords, Captcha, or other information needed for access.

Binance said that it has recently observed an increase in phishing attacks against encrypted users, but did not disclose the specific number of users affected or the direct economic losses caused.

Official Recommendations and Security Measures

To prevent such risks, Binance provides the following key recommendations:

  • Don't trust text message links: Binance made it clear that it will never ask customers to verify or protect accounts through SMS links. When receiving unexpected messages, you should directly open the official Binance application or manually enter the exchange website.
  • Use Binance Verification Tool: Before entering account information or contacting so-called customer service, users can use the "Binance Verification" function to check whether the website, email, phone number or social media account belongs to official channels.
  • Take immediate action: If suspicious links have been clicked, you should contact Binance customer service through the official application. Avoid further communication with the sender and strictly prohibit providing passwords, mnemonics or Captcha.

Three controls to strengthen account protection

In addition to increasing vigilance, Binance recommends that users enable the following functions to limit potential losses:

  1. Whitelist of withdrawal addresses: This feature restricts funds from being transferred to wallet addresses pre-approved by the account holder. Even if an attacker obtains login credentials, he cannot transfer funds to unauthorized destinations. Users should properly protect the mailboxes and authentication methods used to approve changes, as these are also potential targets for attackers.
  2. Anti-phishing Code: When is enabled, all legal emails from Binance will contain user-defined personalized codes. If the message lacks the correct code, it may be forged. Although this protection mainly applies to emails rather than ordinary text messages, users are advised to create and update this code through account security settings.
  3. Automated detection system: Binli uses an artificial intelligence system to monitor suspicious behavior during login, transaction and withdrawal processes. It is reported that more than 100 AI models support its anti-fraud controls, significantly reducing the success rate of phishing attacks.

Regulatory background and historical cases

Fraud using text messages to impersonate Binan is not a new phenomenon. In 2023, Hong Kong police reported a case in which 11 users clicked on links in forged messages and threatened that their accounts would be suspended, resulting in losses of approximately US$446,000. In addition, in July 2026, the Securities and Futures Commission of Hong Kong ordered licensed encryption platforms to adopt anti-phishing identity verification methods within 12 months, replacing traditional verification methods based on text messages, emails or application of one-time codes.

This latest warning does not mention specific deadlines, investigations or regulatory actions and still falls within the scope of account security. Users are reminded to independently verify unexpected communications and only contact customer service through official apps or websites after leaking information or clicking suspicious links.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP