BabianLab
Get started

How Do You Set Up the Binance Withdrawal Whitelist? Adding Addresses and the Cooldown Explained

Once the Binance withdrawal address whitelist is turned on, your account can only withdraw to addresses on the list. Newly added addresses have a 24-hour cooldown before they can be used for withdrawals. This post documents our full hands-on test of enabling it and adding 5 addresses.

Published 2026-05-05 · Reading time 26 min · Security

The withdrawal whitelist is the switch in your Binance account that restricts withdrawals to "only these addresses." Once it's on, sign in to Binance Official Site → [Account] → [Security] → [Withdrawal Whitelist] to flip the master switch, then go to [Address Book] to add addresses. Newly added addresses have a 24-hour cooldown before they can be used, while existing addresses remain usable immediately. After we turned this on, even if an account is phished for the password plus 2FA, the attacker still can't withdraw to their own address unless they wait out the 24 hours — a window that's long enough for you to notice and freeze the account.

The whole setup takes about 5 minutes, and adding a single address takes about 1 minute (not counting the cooldown). But a lot of people miss one step early on: just having entries in the address book without turning on the master whitelist switch means the account can still withdraw to any address — effectively, the whitelist isn't enabled at all.

Whitelist vs. Address Book — Two Different Things

This table lays out the difference we clarified during this test:

Name What it does Restricts withdrawals? Default state
Address Book (Address Management) Saves frequently used withdrawal addresses for quick selection No On by default
Whitelist master switch (Whitelist) Limits withdrawals to whitelisted addresses only Yes Off by default
Whitelist cooldown (Cooldown) Newly added addresses can't be used for withdrawal for 24 hours Yes Automatic

A lot of people treat "adding an address to the address book" as "adding it to the whitelist," but that's really just step one. The address book is a favorites list that saves you from copy-pasting an address every time you withdraw, but it doesn't restrict you to addresses inside it. The real security mechanism is the whitelist master switch plus the cooldown.

Step 1: Turn On the Whitelist Master Switch

Open the Official Binance App, go to [More] → [Security], and find [Withdrawal Whitelist]. This toggle is off by default, with the switch on the right.

Tap the toggle → a description pops up → enter your 6-digit 2FA code → enter your 6-digit email verification code → enter your 6-digit SMS code (if bound) → submit. Verifying with three codes at once is the standard procedure for enabling this kind of security feature, to confirm it's really you.

Once submitted successfully, the toggle turns green. From that moment on, every withdrawal request first checks whether the destination address is in the address book and past its cooldown. If not, the withdraw button is simply disabled — the request never even gets sent.

Note: enabling the whitelist does not affect withdrawals that are already under review — those continue on their original process. The new rule only applies to new withdrawal requests initiated after it's turned on.

Step 2: Add a Whitelisted Address

Go to [Wallet] → [Address Book] (sometimes labeled [Address Management]), then tap [Add Address]. Each address requires:

Field What to enter Notes
Label A custom name, e.g. OKX-BTC-cold English or any language, up to 30 characters
Coin Choose BTC / ETH / USDT, etc. One coin per line; multi-chain USDT needs separate entries
Network TRC20 / ERC20 / BEP20, etc. Required — the wrong network means lost funds
Address Copy and paste Double-check the first 4 and last 4 characters
Memo Required for some chains (XRP/EOS, etc.) Leave blank if not required
Add to Whitelist Check this box Critical — without it, this is just an address book entry

That last option, [Add to Whitelist], must be checked, or the entry stays a plain address-book item and never enters the whitelist. Checking it is what starts the 24-hour cooldown timer.

We added 5 addresses this time, filling in coin, network, label, and memo for each. After adding, each one showed "Status: pending activation, 23:58:42 remaining."

Step 3: Wait Out the Cooldown — 24 Hours, No Skipping

The moment you add an address, the system records a timestamp, and for the next 24 hours that address cannot be used for withdrawals. Selecting it on the withdrawal page shows "This address is in cooldown, available in X hours X minutes," and the button turns gray.

The 24-hour period is a hard rule of Binance's risk control — it can't be expedited, support can't skip it, and there's no way to pay to unlock it. The whole point of this mechanism is to give the "real account owner" 24 hours to react — if an attacker just added a new address, you still have this 24-hour window to notice, change your password, and delete the address.

What you can do during the cooldown:

  • Edit the address's label or memo (doesn't restart the timer)
  • Delete the address (takes effect immediately, no cooldown required)
  • Withdraw to other addresses that have already passed their cooldown (unaffected)

What you can't do during the cooldown:

  • Withdraw using that address (button stays gray)
  • Force the address from "cooldown" to "available now" (there's no such action)

If you need to withdraw immediately and every address is still cooling down, the only way is to turn off the whitelist master switch → make the withdrawal → turn it back on. But turning off the whitelist also triggers its own 24-hour cooldown. This nested design is intentional.

Step 4: Delete an Address — Effective Immediately

Go to [Address Book] → find the address you want to remove → tap [Delete] → enter your 2FA code → confirm. Deletion takes effect immediately, with no cooldown required.

This is another deliberate security design: adding an address requires a 24-hour cooldown, but deleting one is instant. It's asymmetric on purpose — adding an address expands the attack surface (an attacker could withdraw to it), while deleting one shrinks the attack surface (nothing can be withdrawn to it anymore). It makes sense for a security mechanism to be biased toward "shrinking."

If you notice suspicious activity on your account, the first thing to do is delete every unfamiliar whitelisted address, then immediately turn off the whitelist master switch and turn it back on (re-enabling doesn't require a cooldown but does require 2FA). This effectively resets "who can withdraw to where" back to zero.

Our Test Timeline

Time Action Result
10:02 Turned on the whitelist master switch Effective immediately
10:05 Added an OKX BTC address Entered cooldown
10:08 Added an OKX USDT-TRC20 address Entered cooldown
10:12 Added a self-custody ETH address Entered cooldown
10:15 Tried sending 0.001 BTC using the BTC address Button gray, cooldown shows 23:47 remaining
10:20 Picked the wrong network (chose ERC20 for USDT but the address was TRC20) System detected the address format mismatch and refused to save
Next day 10:08 OKX BTC address cooldown ended Withdrawal now works normally
Next day 10:15 Withdrew a test amount of 0.005 BTC Arrived in 18 minutes

Note the 10:20 entry: Binance validates address formats — a TRC20 address (starts with "T," 34 characters) and an ERC20 address (starts with "0x," 42 characters) have different formats, and forcing a mismatch triggers an error. But it doesn't validate different coins on the same chain — for example, an ERC20 USDT address and an ERC20 USDC address both start with "0x," so Binance can't tell whether you meant to send USDT but accidentally selected USDC. You have to catch this kind of mistake yourself.

How Risky Is It Without the Whitelist?

Without the whitelist enabled, if an account is phished for its password plus 2FA, the attacker can:

  1. Log in immediately from their own device
  2. Withdraw funds to their own wallet
  3. Do all of this with nothing more than an email verification code (and if your email is also compromised, there's no obstacle at all)

The whole process can be finished within 10-30 minutes. By the time you notice something's wrong, the funds are already on-chain, and on-chain transfers can't be reversed.

With the whitelist enabled, the attacker's steps become:

  1. Log in → change the password → turn off the whitelist or add a new address
  2. Turning off the whitelist triggers a 24-hour cooldown
  3. Adding a new address also triggers a 24-hour cooldown
  4. During those 24 hours, you have a chance to notice and freeze the account

That's the core value of the whitelist: it stretches the window between "account compromised" and "funds withdrawn" from 30 minutes to 24 hours. That's enough time for you to see Binance's "new device login" email, notice your anti-phishing code disappear (see How to Set Up the Binance Anti-Phishing Code and Use It to Spot Fake Emails), see the password-change email, and then contact support to freeze the account.

Whitelist Strategy by Account Type

Account type Whitelist recommendation Number of addresses Cooldown handling
Mostly long-term holding Strongly recommended 2-3 (your own cold wallet + main exchange) Set them all up once, rarely change afterward
High-frequency arbitrage / cross-exchange trading Depends 5-10 (multiple exchange counterparties) Plan 24 hours ahead
Frequently withdraw to third-party wallets Strongly recommended As needed Expand gradually, add new addresses a day in advance
Mainly futures, rarely withdraw Optional 1-2 as backup Doesn't affect futures trading
Company account / multi-person collaboration Mandatory, plus multisig Strict whitelist Add addresses through an approval process

That last scenario matters most: for a company account or a shared account used by multiple people, the whitelist is the bare minimum for compliance auditing — skipping it means there's no internal control at all.

Frequently Asked Questions

Q: Does Binance email me when a new address is added to the whitelist during the cooldown? A: Yes. An email is sent every time an address is added, and the body includes your anti-phishing code (if you've set one) along with the 24-hour countdown. If you didn't add an address but receive this email, immediately change your password, delete the address, and turn off the whitelist.

Q: Can I make the cooldown 7 days or 30 days instead? A: No. Binance fixes it at 24 hours with no configurable options. You can enforce your own discipline of "add addresses 7 days ahead of time," which effectively extends the cooldown yourself.

Q: Once the whitelist is on, are internal transfers (between Binance accounts) also restricted? A: Internal transfers (in-app transfers, UID transfers) aren't subject to the whitelist. The whitelist only applies to on-chain withdrawals. If you're concerned about internal transfers, you need to separately enable the [Withdrawal Cooling-Off Period] feature.

Q: If a whitelisted address is shared by multiple coins, does it count as one entry or several? A: Several. For example, if you want to use the same 0x-prefixed ERC20 address to receive USDT, USDC, and ETH, you need to add 3 separate entries, each with its own independent cooldown.

Q: Do I need to whitelist the address when withdrawing from OKX to Binance? A: No. The whitelist only controls the direction "out of Binance" — it has no control over incoming transfers. Any address can deposit into Binance.

Q: Do I need to set up the whitelist again after switching phones or devices? A: No. The whitelist and address book are account-level settings, unrelated to the device. After logging in on a new phone, your existing settings remain unchanged.

Q: If the whitelist master switch gets turned off, are the previously added addresses still in the address book? A: Yes. The address book is a separate layer — turning off the whitelist only stops the "restrict withdrawals to these addresses only" behavior; the address records themselves aren't lost. Turning the whitelist back on takes effect immediately, without needing to re-add addresses or restart any cooldown.

Q: How does the whitelist relate to API withdrawals? A: API withdrawals go through the whitelist by default. Even if you've granted an API Key withdrawal permission, the destination address still must be on the whitelist, or the API call returns error -4007. This is a double layer of protection — see How to Manage Binance API Keys: Minimum-Permission Setup and Periodic Review.

Ask AI… Ctrl I