Security guide · SET-01 · Beginner week one

The first week with a new Binance account: set these security switches before anything else

Plenty of people open an account and rush to deposit and buy, leaving every security setting for "later". The trouble is, scams and account theft tend to strike during that "later". This page lays the first-week tasks out as a checklist, starting with the one that matters most — two-factor authentication — through to how to keep a seed phrase. Work through it once and you've kept most of the risk outside the door.

Binance beginner first-week security checklist: two-factor authentication, anti-phishing code, withdrawal whitelist, bookmark login
Chain Scam Index · beginner first-week security checklist

Set security first, talk profit later

The mood in your first week in crypto is usually excitement: you want to buy the coin you've been eyeing, you want to start trading. But there's an order worth following against your instinct — make the account's defences solid before you start putting money in. The reason is practical: while you're still unfamiliar with the interface and don't yet recognise the various scripts, that's exactly when you're easiest to phish and to rob. Locking the door first is far cheaper than patching things up after you're already inside.

The good news is that most of the settings below are one-offs that take little time and serve you for the long run. Think of it as "the last step of opening an account" — only after you've done it is the account truly open for business.

The first-week checklist at a glance

Here's the overview first, with each item detailed below. We'd suggest doing them in order:

  • Turn on two-factor authentication (2FA): prefer an authenticator app, not SMS alone.
  • Set an anti-phishing code: have official emails carry your own secret token so fakes give themselves away.
  • Turn on a withdrawal address whitelist: limit withdrawals to addresses you trust.
  • Bookmark the official site: from then on, log in only from the bookmark, not from search.
  • Run the full flow once with a small amount: deposit, buy, withdraw, with small money before scaling up.
  • Understand that wallets come in two kinds: exchange-custodied vs self-custody, and how to keep a seed phrase.

1. Two-factor authentication (2FA): an authenticator app beats SMS

Two-factor authentication means a password alone isn't enough — logging in or withdrawing also needs a one-time code. It's the most effective barrier against account theft, so turn this on first in week one.

2FA comes in a few forms with different security levels. The key points:

  • Authenticator app (recommended): tools like Google Authenticator or Authy generate a fresh code every few dozen seconds on your phone. The code is generated offline on the device and doesn't go through the mobile network, so it's harder to intercept.
  • SMS verification (better than nothing, but it has weaknesses): the code is texted to your phone. The problem is that SMS can be intercepted, and "SIM-swap" attacks exist — if an attacker has your number ported away, they can receive your codes. So if you can use an authenticator, don't rely on SMS alone.

When you set up the authenticator, a backup key or backup codes will appear; write them down and keep them offline. If your phone is lost or reset, that's what lets you recover; without it, you may lock yourself out. Where to enable each method may shift on Binance's side, so go by the official security settings you see after logging in, and cross-check the Binance help centre when needed.

A common beginner pitfall is installing the authenticator only on "the phone you'll later replace" without keeping the backup key, then locking themselves out when they change phones or the phone gets water-damaged. So writing the backup key down offline at setup time is the one step you should never skip in that same action. Also worth noting: the codes an authenticator generates are time-limited and change every few dozen seconds, so enter the current one, not an expired one; if it keeps showing an error, first check whether your phone's time is set to auto-correct, because a drifting clock makes the codes fail to match.

A verification code belongs to you alone. Anyone — including anyone claiming to be "support" — who asks you for a 2FA code or SMS code is running a scam. In the official flow, this code is only ever entered by you on an official page, never read aloud or pasted to anyone else.

2. Anti-phishing code

The anti-phishing code is a move aimed squarely at fake official emails. In account security settings you choose a string of text or numbers only you know, and once set, every email the official side sends you carries that code.

That makes calling a "Binance" email real or fake simple: present and correct, it might be real; absent or wrong, treat it as phishing. A scammer sending email doesn't know what you set, so they can't reproduce it. When setting it, don't use a birthday or nickname that's easy to associate with you. More on spotting email scams is in fake official emails and phishing mail.

3. Withdrawal address whitelist

The withdrawal address whitelist (also called withdrawal address management) does this: once enabled, your account can only withdraw to addresses added to the whitelist in advance, and unknown addresses can't be used.

Its value is as "the last line of defence in the worst case". If your account really is breached and the attacker wants to withdraw your coins, they can only send to whitelisted addresses — and those are all ones you added yourself. It seals off the "withdraw to an unknown address" route entirely. When setting it, add your common, verified recipient addresses; future additions or changes usually involve extra verification and a cooling-off period, and that small hassle buys a big safeguard, so it's worth it.

When adding addresses, check them character by character, and especially confirm the "chain" too — within the same exchange, USDT may support several chains, each with a different address format, and adding the wrong chain or pasting the wrong address can send coins somewhere they can't come back from. For a first whitelist, we'd suggest adding only one or two addresses you're 100% sure of (for example another wallet of your own), rather than filling it up in one go. To confirm which chain USDT runs on and which chain an address belongs to, you can compare it first with the USDT network checker.

Think of 2FA, the anti-phishing code, and the withdrawal whitelist as three locks in three different places: 2FA guards "logging in and acting", the anti-phishing code guards "your judgement against being misled by a fake email", and the whitelist guards "even if the first two are broken, the money can't get out". Only with all three on is it complete.

4. Logging in from a bookmark

Much account theft isn't a technical break-in — it's you "walking into" a fake site yourself: clicking into a Binance look-alike from a search ad or a link someone sent, and typing your password in by hand.

The fix is simple and effective: add the Binance site to your browser bookmarks and from now on always log in by clicking the bookmark, no search, no clicking links anyone sends. Once this habit sets in, you've bypassed a whole class of phishing sites. Why going in via search is so dangerous, how to set the bookmark, and how to tell at a glance whether an address is right — that's in the golden rule of logging in from a bookmark; if you're unsure whether an address in hand is clean, drop it into the look-alike domain checker for a character-by-character comparison.

5. A small test first

In your first week, don't jump straight to a big deposit and big trades. Run the full flow once with an amount you wouldn't mind losing: deposit, buy a little, then withdraw a small amount to your whitelisted address.

This does two things. One, it gets you used to the interface and what each step looks like, so when you later handle larger sums you won't fumble or slip up in a panic. Two, it confirms the whole path works and the address is right — at withdrawal especially, the wrong chain or a mispasted address can mean coins you'll never get back. Stepping on a pothole with small money once is far cheaper than doing it with large money. When withdrawing, always double-check the chain and the address; which chain USDT runs on can be confirmed with the USDT network checker.

Exchange wallet vs self-custody: who actually holds your coins

A common beginner confusion is not grasping the difference between "coins on an exchange" and "coins in your own wallet". This is about who holds the key to your assets, and it's worth a moment to make clear.

Exchange-custodied (like the balance in your Binance account)

When your coins sit in an exchange account, the reality is that the exchange holds them for you, and you operate via your account login. The upside is convenience — trading and converting all happen on the platform, and a forgotten password can be recovered through the official flow. The cost is that you have to trust the platform, and account security (password, 2FA) becomes the crux, which is why those locks earlier matter so much.

Self-custody wallet (like MetaMask, a hardware wallet)

Self-custody means you hold the private key / seed phrase yourself, with no middleman. The key is entirely in your hands — nobody can freeze it or move it — but nobody can recover it for you either: lose the seed phrase and the assets are gone for good; leak the seed phrase and someone else takes the money. "Not your keys, not your coins" is exactly this point.

Neither is absolutely better; they're different trade-offs. As a beginner, most people start with an exchange account to get used to things, then learn self-custody when they need to hold long-term or take part in on-chain activity. Whichever you use, the seed-phrase rules in the next section are the baseline. For scams aimed at self-custody wallets, see fake wallets and the seed-phrase trap; for a neutral explanation of wallet concepts, see the ethereum.org wallets page.

Rules for keeping a seed phrase

If you use a self-custody wallet, you'll get a seed phrase (usually 12 or 24 English words). This phrase is the wallet's top-level key — whoever has it has everything in that wallet. So the rules for keeping it are the strictest:

  • Write it on paper, keep it offline: write it on paper, store it somewhere safe, ideally two copies kept apart, to guard against both loss and damage.
  • Never photograph it, screenshot it, store it in the cloud, or type it into a phone note: anywhere connected to the internet can leak.
  • Never enter it on any web page: in normal wallet use, beyond the first backup, you almost never need to enter the seed phrase again. Any page asking you to enter it is out to steal your money.
  • Anyone who asks for it is a scammer: whatever they claim — support, official, technical help — asking for your seed phrase or private key confirms it's a scam right there.
  • Tell a seed phrase apart from a password: a forgotten exchange password can be recovered; a seed phrase has no "recovery" — lost is lost.

Take this as crypto's first iron rule: seed phrase and private key — offline, secret, never entered on any web page. Remember this one and you block a whole class of the most fatal losses.

We set these up ourselves

We set each of these switches up on our own account. Two-factor authentication can use an authenticator app or SMS, and when you set up the authenticator the system hands you a backup key — this is the step people skip most, but without it a change of phone can lock you out, and our takeaway is to write it down offline on the spot before moving on. The anti-phishing code is set in account security settings, and once it's on, official emails carry your code. Once the withdrawal address whitelist is enabled, withdrawal targets are limited to addresses you've added. The names and locations of these entries shift with versions, so we don't hard-code a path below — go by the security settings you see after logging in.

Finishing the checklist isn't the same as doing it right; the three things most easily overlooked are these. First, does your 2FA prefer the authenticator over SMS alone, and have you written that backup key down offline? Skip this and a phone change can lock you out. Second, is the withdrawal whitelist actually enabled, and were the addresses checked character by character along with the chain? Third — and the step to be most wary of — any request to "enter a seed phrase / private key / verification code", from anyone, for any reason, means stop.

FAQ

I only want to dabble with small amounts. Do I still need all this?

Yes. Account theft and scams won't spare you because your amount is small, and most of these settings are done once and last indefinitely, so there's no reason to skip them. Treat it as a necessary part of opening an account.

Does 2FA have to be an authenticator? Won't SMS do?

SMS is better than nothing, but it carries interception and SIM-swap risk, so if you can use an authenticator app, prefer it. If you can enable both, using the authenticator as the main method is steadier.

Are a seed phrase and an exchange login password the same thing?

No — this is the most common beginner mix-up. An exchange password logs you into your account and can be recovered if forgotten; a seed phrase is the top-level key to a self-custody wallet, has no recovery mechanism, and is far more important and far stricter to keep safe.

Isn't a withdrawal whitelist a hassle?

Adding or changing an address usually needs extra verification and may have a cooling-off period, so it is a little more bother. But that bother is exactly its value — it stops an attacker from withdrawing your coins to an unknown address on the fly. For the safety, it's worth it.

2026-06-22 · Entry created, covering the beginner first-week checklist and custody / seed-phrase concepts.