Binance Warning: SMS phishing attacks against cryptocurrency users surge
On September 3, Binance issued a warning pointing out that a large number of phishing attacks disguised as account security alerts have recently occurred. The exchange emphasizes that it will never ask customers to verify or protect their accounts via SMS links. Users should not reply or enter any account information before using the Binance Verification feature to confirm suspicious communications.
Fraud Methods and Characteristics
According to Binance, fraudsters sent text messages claiming that account settings had been changed or that there was suspicious login activity. These messages often contain shortened malicious links and induce recipients to click to "verify" or "protect" their accounts. Such fraudulent information is designed to mimic official currency security notices, and common excuses include abnormal logins, changes in account settings, or other security issues that need to be addressed immediately.
Although phishing messages often create the illusion of urgency, their core purpose is only one: to trick users into clicking on links without thinking. These links may direct users to websites on counterfeit coin login or account verification pages, stealing passwords, Captcha, or other information needed for access.
Binance said that it has recently observed an increase in phishing attacks against encrypted users, but did not disclose the specific number of users affected or the direct economic losses caused.
Official Recommendations and Security Measures
To prevent such risks, Binance provides the following key recommendations:
- Don't trust text message links: Binance made it clear that it will never ask customers to verify or protect accounts through SMS links. When receiving unexpected messages, you should directly open the official Binance application or manually enter the exchange website.
- Use Binance Verification Tool: Before entering account information or contacting so-called customer service, users can use the "Binance Verification" function to check whether the website, email, phone number or social media account belongs to official channels.
- Take immediate action: If suspicious links have been clicked, you should contact Binance customer service through the official application. Avoid further communication with the sender and strictly prohibit providing passwords, mnemonics or Captcha.
Three controls to strengthen account protection
In addition to increasing vigilance, Binance recommends that users enable the following functions to limit potential losses:
- Whitelist of withdrawal addresses: This feature restricts funds from being transferred to wallet addresses pre-approved by the account holder. Even if an attacker obtains login credentials, he cannot transfer funds to unauthorized destinations. Users should properly protect the mailboxes and authentication methods used to approve changes, as these are also potential targets for attackers.
- Anti-phishing Code: When is enabled, all legal emails from Binance will contain user-defined personalized codes. If the message lacks the correct code, it may be forged. Although this protection mainly applies to emails rather than ordinary text messages, users are advised to create and update this code through account security settings.
- Automated detection system: Binli uses an artificial intelligence system to monitor suspicious behavior during login, transaction and withdrawal processes. It is reported that more than 100 AI models support its anti-fraud controls, significantly reducing the success rate of phishing attacks.
Regulatory background and historical cases
Fraud using text messages to impersonate Binan is not a new phenomenon. In 2023, Hong Kong police reported a case in which 11 users clicked on links in forged messages and threatened that their accounts would be suspended, resulting in losses of approximately US$446,000. In addition, in July 2026, the Securities and Futures Commission of Hong Kong ordered licensed encryption platforms to adopt anti-phishing identity verification methods within 12 months, replacing traditional verification methods based on text messages, emails or application of one-time codes.
This latest warning does not mention specific deadlines, investigations or regulatory actions and still falls within the scope of account security. Users are reminded to independently verify unexpected communications and only contact customer service through official apps or websites after leaking information or clicking suspicious links.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC