Let's get straight to it: the first minute after you discover your Binance account has been hacked decides whether you can recover your funds. Do these 5 things immediately — lock the account, change your password, disable every API key, revoke any newly-added whitelist addresses, and contact Binance support. Every minute you delay gives the hacker one more minute to move your assets. Log in urgently through the Binance Official Site to handle it right away; if you suspect your computer has been compromised, switch to the Official Binance App on a different device; iPhone users should check the iOS installation guide to install the app.
The most common warning signs of a hacked Binance account are: a sudden "withdrawal successful" email, an unfamiliar IP address in your login notifications, a new API key you didn't create, or your balance changing in ways you can't explain. The moment you see any of these signals, don't hesitate for even a second — work through the 5 steps below immediately.
Both the Binance app and website have a one-tap account lock feature, which is the fastest way to stop the bleeding.
On the website:
Log in to the Binance website → click your avatar in the top-right corner → "Security" → scroll to the bottom to find "Lock Account" → click "Lock Now".
In the app:
Open the Binance app → tap your avatar in the top-left corner → "Security Settings" → scroll to the bottom → "Lock Account" → confirm.
Once locked, all trading, withdrawals, and API calls are stopped instantly. Even if a hacker is already logged into your account, they will not be able to move any more assets out. Locking doesn't require 2FA — only an email verification code — so you can still lock the account even if your 2FA has been compromised.
The lock takes effect in roughly 5 seconds, so execute it first.
After locking the account, go straight to "Account" → "Change Password". Your new password should meet these requirements:
Changing your password requires an email verification code plus your old password. Once changed, every currently logged-in device is forced offline, immediately invalidating the hacker's session.
If your email has also been compromised (hackers often breach the email first, then the Binance account), go change your email password and enable 2FA on your email provider first, then come back and change your Binance password. Otherwise the change is pointless — the hacker can simply request another verification code through your email again.
In many hack cases, the attacker never logs in directly — they use a stolen API key to quietly move assets instead. An API key can place orders and transfer spot assets without going through 2FA at all.
Steps:
It's better to delete everything by mistake than to miss even one compromised key. If you genuinely need an API later, create a new one and set an IP whitelist and proper permission scope for it.
If you previously enabled a withdrawal address whitelist (strongly recommended), a hacker who compromised your account may have quietly added their own wallet address to it, then waited out the 24-hour cooling-off period before withdrawing.
Steps:
If you never set up a whitelist yourself but strange addresses have appeared in it, it's almost certainly the work of a hacker. Delete everything and re-add only your own addresses.
Completing the first 4 steps will generally stop the bleeding; step 5 is about recovering funds and preserving evidence.
Contact Binance support:
Binance's risk team can freeze related transactions and cooperate with police to trace the flow of funds. If the hacker moved funds to another account within Binance, Binance can freeze that receiving account directly. If the funds were moved to an external on-chain wallet, Binance can provide on-chain evidence but cannot intercept the funds directly.
File a police report:
Once police open a case, they can request detailed data from Binance through legal channels. Binance has a dedicated law-enforcement assistance channel, and the recovery probability after a formal case is opened is much higher than a plain support complaint.
| Order | Action | Where | Time Needed | Necessity |
|---|---|---|---|---|
| 1 | Lock the account | Security → Lock | 30 seconds | Mandatory |
| 2 | Change password | Account → Change Password | 2 minutes | Mandatory |
| 3 | Delete all API keys | Account → API Management | 2 minutes | Mandatory |
| 4 | Clean up whitelist | Security → Whitelist | 1 minute | Mandatory |
| 5 | Contact support + file report | Live Chat + police | 30 minutes | Strongly recommended |
In total, the first 4 steps can be completed within 5 minutes of urgent handling. Step 5, contacting support and filing a report, may take longer.
Once you've calmed down after being hacked, you absolutely need to review how it happened, or you'll simply be hacked again after changing your password. Here are the 5 most common vulnerabilities:
Phishing site: The site you entered your password into wasn't the real Binance. Check whether the URL is actually binance.com and not something like binance-1.com or b1nance.com.
Compromised email: The hacker breached your email first, then used "Forgot Password" to reset your Binance account. Your email must have 2FA enabled and must not reuse a password from any other site.
Clipboard malware: Malicious software on your computer or phone silently monitors your clipboard, uploading anything you copy that looks like a password. Run a full scan with antivirus software.
SIM swap attack: The hacker socially engineers your carrier's support staff into issuing a duplicate SIM card for your phone number, letting them intercept SMS verification codes. This is exactly why 2FA should use Google Authenticator rather than SMS.
Leaked API key: You pasted your API key into a third-party website for price tracking or grid trading, and that site used it to drain your spot assets. Never enter your API key into a site you don't fully trust.
Based on public case data and Binance's annual security reports:
Binance's own SAFU fund (Secure Asset Fund for Users) only covers losses from a hack of Binance itself — it does not cover individual accounts being compromised. This is exactly why prevention always matters more than remediation.
Once you've confirmed all 5 urgent steps are done and you're ready to start using the account again, run through a full checkup one more time:
Q: If all the assets in my account have already been transferred out, can they still be recovered? A: It depends where the hacker sent them. Moved to another account within Binance: support can freeze it. Moved to an on-chain exchange (OKX/Coinbase): there's a chance of recovery through law-enforcement cooperation. Moved through a mixer: essentially unrecoverable. Filing a police report right away and getting a case opened is the key factor.
Q: How do I unlock my account after locking it? A: Log in to the Binance website → Live Chat → submit an "Account Unlock Request" → complete facial recognition plus video identity verification → wait 3-7 business days for review. The assets in your account are safe during this period.
Q: Will the hacker who's already logged in be kicked out once I change my password? A: Yes. Changing your password on Binance forces every session to re-authenticate. But if the hacker has already set up an API key or whitelist address, simply changing your password won't stop them from using that API — which is exactly why step 3 (deleting all API keys) is mandatory.
Q: Why do I need to change my email password too? A: Many account-takeover chains start with the email being compromised first, then the attacker resets your Binance password using it. If you don't change your email password, the hacker can simply repeat the reset process at any time.
Q: Will the police actually take the report seriously? A: Yes. Cryptocurrency theft is recognized as a legitimate property loss, and law enforcement agencies have dedicated cybercrime units that handle these cases. It's worth filing a report even for relatively modest losses.
Q: How does an Authenticator code even get stolen? A: It could be spyware installed on your phone, you being tricked into entering your 2FA code into a fake Binance app, or you having granted remote access to someone who saw your screen. Authenticator itself isn't connected to the internet — theft of a code is almost always the result of social engineering.
Q: How do I avoid being hacked again in the future? A: The essential four-piece combo: Google Authenticator 2FA + anti-phishing code + withdrawal address whitelist + good phishing hygiene (don't click email links, don't download unofficial apps, put an IP whitelist on every API key). None of these are optional.
One final piece of advice: the moment you discover you've been hacked, don't hesitate and don't go asking others first — follow the 5 steps above immediately. Every second matters.