Binance Warns Users After Fake Security Texts Appear
Binance has warned customers about a new phishing campaign. The exchange said the attempts appeared on 3 September. Scammers sent text messages that looked like account security alerts. The company did not say how many people received the texts. It also did not publish any loss figures for this campaign.
The fake messages copied the tone of official Binance notices. They claimed that account settings had changed. In other cases, they claimed that someone had signed in from an unknown place. The texts then urged the recipient to “verify” or “secure” the account. Shortened links sat inside those messages.
Those links did not lead to Binance. They opened pages that copied the look of a Binance login or verification screen. Binance said it had seen an increase in phishing attacks against crypto users. It did not give a number for that increase.
This warning follows earlier campaigns that used the Binance name. In 2025, Australian police said scammers had placed fake texts inside existing Binance message threads. Binance now stresses a simple rule. The company will not ask users to confirm an account by tapping a link in a text message.
Anyone who receives a strange message should ignore the link. Open the official Binance app instead. Or type the official website address directly into a browser. Then check the account from there.
Binance also tells users to run checks through Binance Verify. That tool can show whether a website, email address, phone number, or social media account belongs to the exchange. Complete that check before sharing account details. Do not treat an unexpected sender as customer support.
If a user has already opened a suspicious page, contact Binance through the official app. Do not keep talking to the person who sent the text.
Binance also recommends a withdrawal address whitelist. That setting allows withdrawals only to addresses the user has already approved. Even if someone steals login details, the extra control makes a quick theft harder. Users should also protect the email account and the verification steps tied to that whitelist.
The broader lesson is straightforward. Treat unexpected security texts with suspicion. Use official apps and official web addresses. Verify first. Then act.