Binance Issues a Critical Scam Warning: Details Inside

Exchange News·6 min read

Binance has issued an urgent warning about rising phishing attacks targeting its users through fraudulent text messages impersonating security alerts, a critical threat for institutional investors managing large positions on the world’s largest crypto exchange. The advisory details three specific technical protections, link verification, withdrawal whitelisting, and anti-phishing codes, that institutional traders and custodians should implement immediately to prevent account compromise and fund loss.

  • Attackers send fake “security alert” SMS messages with shortened links claiming account changes or suspicious login attempts to trigger urgent action.
  • Binance confirmed the exchange will never request verification via text message links; genuine alerts include unique anti-phishing codes in official emails.
  • Three specific defenses, Binance Verify for link authentication, Withdrawal Address Whitelist for fund restrictions, and Anti-Phishing Code verification, provide layered protection against compromise.
  • 3 Mandatory security features Binance recommends enabling to prevent phishing account takeovers
  • $500M Market capitalization of PONS after Binance Alpha listing; up 1,500% in two weeks
  • 3 Cryptocurrencies delisted on September 3 following previous announcement of service termination

Binance, the world’s largest cryptocurrency exchange by trading volume, has issued an urgent advisory to its user base warning of a surge in phishing attacks designed to compromise account security and facilitate unauthorized fund transfers.

The attack vector centers on fraudulent Short Message Service (SMS) communications that impersonate official Binance security notifications, requesting users click links to verify account changes or respond to alleged suspicious login attempts.

The exchange explicitly stated that criminals are exploiting the natural urgency users feel when receiving apparent security alerts, pressuring them to act before verifying the message’s authenticity.

For institutional investors and custody providers operating on Binance, who custody assets worth billions across thousands of accounts, the threat landscape has immediate implications for operational security protocols and staff training.

Binance Clarifies That Legitimate Security Alerts Never Arrive Via Text Message Links

The core deception in these phishing campaigns relies on mimicking the language and formatting of genuine security warnings. Attackers craft messages stating phrases such as “Your account settings were changed” or “Suspicious login detected,” paired with shortened URLs that redirect victims to credential-harvesting pages designed to visually resemble Binance’s login interface.

Once a user submits their email and password, or in more sophisticated variants, additional two-factor authentication codes, attackers gain access to the account and can disable withdrawal restrictions, drain holdings, and move funds to external wallets within minutes.

Binance’s advisory directly addresses this methodology by clarifying a fundamental rule: the exchange will never request that users click links embedded in text messages to verify, secure, or authenticate their accounts.

This statement is critical for institutional operations, where staff members may receive these messages while traveling, using mobile devices without corporate security tools, or during high-stress market conditions when judgment lapses. The advisory reinforces that any text message requesting account action should be treated as fraudulent regardless of how official it appears.

Remember: Binance will never ask you to tap a link in a text message to “verify” or “secure” your account.

Binance, official security advisory

Three Layered Technical Controls Reduce Account Compromise Risk Significantly

Binance outlined three specific security configurations that create overlapping defenses against unauthorized account access and fund transfers. The first measure, Binance Verify, allows users to authenticate links before clicking by checking them against a whitelist of legitimate Binance domains.

Users who receive a text message containing a URL can use this feature to confirm whether the link actually originates from Binance infrastructure or leads to a third-party phishing site. This simple validation step eliminates the majority of successful phishing attacks, as attackers rely on users bypassing verification in the moment of perceived urgency.

The second control, Withdrawal Address Whitelist, operates at the account level rather than the message level. Once enabled, this feature restricts all outbound fund transfers to a pre-approved list of cryptocurrency addresses entered during setup.

Even if an attacker successfully compromises credentials and gains full account access, they cannot move funds to their own wallets, the exchange’s backend system will reject any withdrawal instruction to an address not on the whitelist.

For institutional accounts managing millions in daily trading activity, this control transforms a potential total-loss scenario into one where funds remain locked until the institution reapplies whitelisting through its own formal processes.

The third layer involves Anti-Phishing Code, a unique alphanumeric string that Binance includes in every legitimate email communication from the exchange.

Users set their own anti-phishing code during account setup; any email from Binance that does not include this code in plain text is fraudulent. This mechanism prevents attackers from using email spoofing to impersonate Binance support staff requesting account changes or claiming to have detected suspicious activity.

The three controls together create a defense-in-depth model: verification before clicking, restriction at the withdrawal level, and email authentication at the content level.

Binance Delisting of Three Major Tokens Demonstrates Market-Wide Exchange Risk

The phishing warning arrives amid broader Binance operational activity that illustrates how exchange decisions directly impact token liquidity and institutional trading conditions. On September 3, Binance delisted three cryptocurrencies, ICON (ICX), Secret (SCRT), and Storj (STORJ), following a previous announcement that the exchange would terminate support for these assets.

The delistings were completed after a specified deadline, after which users could no longer trade the tokens on Binance or withdraw them to external wallets during a final settlement window.

The market reaction to these delistings was immediate and severe. Prices of all three affected tokens declined sharply following the public announcement, reflecting the loss of liquidity that Binance’s removal creates.

As the largest cryptocurrency exchange by volume, controlling a disproportionate share of trading activity and price discovery for most altcoins, Binance delistings have outsized market impact. A delisting reduces available liquidity, increases the bid-ask spread on remaining venues, and damages perceived legitimacy of the project.

Institutional traders who held positions in these assets faced forced liquidation or sale at unfavorable rates, or relocation of holdings to smaller, less liquid exchanges.

Prior delistings in June affecting Alchemix (ALCX), Ardor (ARDR), NFPrompt Token (NFP), and Marlin (POND) produced similar price declines, establishing a clear pattern of market impact.

PONS Listing on Binance Alpha Fuels 1,500% Gain in Two Weeks as Early-Stage Discovery Hub Gains Traction

In contrast to the delisting pressure, Binance added PONS to its Binance Alpha section earlier this week, a discovery hub designed to surface emerging cryptocurrencies with potential for official listing. The listing sparked immediate upward momentum, with PONS gaining approximately 1,500% in value over the two-week period surrounding and following the announcement.

The token’s market capitalization reached approximately $500 million, reflecting the outsized impact that Binance platform access, even to an early-stage discovery section, carries for smaller projects.

The PONS rally illustrates the dual nature of Binance’s influence on the broader crypto market. While delisting decisions can crater valuations through reduced liquidity, early-stage listings on the Alpha platform can generate explosive gains for projects meeting the exchange’s criteria.

For institutional investors evaluating early-stage cryptocurrency investments, Binance Alpha listings have become a signal of preliminary exchange vetting and a potential indicator of future official listing, and the associated liquidity upgrade that accompanies it.

Institutional venture firms and hedge funds now monitor Binance Alpha additions as a leading indicator of emerging projects worth deeper research.

The PONS case demonstrates that exchange platform decisions remain the primary liquidity and valuation driver for most altcoins, with Binance’s choices directly determining investment outcomes across institutional crypto portfolios.

Institutional investors should immediately implement the three security controls outlined in Binance’s advisory, Binance Verify, Withdrawal Address Whitelist, and Anti-Phishing Code, across all trading accounts

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe