BabianLab
Get started

What Does Each Item on the Binance Security Page Do? 2FA, Anti-Phishing, and Whitelist Fully Explained

The Binance account security page has a dozen or so features, including 2FA, Anti-Phishing Code, withdrawal address whitelist, device management, and API management. This article goes through the page top to bottom, item by item, explaining what each security setting does, the recommended configuration, and the common pitfalls.

Published 2026-05-06 · Reading time 32 min · UI Map

The Binance security settings page is the "account checkup" beginners most often skip. Once an account is opened, there are at least 8 security settings that need to be configured one by one, or it's like living in a house with no lock on the door. This time, we went through the Binance Official Site and explained every item on the security page from top to bottom, along with exactly what's different when it's configured versus when it isn't. The short answer up front: the 4 must-enable items are 2FA, the Anti-Phishing Code, the withdrawal whitelist, and device management; the 3 optional ones are API management, changing your login password, and an emergency contact; and the 2 rarely-used ones are freezing your account and closing your account.

Where to Find the Security Page

Open the Official Binance App:

  1. Tap the "Account" icon on the far right of the bottom bar
  2. Tap the "Security" icon (shield-shaped) below your account name at the top
  3. You'll land on the main security settings page

You can also get there through the "Account" menu by tapping "Account & Security."

Overall Structure of the Security Homepage

The security homepage is generally arranged from top to bottom by level of importance:

Order Item Importance
1 2FA Must enable
2 Anti-Phishing Code Must enable
3 Withdrawal Address Whitelist Must enable
4 Device Management Must enable
5 Login Password Must change
6 Withdrawal Password Some users
7 API Management Optional
8 Emergency Contact Optional
9 Account Freeze For emergencies
10 Close Account For leaving

Each item shows an "Enabled" or "Not Enabled" status indicator.

2FA

The single most important security feature, full stop.

What 2FA Is

2FA (Two-Factor Authentication) means logging in or performing sensitive actions requires "your password + a second verification factor." Common second factors include:

  • Google Authenticator (a time-based one-time password, TOTP)
  • SMS verification code
  • Email verification code
  • Hardware key (YubiKey)

Binance supports all 4 of the above.

Recommended Setup

Google Authenticator is the best first choice. Reasons:

  • Generated offline, doesn't depend on network connectivity
  • Can't be hijacked through a SIM swap
  • Changes every 30 seconds, so a screenshot becomes useless fast

A hardware key (YubiKey) is the next best option. It offers the highest security level, but has a higher cost and steeper learning curve for average users.

SMS and email work as backups. SIM swapping is a real threat, so don't rely on SMS as your only 2FA method.

For a hands-on walkthrough of setting up Google Authenticator, check the related notes in the Security category.

Hands-On: What It's Like After Enabling 2FA

We set up a new test account and enabled Google Authenticator on it:

Action Requires 2FA
Login Yes
Changing withdrawal address Yes
On-chain withdrawal Yes (every time)
Transfer No
Placing a spot order No
Modifying API permissions Yes
Disabling 2FA Yes (plus email re-confirmation)

As you can see, 2FA steps in on every action that could result in funds leaving the account. It doesn't get in the way of everyday trading.

Anti-Phishing Code

The Anti-Phishing Code is a mechanism unique to Binance. The idea is simple but effective.

What the Anti-Phishing Code Is

You set a string of 4-20 characters (for example BabianLab2026), and every official email or SMS Binance sends you will carry that string.

If you receive a "Binance" email that doesn't contain your code, it's a phishing email.

Setup Process

  1. Security page → Anti-Phishing Code → Enable
  2. Enter 4-20 characters (a mix of letters and numbers is recommended, but don't include anything related to your password)
  3. Triple verification via SMS + email + 2FA
  4. Enabled successfully

Once enabled, every Binance email will display this string in the subject line or body.

Hands-On: Catching a Phishing Email

We deliberately forged a "your Binance account is abnormal" email using a third-party email service and sent it to a test inbox. The email was designed to look extremely convincing — the logo, fonts, and wording all looked real — but it was missing the Anti-Phishing Code. It was obvious at a glance.

Without the Anti-Phishing Code enabled, a beginner would very likely click the phishing link and hand over their login credentials.

Withdrawal Address Whitelist

The feature beginners underestimate the most.

What the Whitelist Is

Once enabled, you can only withdraw to addresses you've added in advance. Withdrawals to any unfamiliar address are blocked.

Why This Feature Matters

Suppose an attacker gets hold of both your password and your 2FA (through credential stuffing plus a SIM hijack) and wants to steal your coins — but if you have the whitelist enabled, they first have to add a new address, and adding a new address requires a 24-hour waiting period (Binance's security delay), during which you get an email notification. That gives you time to intervene.

Without the whitelist enabled, an attacker who has your 2FA can move your coins out within minutes, and it's nearly impossible to recover.

Setup Process

  1. Security page → Withdrawal Whitelist → Enable
  2. Add your commonly used addresses (your own hardware wallet, Trust Wallet, etc.)
  3. Adding an address requires 2FA verification
  4. After adding, wait 24 hours before the new address can be used

Hands-On: The Whitelist Delay

We added a new address: it showed a "24-hour cooldown." Withdrawals to that address weren't possible during those 24 hours. After 24 hours, the status changed to "Available," and withdrawals could proceed.

This 24-hour cooldown is the key line of defense. If you notice an unfamiliar address was added, delete it immediately.

Device Management

Shows every device that has ever logged into your account.

What the Device List Shows

Field Content
Device Name iPhone 15 Pro / MacBook Pro, etc.
Browser Chrome / Safari / Binance App
IP Address The login IP
Location Resolved from the IP
Last Login Most recent activity

Actions

Each device has a "Remove" button next to it. If you spot an unfamiliar device:

  1. "Remove" that device immediately (force logout)
  2. Change your login password
  3. Reset your 2FA (the old secret may have leaked)
  4. Check recent withdrawal and trading records

Hands-On: Alert for a Login from a New Location

We logged into the test account from a new device. The original account immediately received:

  • An email notification (with the Anti-Phishing Code)
  • An SMS notification
  • An app push notification (if previously logged in)

And it required "email verification code + 2FA" double verification to complete the login. This is the combined effect of 2FA and device management working together.

Login Password

Changing it periodically is a good habit.

Recommended Strategy

  • At least 12 characters
  • A mix of letters, numbers, and special characters
  • Not reused from any other website
  • Changed every 3-6 months

Change Process

  1. Security page → Login Password → Change
  2. Enter your old password
  3. Enter your new password (twice)
  4. Verify with email + 2FA
  5. After a successful change, all devices need to log in again

Note: there's a withdrawal restriction for 24 hours after changing your password (to prevent an attacker who just changed your password from immediately moving assets out).

Withdrawal Password

A concept from older versions of Binance. The current version of Binance has replaced the withdrawal password with 2FA. If this option still appears on your account, you can keep it enabled or turn it off — it's a matter of preference.

API Management

If you do quantitative trading or use third-party tools (like TradingView auto-trading), you'll need an API.

API Permission Tiers

Permission Meaning
Read Can only query account data
Spot Trading Can place spot orders
Futures Trading Can place futures orders
Withdrawal Can initiate withdrawals

Serious warning: never grant withdrawal permission to an API. The vast majority of quant strategies only need "Read + Trading" — withdrawal permission is not required. If an API key with withdrawal permission leaks, your assets can be drained within minutes.

Hands-On: Creating an API

  1. Security page → API Management → Create API
  2. Name it (e.g. "TradingView Bot")
  3. Complete 2FA verification
  4. Generate the API Key and Secret Key (the Secret is only shown once!)
  5. Only "Read" is enabled by default — you need to manually check "Spot Trading"
  6. Restrict IP access (strongly recommended) — only allow specific IPs to call this API

Once the API is set up, keep the Secret Key safe. If the key leaks, delete it and create a new one immediately.

Emergency Contact

A newer feature, visible to some users. You can set an emergency contact email, so that if your account is frozen or you don't log in for a long time, Binance can reach you through that email.

Most beginners won't need it, but it's recommended for accounts holding significant assets.

Account Freeze

If you suspect your account has been compromised, you can freeze it immediately as an emergency measure.

Status After Freezing

  • Can't log in
  • Can't trade
  • Can't withdraw
  • Existing open orders stay in place but can't be cancelled
  • Assets remain intact

The freeze lasts at least 24 hours, during which no action can undo it. After 24 hours, you can apply to unfreeze, which requires identity verification with support.

Emergency Freeze Path

The Binance login page has an "Emergency Freeze Account" button (requires email + 2FA verification). If you can't access your account at all, you can also contact support to have it frozen. For the specific support process, see the Support & Appeals category.

Close Account

If you no longer want to use Binance, you can close your account.

Prerequisites for Closing

  • All coin balances are 0
  • No pending orders
  • No Earn products that haven't matured
  • No withdrawal currently being processed

Closing Process

  1. Security page → Close Account
  2. Confirm there are no remaining assets
  3. Enter your reason for closing
  4. Verify with email + 2FA
  5. Wait out a 7-day cooling-off period
  6. After 7 days, the account is officially closed

Any login within those 7 days will cancel the closure.

Can You Recover It After Closing?

No. After closing, account data is retained for a period of time in accordance with local regulations (usually for compliance audit purposes), but you will no longer be able to log in or use the account.

Recommended Security Configuration

Here's what we recommend beginners set up after opening an account:

Item Recommendation
2FA Google Authenticator + SMS backup
Anti-Phishing Code Enabled (4-12 mixed characters)
Withdrawal Whitelist Enabled, with your common addresses added
Device Management Check periodically
Login Password 12+ characters, updated regularly
API Management Only enable when needed, never grant withdrawal permission
Emergency Contact Enable if you hold significant assets

Completing the above during your first week after opening an account gives your security level enough coverage to handle the vast majority of attacks. For hands-on 2FA setup steps, check the related notes in the Security category.

A Few Common Pitfalls

Pitfall 1: Losing the 2FA Backup Codes

When you set up Google Authenticator, Binance shows you a string of backup (recovery) codes. You must save this string — if you lose your phone or uninstall the authenticator app, the backup codes are the only way to recover your 2FA.

A lot of beginners just dismiss that prompt screen without saving it. The consequence: if you lose your phone, you can't get back into your account, and you have to go through a long identity-verification process with support.

Pitfall 2: Adding the Wrong Address to the Whitelist

Mistyping a single character when adding an address to the whitelist, and only discovering it 24 hours later. Deleting it and re-adding the correct one means waiting another 24 hours. It's best to double-check the address and use copy-paste instead of typing it manually.

Pitfall 3: Uploading an API Key to GitHub

A lot of beginners writing quant code hardcode their API key directly into the source, then push it to a public GitHub repository. Scrapers find it within minutes and the account gets cleaned out. Always keep the key in an environment variable or a .env file, and add it to .gitignore.

Pitfall 4: Enabling Withdrawal Permission on an API

APIs don't have withdrawal permission enabled by default. But some people enable it "to save a step." That's handing money to attackers. No quant strategy needs withdrawal via API — withdrawals should always be done manually.

FAQ

Q: If I forget my Anti-Phishing Code, can I reset it? A: Yes. Go to the Anti-Phishing Code settings on the security page, and it will show your currently set code (some versions only display the first and last few characters). Changing it requires 2FA plus email verification.

Q: Does adding a new whitelist address always require waiting 24 hours? A: Yes. This is one of Binance's security mechanisms, applied uniformly to all users worldwide, and it can't be skipped. A small number of VIP tiers have special arrangements, but regular users always have to wait.

Q: Can I enable multiple 2FA methods at once? A: Your primary Binance 2FA can only be one method at a time (Authenticator / SMS / hardware key — pick one). But you can also enable "email secondary verification" as extra insurance at the same time.

Q: What if I forget my login password? A: On the login page, click "Forgot Password" → get a reset link by email → set a new password. If you've also lost access to your email, you'll need to go through identity verification with support (providing your KYC information for confirmation).

Q: Can an API key be revoked? A: Yes. Every API on the API Management page has a "Delete" button. Once deleted, the key becomes invalid immediately, and any running program using it will stop due to authentication failure.

Q: Can a whitelist address be deleted? A: Yes, it can be deleted instantly, with no waiting period. But if you add the same address again later, you'll have to wait another 24 hours.

Q: What should I do if my phone with 2FA on it gets stolen? A: Follow this order:

  1. Log in with a backup code (if you have one)
  2. Immediately disable the old 2FA and bind a new device
  3. Change your login password
  4. Check recent login and withdrawal records If you've also lost your backup codes, you'll need to contact support and go through identity verification.

Q: Can I see IP addresses in Device Management? A: You can see a partially masked IP (typically the first few segments shown) and a general location (resolved from the IP). If you spot a login from an unfamiliar location, act on it immediately.

Q: Is there a rate limit on API calls? A: Yes. Each API key has its own rate limit (for example, 1,200 requests per minute). Exceeding it results in a temporary ban. Professional users can apply to have their limits raised.

Ask AI… Ctrl I