DEEP DIVE · CORNERSTONE · SC-00

Binance scams in 2026: the 10 most common, broken down one by one

Fake support, fake URLs, fake wallets, fake airdrops, pig-butchering — the tactics look endlessly varied, but the moment they actually trap you comes down to just a few choke points. This page lays out the 10 most reported scams as a single map, and for each one explains what it looks like, why people fall for it, and how to check it yourself.

Binance scams 2026 cover: an index of ten common tactics
Chain Scam Index · specimen catalogue of Binance-related scams (2026)

Why Binance is the name they keep impersonating

The reason is simple: lots of people use it. Binance is one of the largest crypto exchanges in the world, so when a scammer wants to cast a wide net, they pick the name most people know and are least likely to question. That is why you will see profile pictures with a Binance logo, account names stuffed with "Binance" or "Binance Official", and scripts that mimic the real thing closely.

But flip that around and it is good news — scammers can copy the look, never the rules. A few of Binance's rules are fixed: it never messages you first, it never asks for your seed phrase or private key, and it never tells you to move your funds to a "safe account" for verification. Hold on to those and no amount of surface polish will fool you. All 10 tactics below, at their core, are trying to get you to hand over assets or permissions with your own hands at one specific step. Once you can see that choke point, you are much harder to catch.

This is the index page. Each scam has its own in-depth entry you can click through for the details. The best way to read it: skim what all ten look like first, then click into the two or three you run into most and read closely.

1. Fake support DMs

This is the most common opening move. You might be in a trading group or a comment thread, or you just posted "I can't withdraw from Binance" somewhere public — and within minutes a "support agent" DMs you, profile picture wearing a Binance logo, name reading "Binance Official Support". They will tell you your account is "flagged", "suspected of a violation and frozen", or "needs help to unfreeze", then walk you step by step into handing over login details, verification codes, even your seed phrase.

Where is the choke point? It is the fact that they came to you. That alone breaks the rule. Binance support does not message users first, and it will never ask for your password, SMS code, or seed phrase in a chat. When you genuinely have a problem, you start the conversation from the support entrance inside the official app or website — not the other way around.

How to check it yourself: if someone claims to be official, paste their Telegram handle or display name into Binance's own Binance Verify tool. Only an account that shows up there is official; anything that does not is a scam. Watch out for one thing in particular — fake accounts love to stuff "Official", "Support", or similar words into the display name, but anyone can edit a display name, so it proves nothing. If the verification page does not find the account, it has nothing to do with the official side, however grand the name reads. The full script, the wording, and more defensive steps are collected in the fake support entry.

Reminder: anyone — no matter who they claim to be — who asks for your seed phrase, private key, or SMS code is a scammer the moment they ask. You can stop listening right there.

2. Fake URLs (phishing clone sites)

Fake exchanges are the bulk of deposit scams. The scammer builds a site nearly identical to Binance on a domain that is off by a letter or two — binance might become binnance or blnance, or they tack a strange tail on the end by putting the official-looking word up front and burying the real domain behind it. You log in and deposit as usual, and the money lands in the scammer's pocket.

The choke point is how you got to that site in the first place. Most victims were not dragged there — they clicked a link from a search ad or a chat message. Search "Binance login" and the result sitting at the very top is sometimes a fake site that paid for the ad slot.

How to check it yourself: before you open any page that looks like a login screen, hover over the link and read the real URL the browser shows. Focus on the main domain — the two segments right before the last slash. The real site is always binance.com; any number of subdomains in front of it (such as accounts.binance.com) still belong to the same company, but if the main domain becomes binance-secure.com or binance.verify-login.com — official-looking words up front while the real domain is pushed to the back or misspelled — it is a fake. Bookmark the official site and go in through the bookmark every time; do not rely on search and do not click links other people send you. If you are not sure a link is clean, drop it into our look-alike domain checker for a character-by-character comparison. Further reading: how to spot a fake exchange and the bookmark-login rule.

3. Fake wallets and the seed-phrase trap

This one targets people who use self-custody wallets (MetaMask, Trust Wallet, and the like). It comes in a few forms: a fake wallet app published to an unofficial source, a fake browser extension, or a "support agent" who, in the name of "syncing" or "verifying", gets you to type your seed phrase into some page. The moment your seed phrase leaves your hands, the wallet is no longer yours.

The choke point is those three words: seed phrase. The seed phrase is the highest level of access to your wallet, so anyone, at any time, on any page who asks you to enter it is trying to steal your money. In normal use, apart from your first backup, you almost never need to type it again.

How to check it yourself: when a screen tells you to "enter your seed phrase", stop and ask one question — what am I actually doing right now? The only normal reason to enter a seed phrase is restoring an existing wallet on a new device, and that is always something you started yourself. If someone else is telling you to enter it — to "sync", "verify", "upgrade", or "claim a reward" — it is fake, and you close the page right there. Keep your seed phrase written on paper, stored offline: no photos, no cloud photo album, never pasted into any chat window or web page. The full how-to-spot guide is in the fake wallet entry.

4. Fake airdrops and malicious approvals

"Free tokens" sounds harmless, yet in recent years it is one of the fastest ways to lose money. You get an airdrop link, connect your wallet, hit "claim" — and what you actually signed was an approval handing control of one of your tokens to the scammer's contract. Nothing feels wrong in the moment; a while later, the assets quietly move out.

The choke point is the approval signature. Plenty of people see the approval window the wallet pops up, do not understand it, and just hit confirm. But an approval means "I allow this contract to move one of my tokens", and giving it to the wrong party is the same as handing over a key.

How to check it yourself: when the wallet pops up a signature window, do not rush to confirm — read what kind of action it describes. If you see words like "Approve" or "Set Approval For All", you are about to hand over control of a token or a whole collection, and claiming an airdrop simply does not require that — so cancel when you see it. Never connect your wallet to or sign anything for an airdrop of unknown origin. Build the habit of scanning your wallet with an approval-checking tool every so often and revoking any approval you do not recognise or no longer use — it is like periodically calling back the spare keys you handed out. For what an approval is and how to revoke one, see the wallet approval review and revoke guide; for the underlying concepts, the ethereum.org security page has a plain explainer.

5. Trading mentors and pig-butchering

This one runs on emotion and trust. It might be a "match" from a dating app, or a "teacher" in an investment group calling the trades for you. Early on they let you make a little, let you withdraw it, build trust — then slowly steer you to add more capital and move it to some "internal platform", until the whole lot, principal and "profit", disappears. This is what is usually called pig-butchering.

The choke point is "where is the platform" and "why are they so insistent you add more". Real trading happens in your own exchange account, one you can verify independently. Being told to download an app you have never heard of, or to send money somewhere they point you, means being led into an environment the scammer fully controls.

How to check it yourself: lock onto one move — "where are they telling you to send your money". The moment they start guiding you to download an unheard-of app, register on a platform whose background you cannot find, or send funds to some address they give you, stop right there, no matter how many wins came before or how well you click. You can test it in reverse: tell them you only want to trade in your own existing exchange account and will not switch platforms. A genuine relationship will not blow up over that; if they get anxious, apply pressure, or say "that allocation only exists on our platform", the answer is already clear. Any "guaranteed profit", "sure thing", or "follow the teacher and you always win" is false — there is no such thing as a guaranteed return in crypto. For a stage-by-stage breakdown of the script, see the fake mentor and pig-butchering entry.

6. Fake OTC / P2P payments

Over-the-counter trading (OTC / P2P) is a perfectly normal way to buy and sell, but scammers find their angle in it too. The common version: someone offers to sell you USDT privately over Line or Telegram, claims a better price, and wants you to wire the money first; or the reverse, where a buyer pays with funds the bank can later claw back and tricks you into releasing the coins first.

The choke point is leaving the platform's escrow behind. The P2P inside an exchange has a custody mechanism; a private trade runs purely on trust, and if it goes wrong nobody stands behind it.

How to check it yourself: do P2P inside the exchange platform, settled through its escrow, and do not let a "better price off-platform" pull you out. Before trading, confirm which chain the USDT is on and the contract address — you can use our USDT network checker to confirm which chain an address belongs to. More in the fake OTC entry.

7. Fake official emails

You get an email from "Binance" saying your account needs verification, a withdrawal was blocked, or someone logged in, with a "handle this now" button. Click it and you land on a phishing page that wants your username and password. The sender and the layout are imitated closely.

The choke point is how you confirm the email really came from the official side. The sender name alone proves nothing — that can be forged.

How to check it yourself: in your Binance account settings, turn on the anti-phishing code — a string only you know. Once it is on, official emails carry that code in the header; an email without it, or with the wrong code, is fake. There is also a check you can run on the spot: do not click the "handle this now" button, hover over it and read where the real link points. If the main domain is not binance.com, it is a phishing page. If you genuinely need to deal with an account issue, close the email and open the official site from your bookmark to check your notifications yourself — do not follow the path the email lays out. For how to set it up and other email tells, see the fake email entry; the official feature is documented at the Binance Help Center.

8. Fake events and giveaways

Binance runs events often, so scammers pose as "event partners" or "airdrop sponsors", spread fake event pages, and ask you to connect a wallet and pay a "fee" or "deposit" to claim a prize — or steer you to a phishing site.

The choke point is whether an official event would ask you for money like that. It would not. The rules of official events are announced through official channels; they never ask you to pay before you can claim, and never ask for your private key.

How to check it yourself: do not verify it on the event page itself — go somewhere else and check. Open the official site or official app from your bookmark, find the same event in the announcements or events section, and only treat it as real if you can find it there with matching terms. If it is not in the official announcements, it is fake however convincing it looks. The hardest line to draw is the direction of money: a real event gives you something, it never turns around and asks you to pay a "fee", "deposit", or "unfreeze charge" first. Any "giveaway" that wants money out of you first should be skipped. More in the fake event entry.

9. Fake apps and fake extensions

Beyond fake wallets, there are fake "Binance" apps and browser extensions with interfaces made to look just like the official one; after you log in they send your username and password back to the scammer. Some show up on unofficial download sites or get installed via ads.

The choke point is the download source. Where you installed it from matters more than what the app looks like.

How to check it yourself: before installing, look at the "developer / publisher" field on the store page and check it is Binance's official name — if the name does not match, or it is some unfamiliar personal account, do not install it. Then look at two numbers: is the review count strangely low, and is the listing date very recent? A genuine official app has accumulated a lot of reviews and has been listed for a long time; a "Binance" that just appeared with a handful of reviews is almost certainly a clone. Same goes for browser extensions — check the publisher and the install count before adding one. The safest path is to only follow the download link the official website gives you, not ads and not third-party download sites.

10. Fake insider tips and guaranteed returns

"I have inside word, this coin pumps tomorrow." "Follow my trades, 30% a month." Messages like this prey on the wish to get rich fast. Behind them might be a pump-and-dump, a Ponzi scheme, or simply a funnel into one of the scams already described.

The choke point is the words "sure thing" and "guaranteed". The market carries risk by nature, and nobody can guarantee a return; whoever guarantees one is either lying to you or using your money to fill someone else's hole.

How to check it yourself: treat "guaranteed", "sure thing", "insider", and "follow and always win" as alarm words, and the moment you hear one, pull the conversation back a step — is the other side about to have you download some app, send money to some address, or join a trading group? If so, the pitch was the bait. Anyone with a genuine inside edge is not DMing strangers one by one to share it; whoever comes to you wants your principal, not your profit. Make your own investment decisions and understand them yourself; do not hand your money to a smooth-talking stranger. This site gives no investment advice — here we only talk about avoiding scams.

A few tells they all share

The ten tactics wear different shells, but break them down and they keep hitting the same few points. Memorise the signals below and you can measure any new variation with the same ruler — match any one of them and you should stop first, and you will almost never be wrong to.

  • They ask for your private key or seed phrase. This is the hardest line, with no exceptions. The seed phrase is the highest level of access to your wallet; anyone, for any reason — "sync", "verify", "upgrade", "support assistance" — who asks you to say it or type it into some page is trying to empty your wallet. Hear those words and the conversation can end.
  • They messaged you first. Real support responds after you start the conversation from an official entrance; it does not come knocking in your DMs. A stranger who suddenly messages, claims to be official, or "kindly warns you your account has a problem" is suspect on the "first contact" point alone.
  • They tell you to move funds to a "safe account" for verification. That phrase does not exist in any legitimate process. Funds in your own account are safe; no official side asks you to move money to another address to "protect", "verify", or "unfreeze" it — that is only luring you into sending money to a scammer yourself.
  • They rush you with a deadline and manufactured tension. "Your account freezes if you don't act." "Spots only last until tonight." "Transfer now or you'll be charged." Pressuring you so you cannot think or verify is the standard rhythm of a scam. Real matters do not give you only five minutes — the more they rush you, the more you should slow down.
  • The main domain of the URL is wrong. However polished the page, hover over the link and read the real URL; if the main domain (the two segments before the last slash) is not the official one, it is a fake site. Official words shoved to the front of the URL, and the real domain misspelled or pushed to the back, are the same tell.

These five are the lowest common denominator. You do not have to memorise all ten tactics — carry this ruler with you and it is enough. However well the other side performs, it is hard for them not to trip at least one.

A worked example: one fake-support attempt, start to finish

The tactics above are easier to hold onto if you watch one play out in order. Here is a composite of how a fake-support case usually runs — not a specific person's story, but the shape almost all of them share — with the point at each step where you could have stopped it.

It starts where you complained. You post in a group or a comment thread that you can't withdraw, and within minutes a friendly account DMs you: profile picture with a Binance logo, name reading "Binance Official Support". Stop point one: they messaged you first. That alone is enough to treat it as fake — real support does not open the conversation.

They build the pressure. "Your account is flagged for a suspected violation and has been temporarily limited; I can fast-track the unfreeze for you." The anxiety is the product — it makes you want to cooperate before you think it through. Stop point two: a manufactured deadline ("act within 30 minutes or it becomes permanent") is itself a tell, not a real constraint.

They ask you to "verify". First something that feels harmless — your account email — then the SMS code, then the login password, and on a wallet issue, eventually the seed phrase. Each request is dressed up as the next reasonable step, so it never feels like a single big ask. Stop point three, the hard line: the moment anyone asks for a code, a password, or your seed phrase, the conversation is over. No legitimate process needs them.

They reach for the money. If none of that has worked, the finale is "move your funds to a safe account while we investigate, then we'll move them back". Stop point four: there is no "safe account". Any instruction to move assets elsewhere to "protect" or "verify" them is the scam's last move.

Notice that the clean exit existed at step one — long before any money was at risk. You did not have to spot a clever forgery; you needed one habit: when someone contacts you first claiming to be official, check the account with Binance Verify and start any genuine support request yourself from inside the official app. Everything after that is just the script running its course, and any single stop point above ends it.

Cases people often misjudge

After reading about enough scams, some people swing to the other extreme: jumping at shadows, treating normal official actions as scams, and then being too scared to do the security steps they should. This section spells out a few normal situations that get misread, so you do not panic for nothing — or, conversely, skip something you really should finish because "it all looks suspicious anyway".

The official side does post announcements, but only through official channels. Binance launches features, adjusts rules, and runs events, so "seeing a Binance announcement" is not strange in itself. The point is not whether there is an announcement, but where you saw it. The same news appearing in the announcements section of the official site you opened from your bookmark, or in the official app, is normal; appearing in a link a stranger forwarded, a screenshot in a DM, or a group of unknown origin only counts once you have cross-checked it through an official channel. The axis is the source, not how convincing the content looks.

KYC really does ask you to upload documents, but only inside the official site or app. Identity verification is a compliance requirement, and it genuinely asks for documents and a selfie — that itself is not a scam. The problem is where you upload them: normally you do it while logged into the official website or app, inside the verification flow in account settings. If someone DMs you an external link telling you to "submit additional documents" or "re-verify", or tells you to send your ID photos straight to some "support agent", that is data theft. The same action is compliance in the right place and a scam in the wrong place.

Real support exists, but you start the conversation. Binance has support that can help with account issues, so "talking to support" does not mean you met a scammer. The difference is direction — did you click into it from the support entrance in the official app or website, or did it message you first? The former is normal; the latter is almost always fake. By the same logic, official emails are real too: once you have turned on the anti-phishing code, an email carrying your code is genuine, and you do not have to treat every Binance email as phishing.

One line to close: judging real from fake comes down to "who made first contact, through which channel, and which way the money flows" — not "is this thing normal". A normal thing through the wrong channel is just as dangerous, and a normal thing through the right channel is no reason to scare yourself.

A one-page self-defence checklist

Pull all ten together and a handful of habits block most of them:

  • Log in from a bookmark: bookmark the official site, go in through the bookmark every time, do not click search ads or stranger links.
  • Turn on the anti-phishing code: let official emails carry your custom code so a fake one is obvious at a glance.
  • Check identity with Binance Verify: for any account claiming to be official, check it first with the official verification tool.
  • Turn on two-factor authentication (2FA): use an authenticator app where you can, rather than SMS alone.
  • Keep the seed phrase offline and never type it into a web page: this is the floor beneath the floor.
  • Review and revoke wallet approvals regularly: clear out approvals to contracts you do not recognise.
  • Remember the three "nevers": the official side never messages you first, never asks for your seed phrase, and never tells you to move funds to a "safe account".

Turning these few into muscle memory is more useful than memorising a hundred scam scripts.

If it already happened to you, what next

If you only realised partway through reading that you may already be caught — you transferred funds, typed your seed phrase, or logged in on a suspicious page — do not panic, and do not shut everything down and pretend it never happened. Time matters, but the wrong move made in a panic makes it worse. Work through the items below, starting with whatever you can do right now:

  • Stop the bleeding first, cut off the risk. If you entered your Binance username and password on a suspicious page, open the official site from your bookmark immediately, change your password, and check whether your 2FA has been tampered with. If it is a wallet issue and your seed phrase may have leaked, the wallet behind that phrase can no longer be used — move whatever assets still move to a brand-new wallet with a clean seed phrase as fast as you can.
  • Preserve the evidence, do not delete it. Chat logs, the other party's account, the URL, the transaction hash (TxID), the receiving address, the timestamps — screenshot and keep all of it. These are the basis for reporting to the police and notifying platforms later; however angry you are, do not impulsively delete the conversation.
  • Notify the platform and report it quickly. Report the relevant accounts and addresses to Binance through official channels, and report the fraud to the authority for your country — in the US, the FTC (reportfraud.ftc.gov) and the FBI's IC3 (ic3.gov); in the UK, Action Fraud; in Australia, Scamwatch; in Canada, the Anti-Fraud Centre; anywhere else, your local police and national cybercrime portal. Crypto is rarely recoverable once moved out, but in a few cases — for example, when the funds are still sitting on the exchange and have not been withdrawn — a timely report can still get them stopped.
  • Do not get harvested twice by "recovery help". After an incident, people often appear claiming "I can get your money back" and asking for a fee up front — this is a second round of scam aimed at victims. Ignore it.

The full order of steps, the reporting entry points for each channel, and which materials to prepare are collected in the first 4 things to do after a scam — if it really happens, walk through it once.

Self-check list

The key points of the whole page, condensed into a list you can tick item by item. Read it now and then as a reminder; when a specific situation comes up, tick down it — if even one item fails, stop and verify before going on.

  • I only log in from a bookmark, not from search results or a link someone sent.
  • Before paying or logging in, I confirmed the main domain is binance.com, with no extra characters or prefixes.
  • I have not told my seed phrase, private key, or SMS code to anyone, nor typed them into any web page.
  • Any account that contacted me first claiming to be official, I checked with Binance Verify, and only continued if it showed up.
  • I did not move funds to a "safe account" or address because of an "account anomaly" or "limited time" story.
  • Before signing in my wallet, I read the window contents and did not hit "Approve" on a page of unknown origin.
  • I only download apps and extensions from official links or official stores, checking the developer and reviews first.
  • 2FA is on, using an authenticator app rather than SMS alone where possible.
  • I review my wallet approvals regularly and revoke any to contracts I do not recognise.
  • When I hear "guaranteed", "sure thing", "insider", or "follow and always win", I automatically treat it as an alarm, not an opportunity.
Hands-on notes from the desk

We've actually used both of these features a round ourselves. "Binance Verify" is where you paste in the other side's account, email domain, or whatever URL they sent you and check it — it only counts if the official side has it on record. The anti-phishing code is a secret token you set in your account security settings, so that emails from the official side carry it. What actually trips people up isn't the operation — it's remembering to stop and check in the moment someone's rushing you; the best feature in the world does nothing if you forget to use it under pressure. The names and locations have moved more than once, so we don't hard-code menu paths here — go by the official interface you see after logging in.

What really deserves your attention are these three steps: one, check the address bar for the official domain, and if it is wrong do not go on; two, the moment any "enter your seed phrase / private key / verification code" request appears, stop, however reasonable the reason; three, "transfer first and then we can fix it" simply does not exist in any official process — hear it and it is an alarm.

FAQ

If I have been scammed, can I get the money back?

Crypto is hard to recover once it has been moved out, but there are still things worth doing — preserve the evidence, report it to the police quickly, and notify the relevant platforms; in a small number of cases you can still limit the loss. The specific steps are in the first 4 things to do after a scam.

I am new to this. What should I do first?

Set up a few security switches on your account first, then start trading small. See the security setup for week one.

How do I confirm whether someone claiming to be "Binance support" is genuine?

Two things: the official side never messages you first, and you check the person's account with Binance Verify. If it does not show up, it is fake.

Is it safe to click a Binance link a friend forwarded?

Treat it like any other link, even from someone you trust — your friend may have been phished and forwarded a fake page without knowing. Don't log in or connect a wallet through a forwarded link. Open the official site from your own bookmark instead, or run the URL through our domain checker first.

How can I tell a real Binance email from a fake one quickly?

The fastest check is the anti-phishing code: once you set one in your account security settings, every genuine official email carries it, and one without it is fake — no need to squint at the sender address. As a second check, hover over any button and read the real link; if the main domain isn't binance.com, don't click. When in doubt, ignore the email and open the official site from your bookmark to read your notifications there.

2026-06-22 · Entry created; ten tactics and a self-defence checklist compiled.