The bottom line first: if you spot a withdrawal request on your Binance account that you never made, do three things immediately — go to your withdrawal history and click "Cancel" on the unconfirmed order, lock your account to block further activity, and change your password while deleting your API keys and whitelist entries. A withdrawal can be canceled up until its status changes to "broadcast on-chain" — the earlier you catch it, the better your odds of success. Go to the withdrawal history on the Binance Official Site first; app users can move faster with the Official Binance App; iPhone users should reference the iOS Installation Guide.

If you receive a "withdrawal initiated" email alert that you never triggered yourself, it means your account has already been compromised. Below is a full emergency response — every second counts, and you're racing against whoever has control.

Assess Urgency: Check the Withdrawal Status

Before you start canceling, check the current status of the unfamiliar withdrawal:

Status Meaning Can it be canceled
Pending review Binance risk control is reviewing it Yes
Email verification pending Waiting on user email confirmation Yes
Processing Binance is preparing to broadcast on-chain Yes
Broadcast on-chain Already broadcast to the blockchain No
Confirmed Confirmed on-chain No

Binance's standard withdrawal flow is: user initiates → email confirmation → risk review → on-chain broadcast → on-chain confirmation. The first three steps can still be stopped; once the fourth step begins, the funds are unrecoverable.

Fortunately, Binance requires email confirmation on every withdrawal by default. If the attacker doesn't have access to your inbox, the withdrawal will stay stuck at "email verification pending" and can't proceed.

Step 1: Go to Withdrawal History and Cancel Immediately

Log in to your account via the Binance website or app.

Web path:

Wallet → Withdraw → Withdrawal History, which shows all recent withdrawal requests — find the unfamiliar one.

App path:

Wallet → Spot → History → Withdraw, then find the unfamiliar record.

Tap that record, and if a "Cancel" button appears (it shows up when the status allows it), tap it immediately.

Canceling may require 2FA verification — enter your 6-digit Google Authenticator code. Once submitted, the withdrawal order's status changes to "Canceled" and the funds return to your account balance.

Step 2: Lock Your Account Immediately

After canceling one withdrawal, the attacker could initiate another one right away. That's when you need to lock your account to block all further activity.

Path:

Security → scroll to the bottom → tap "Lock Account" → enter the email verification code → submit.

Once locked, all trading, withdrawals, and API calls stop entirely. This is the core action that stops the bleeding.

Locking doesn't require 2FA (in case your 2FA has also been compromised and you'd otherwise be locked out) — an email code alone is enough to lock the account.

Step 3: Change Your Password and Delete All API Keys

Once locked, immediately address your account access rights:

Change password:

Account → Change Password → set a new password (at least 16 characters, strong) → enter your old password + email code + 2FA. This invalidates every currently logged-in session.

Delete all API keys:

Account → API Management → click "Delete" on every single key → verify with email code + 2FA.

It's better to delete everything, even by mistake — you can always recreate an API key later. A compromised account very likely has API keys the attacker added.

Clear the whitelist:

Security → Withdrawal Address Whitelist → click "Delete" on every address you don't recognize → verify with email code + 2FA.

Attackers commonly add their own address to your whitelist first, then wait out the 24-hour cooling-off period before initiating a withdrawal. Remove every unfamiliar address completely.

Step 4: Contact Binance Support and Report the Incident

After completing the three steps above, the fourth step is to report the incident to customer support and preserve evidence.

What to do:

Go to Live Chat → select "Account Compromised" → provide:

Binance's risk team will:

  1. Help investigate how the account was compromised
  2. Freeze the attacker's account if the funds went to another Binance account
  3. Provide the on-chain transaction ID for you to use when filing a police report
  4. Help you unlock and recover your account

Step 5: A Full Security Self-Check and Filing a Police Report

Filing a report:

Full security self-check list:

5-Step Emergency Timeline

Order Action Where Time needed
1 Cancel the pending withdrawal Wallet → Withdrawal History 30 seconds
2 Lock the account Security → Lock 30 seconds
3 Change password + delete API keys + clear whitelist Account + Security 5 minutes
4 Contact support and report Live Chat 10 minutes
5 File a police report + full self-check Police station + security settings 30 minutes

The first three steps must be completed within 5 minutes. Steps 4 and 5 can move a bit slower, but must be done the same day.

If the Withdrawal Has Already Been "Broadcast On-Chain"

If you discover the issue late and the withdrawal already shows "Broadcast On-Chain" or "Confirmed," the on-chain transaction is irreversible. At this point:

1. Record the full details:

2. Trace on-chain:

Paste the TXID into a block explorer (Tronscan, Etherscan, BSCscan, etc.) to trace where the funds moved next.

3. Notify every possible receiving platform:

If the attacker moved the funds to another exchange (OKX, Bybit, Coinbase, etc.), immediately:

4. Wait for law enforcement to get involved:

Once a case is filed, Binance and other exchanges can freeze related accounts through official law enforcement channels. This process typically takes anywhere from several weeks to several months.

5. On-chain mixing is essentially untraceable:

If the attacker routes the funds through a mixer like Tornado Cash, the trail effectively goes cold.

How Attackers Initiate Unfamiliar Withdrawals

Let's walk through this to understand the vulnerabilities and avoid a repeat. The most common attack paths:

Path 1: Phishing site steals your password + 2FA

You click a fake Binance link and enter your password and 2FA code. The attacker immediately logs into the real Binance account, adds a whitelist address, and initiates a withdrawal.

Path 2: Your email gets compromised

The attacker breaches your email first (often because you reused the same password, or your email doesn't have 2FA enabled). They then use "Forgot Password" to reset your Binance account and confirm the withdrawal directly from your inbox.

Path 3: API key leak

You pasted your API key into a quant platform or grid bot, the platform gets hacked (or an employee acts maliciously), and the leaked key is used for wash trading and withdrawals.

Path 4: Clipboard-hijacking malware

Your computer or phone is infected with malware that monitors everything you copy — passwords, 2FA codes, addresses.

Path 5: SIM swapping

The attacker social-engineers your carrier's customer support into issuing a duplicate SIM card for your number, intercepting your SMS verification codes. This is exactly why 2FA should use Google Authenticator instead of SMS.

Preventing This From Happening Again

Once the emergency is handled, it's time to close the underlying gaps:

1. Turn on all three: Google Authenticator 2FA + anti-phishing code + withdrawal address whitelist

2. Give your registered email its own 2FA and a unique password

3. Restrict API keys to an IP whitelist + disable withdrawal permission on API keys

4. Never click links in emails, texts, or social media messages

5. Only download the Binance app from an app store or this site's official links

6. Install antivirus software on your computer and run a full scan monthly

7. Move large holdings to a hardware wallet for cold storage (Ledger/Trezor)

FAQ

Q: How long does canceling a withdrawal take? A: Canceling takes effect immediately — the status changes from "Pending Review" or "Email Verification Pending" to "Canceled," and the funds return to your account.

Q: Will an unconfirmed withdrawal cancel itself if I don't confirm the email? A: Yes. Binance withdrawals require email confirmation within 24 hours by default, or they're automatically canceled. But if an attacker has also compromised your email, they can "confirm" the withdrawal for you.

Q: Will Binance compensate stolen assets? A: Generally, no. Binance's SAFU fund only covers losses from Binance itself being hacked, not individual accounts being compromised. But if the loss was caused by a Binance system vulnerability, compensation may apply.

Q: My account is locked but I still see a withdrawal in progress — what do I do? A: Locking the account doesn't cancel a withdrawal already in progress; you need to cancel it separately. Cancel first and then lock, or handle both at the same time.

Q: Canceling fails with "status doesn't allow cancellation" — what now? A: This means the withdrawal has already been sent on-chain and can't be canceled. Immediately record the transaction ID and follow the "Broadcast On-Chain" process above.

Q: Can the police actually recover stolen assets? A: It depends on what the attacker did next. If the funds are still on an exchange (Binance, OKX, Bybit, etc.), law enforcement assistance has a real chance of freezing and recovering them. If the funds went to an on-chain wallet or a mixer, the odds of recovery are very low. Filing early with complete evidence is key.

Q: The unfamiliar withdrawal is a small amount (like 1 USDT) — does it still need urgent action? A: Yes. A small withdrawal may just be an attacker's "test" to confirm that withdrawals work, with a larger one to follow. Any unfamiliar withdrawal needs to be taken seriously.

Q: I get a withdrawal notification every time I log in — how do I turn it off? A: We recommend never turning this off — it's the key signal that alerts you to a compromised account. If the emails feel like too much, turn off "marketing emails" instead, but keep security alert emails on.

An unfamiliar withdrawal is the strongest possible signal that your account has been compromised. Every second matters — follow the 5 steps in this article immediately.