Let's get straight to the point: a Binance phishing site and the real thing look almost identical, but the URL domain is always different. Binance's genuine official domains are binance.com, accounts.binance.com, and www.binance.com. Any domain with even the slightest spelling deviation (binance-1.com, b1nance.com, binnance.com, binance.org, and so on) is a phishing site. This article covers 4 common phishing patterns and how to spot each one. Always enter through the Binance Official Site link; app users should download the Official Binance App only from a trusted tutorial site or app store; iOS users should refer to the iOS install guide.
Phishing sites steal massive sums from Binance users every year. Scammers copy Binance's entire web page — code, fonts, images, color scheme — and the resulting fake site is indistinguishable to the naked eye for most users. But there are 4 tell-tale signs that a phishing site can never fully escape. Let's break each one down.
Scammers register a domain that looks like binance.com to run their phishing operation.
| Type | Example | Real Domain |
|---|---|---|
| Added hyphen | binance-1.com | binance.com |
| Added suffix | binance-login.com | binance.com |
| Character substitution | b1nance.com (1 instead of i) | binance.com |
| Character duplication | binnance.com (extra n) | binance.com |
| Different TLD | binance.org / binance.cc / binance.shop | binance.com |
| Subdomain trap | binance.com.fakedomain.com | binance.com |
| Country-code TLD | binance.cn / binance.com.cn | binance.com |
The key test: is the part right before the very last dot actually binance.com?
binance.com → realaccounts.binance.com → real (accounts is a subdomain of binance.com)binance.com.cn → fake (the actual domain is com.cn, not binance.com)binance-pay.com → fake (the domain is binance-pay.com, not binance.com)Point your cursor at the browser's address bar, find the / in the URL, and count leftward from it: the segment between the last two dots must read binance.com for the site to be real.
Examples:
https://www.binance.com/en/login → last part is .com, second-to-last is .binance → realhttps://login.binance-vip.com/aaa → last part is .com, second-to-last is .binance-vip → fakeMany users assume that a padlock icon in the address bar equals "safe." That's a mistaken assumption.
Any domain can obtain a free SSL certificate (Let's Encrypt issues them for free). After registering binance-fake.com, a scammer can get an HTTPS certificate up and running within half an hour, complete with a green padlock in the browser.
A padlock only means "your connection to this website is encrypted" — it does not mean "this website is the official Binance."
Once on a site, click the padlock icon to the left of the address bar and select "Certificate Valid" or "Certificate Details."
A genuine Binance certificate is issued to:
*.binance.com or binance.comA phishing site's certificate is issued to:
The "subject" field of a certificate determines which domain has actually been verified.
Scammers buy ad placements on Google and Bing for keywords like "Binance official site." When you search "Binance official site," the very first result marked "Ad" is quite likely a phishing site.
A user searched for "binance," clicked the first result on a search engine marked "Ad," was redirected to a phishing site at binance-cn.org, entered their account credentials, and had their account emptied within 5 minutes.
Method 1: Bookmark it directly
The first time you visit the genuine official site, immediately press Ctrl+D to bookmark it, then always enter through the bookmark from then on.
Method 2: Go through a trusted tutorial site's link
Every "Binance Official Site" link on this site has been verified and will take you straight to the genuine binance.com site.
Method 3: Never click the first search result marked "Ad"
The "Ad" slot in search results is paid placement, purchased by whoever's willing to pay. Look at the second or third organic result that isn't marked as an ad first.
Method 4: Type the URL manually
Type binance.com directly into your browser's address bar and press enter. This is the least error-prone method of all.
Phishing links are usually sent via email, SMS, or social media.
Disguise 1: Shortened links
Link shorteners (bit.ly, t.co, and similar) can wrap any URL into a short bit.ly/xxx format, so hovering your cursor won't reveal the real destination. Before clicking, run the shortened link through a service like unshorten.it to see where it actually leads.
Disguise 2: HTML anchor-text spoofing
An email might read [Click here to go to the Binance official site](https://binance-fake.com) — the visible text says "Binance official site," but clicking takes you to a fake site. Hover over the link first and check the real URL that appears at the bottom of your browser before clicking.
Disguise 3: Multi-layer redirects
Link A → redirects to link B → redirects again to phishing site C. This chain of redirects hides the true destination. Modern browsers like Chrome and Firefox will show the full redirect chain, but many users never notice it.
Disguise 4: Mobile-screen disguise
On a narrow phone screen, URLs get truncated. A scammer's link might be binance.com.evil.com, but on a phone it displays as binance.com.evi..., which looks like binance.com at a glance. Always long-press a link on mobile to see its full URL before tapping it.
| Pattern | Characteristic | How to Spot It | Defense |
|---|---|---|---|
| Domain spoofing | URL spelling deviation | Check the full domain | Bookmark the official site |
| SSL disguise | Fake sites can have a green padlock too | Check the certificate's subject | Don't rely on the icon alone |
| Ad poisoning | First result in search | Skip the ad placement | Type the URL directly |
| Link disguise | Shortened links in email/SMS | Hover to see the real URL | Don't click unfamiliar links |
If you accidentally click a phishing link and enter your account credentials, here's the scammer's typical playbook:
Step 1: Real-time theft
The username and password you type are transmitted to the scammer's server instantly. At the same time, the fake site displays "Incorrect password, please try again," so you think it's just a network glitch.
Step 2: Attempting to log into the real Binance
The scammer takes your credentials and tries logging into the real Binance. If you haven't enabled 2FA, this succeeds immediately.
Step 3: Triggering a 2FA bypass
If you have 2FA enabled, the fake site redirects you to a "2FA Verification" page asking for the 6-digit code from your Authenticator app. You assume it's Binance asking, enter it, and that code gets stolen too.
Step 4: Logging into the real Binance within 30 seconds
Your 2FA code is only valid for 30 seconds. The scammer immediately enters your username, password, and 2FA code on the real Binance login page and gets in.
Step 5: Cashing out
Once logged in, they immediately convert your spot holdings into USDT and withdraw it to an on-chain wallet. The whole process takes 5-10 minutes.
This is exactly why the whitelist feature matters so much — its 24-hour cooling-off period is what blocks this kind of "rapid cash-out."
If you realize the site you just entered your credentials on wasn't the real Binance:
Completing all of the above within 5-30 minutes gives you a good chance of keeping your account safe.
Q: How many official domains does Binance have?
A: The main domain is binance.com, and subdomains including accounts.binance.com, www.binance.com, and api.binance.com are all genuine. Variants like binance.org, binance.cn, and binance.shop are not official Binance domains.
Q: Where's it safe to download the official Binance app installer? A: iOS users should use the US or Hong Kong App Store. Android users should use Google Play, the official Binance website's download page, or this site's official download link. Never install a package from a third-party app store, cloud drive share, or email attachment.
Q: Can I trust the "official" badge shown next to search results for "binance"? A: Search engines' "official" verification badges are sometimes a paid "verification service" scammers can also purchase — don't trust it blindly. Always verify the domain itself.
Q: Is searching for Binance on Google safer than on Baidu? A: Relatively speaking, yes — Google filters phishing sites more aggressively. But Google's ad slots can still carry phishing links too, so avoid the ads and stick to organic results.
Q: Is it safe to add a "Binance official support" contact I found in a Telegram group? A: No. Binance never DMs users first on Telegram. Anyone in a Telegram group offering to "add you and connect you with support" is a scammer. Binance support only operates through the "Live Chat" channel inside binance.com.
Q: How do I report a phishing site if I find one? A: Submit a "Report Phishing Site" ticket through the Binance official site's Help Center, providing the URL. Binance will file takedown requests with the domain registrar and search engines, typically taking the site down within about 48 hours.
Q: Can my browser's built-in "Safe Browsing" feature block phishing sites? A: It blocks some of them. Chrome, Firefox, and Edge all have built-in phishing-site blocklists. But a brand-new phishing site takes a few days to get added to those lists, leaving a window where you're not protected.
Q: Will phishing sites try to get me to download a file? A: A few will. If a site asks you to "download the Binance client .exe or .apk," what you download is almost certainly malware. Binance's official desktop client is only available for Windows/Mac, downloaded from the official site's download page.
Make it a habit to verify the domain on any page that asks for your password — it's the first line of defense for your Binance account's security.