To log in to an exchange, always go in from a bookmark — this habit beats any antivirus
Many people who get robbed had nothing technical broken at all; they simply "went in the wrong door": out of habit they typed "Binance login" into the search box, clicked the first result, entered their credentials — and that was a fake site that bought an ad. Fix the login entry point as a bookmark and you bypass this whole class of trap. This page lays out why, and how.
Why not to go in via search
"Find a site by searching" is most people's years-old internet instinct, but for logging in to an exchange, that instinct will hurt you. There are three layers to why.
First, the top of search results is often an ad. Scammers buy keyword ads so their fake site ranks at the top for searches like "Binance login", with title and description made to match the official one. You click the top one out of habit, and step straight into a fake.
Second, a fake site's URL differs from the real one by only a little. It might swap one letter, add a tail, or use a near-identical glyph to confuse. The page appearance is copied wholesale from the official site, so as you log in you can't tell the difference, and your credentials are handed over just like that. More on spotting fake exchanges is in how to spot a fake exchange.
Third, every search is a fresh gamble. Even if you get it right by luck this time, next time the result order changes, a new ad-bought fake appears, and you still have to judge afresh each time. Driving the number of judgements down to zero is the steady approach — and the bookmark is exactly that answer: set it once, then click the same confirmed-correct entry every time.
People often push back: "Can't I just glance at the URL each time?" The trouble is that logging in is a high-frequency, often-distracted action — you're rushing to check prices, you tap a notification on reflex, the text is small on a phone. Relying on focus each time to catch that one or two swapped letters means sooner or later you'll miss one, and missing once can cost the whole account. Safe design lets you "not have to judge correctly every time", and the bookmark is how you do that judgement once and stop depending on in-the-moment attention afterward.
How to set and use the bookmark
It's simple, but there's an order you can't get wrong: you must first be sure that this time you've reached the real official site, then save it as a bookmark. After that, keep using this confirmed bookmark.
First time: confirm, then save
Reach the official site once by a reliable means — for example get the official URL from a source you trust and have verified — carefully check the address is correct, confirm it's the real site, then use your browser's "add bookmark" to save it (on a computer this is usually the star beside the address bar, or the bookmark shortcut). We'd suggest putting it on the bookmarks bar so it's a single click away at login.
After that: always click the bookmark
From then on, to log in to the exchange, click that bookmark, every time. Don't type in the search box again, don't click links in email or messages. Make it muscle memory: want to log in → click the bookmark, with no search and no link from anyone in between.
A few small reminders
- Set it on your phone too: mobile browsers can bookmark or add to the home screen just the same — don't go in via search on a phone. A small screen with the address bar often hidden makes telling real from fake by eye even harder, so a phone needs a fixed entry point all the more.
- Same for the official app: download the app only from the link on the official website or the official app store, and once installed, just open the app rather than going through the web each time.
- Check the bookmark itself periodically: occasionally open it to glance at the address it points to, to make sure it hasn't been altered.
- Don't rely on autofill as your judgement: a password manager usually only autofills when the domain matches, which you can take as a supporting signal — if a page that should autofill doesn't, be alert. But it's a support, not a replacement for reading the URL and using the bookmark.
By the way, logging in is about more than "where you go in from"; there's also "what stands guard once you're inside". Even if you do one day slip into a fake site and type your credentials, if you've already turned on two-factor authentication an attacker with only your credentials usually can't get past it; and a withdrawal whitelist means that even if they get in, they can't withdraw to an unknown address. The bookmark is the first door, and these are the backup lines behind it — how to set the whole set up is in the beginner security setup referenced below.
How to tell at a glance whether a URL is right
Even with the bookmark habit, knowing how to read a URL is still basic skill — in case you're one day on another device, or accidentally click a link, you need to be able to judge real from fake on the spot. Watch these points:
- Look at the "main domain", not the words in front: what really decides which site you're on is the main domain at the far right (for example, the example.com in example.com). Scammers often stuff the official wording into a subdomain or path in front — for instance putting "binance" at the start of a long string while the real main domain is some other, unfamiliar name. Read from right to left and identify that main domain.
- Compare the spelling character by character: watch for a missing letter, an extra letter, or a near-identical glyph swapped in (this kind of confusion is easy for the eye to slide past).
- Be wary of odd tails and extra segments: an official domain is clean; fake sites often tack on a pile of strange words or symbols.
- Don't go by the padlock alone: the padlock in the address bar only means the connection is encrypted, not that this is the official site — a fake site can have a padlock too. The padlock is no proof that "this is the real site".
Drill "right to left, identify the main domain, compare spelling character by character" into a reflex, and a suspicious link won't fool you with surface-level official wording.
Pairing it with the look-alike domain checker
Eyeballing sometimes goes wrong, especially with near-identical glyphs. So we built a small tool to help you keep guard: the look-alike domain checker. Paste in the address you're unsure of and it sets it side by side with the official domain, helping you check character by character whether letters have been swapped, a tail added, or something else tampered with.
When to use it? When an email or message has a link, or when you're on an unfamiliar device with no bookmark to hand and need to log in — drop the address in for a comparison first, which is steadier than guessing by eye. It's especially good for the kind of address that "looks completely fine at first glance" — the human brain auto-fills as it reads, taking a very similar spelling as correct, while the tool compares one character at a time and isn't fooled by visual habit. Of course, the easiest approach is still to use the bookmark all along — the tool is a backup, the habit is the main defence.
A companion: the anti-phishing code
The bookmark governs "how you reach a site"; the anti-phishing code governs "how a fake email tricks you into clicking a link" — together they're more complete. The anti-phishing code is a secret token you set in your Binance account security settings; once set, the emails the official side sends you all carry it, and an "official email" without that code is fake, so you naturally won't go and click the links inside it. How to set it and more email-spotting detail is in fake official emails and phishing mail. How to set up the whole set of account-security switches at once is in the beginner first-week security setup.
Saving the official site as a bookmark and entering from it every time — we did this on both desktop and mobile. Honestly there's nothing to it: every mainstream browser can tuck a confirmed URL into the bookmarks bar or home screen; the hard part is building the habit of not reaching for search out of reflex. Two things we'd flag from doing it: read a URL by identifying the main domain at the far right and comparing the spelling character by character; and that padlock in the address bar only means the connection is encrypted, not that the other side is official. Where "add bookmark" sits varies a little between browsers, so we don't hard-code the steps here — just follow the interface of whatever browser you're on.
What's truly worth turning into reflex are three confirmation points. First, did you actually come in from the bookmark this time, rather than reaching for search on reflex? This is where most people's habit breaks. Second, is the main domain at the far right correct, and has the spelling been tampered with? Read right to left. Third, don't treat the padlock as a guarantee of a real site — the most commonly trusted mistake. If any point feels off, stop, and put the address into the checker before going any further.
FAQ
I'm used to using search. Does it really make a difference?
Yes, a big one. The top of search results is often a fake site that bought an ad, looking almost identical to the official one; switching to a bookmark turns "judge real or fake every time" into "click an entry you've already confirmed is correct", and the whole class of phishing sites is bypassed.
There's a padlock in the address bar — doesn't that mean it's safe?
No. The padlock only means the connection between you and that site is encrypted; a fake site can have a padlock too. It can't serve as proof that "this is the official site" — real or fake still comes down to the main domain and the spelling.
I need to log in on a friend's computer and don't have my bookmark. What do I do?
Avoid logging in to an exchange on an unfamiliar device where you can. If you really must, first put the address into the look-alike domain checker to confirm it character by character, watch for new-device verification after logging in, log out when done, and check your account activity once you're back on your own device.
Could a bookmark be changed?
It won't normally change on its own, but occasionally opening the bookmark to glance at the address it points to and confirm it's still right is a good habit that costs almost no effort.