If you receive an "unfamiliar device login" email from the Binance Official Site or a push alert from the Official Binance App, what matters most is what you do in the next 5 minutes; if you've never used the app before, install it first using the iOS installation guide and then handle the alert. Here's the response process laid out in chronological order.
Binance triggers an "unfamiliar device login" notification in situations like these: you switched to a new phone, used a new browser, connected to a new network, cleared your browser cache, switched IP addresses through a VPN, or changed your system clock. None of these mean you've actually been hacked — they just mean your device fingerprint changed.
Here's how to tell whether it's a false alarm: the email body shows the "login device" (e.g., iPhone 15 Pro / Chrome on Mac), the "login IP," and the "login location." Compare that against what you actually just did.
If you think "I just logged in from my Mac a minute ago," that's you. If it shows "Android / Moscow, Russia" and you've never been to Russia while living in China, that's a genuine unfamiliar login.
| Alert Details | Likely Cause | Risk Level |
|---|---|---|
| Your usual device | Device fingerprint changed | Low |
| Your usual country, new device | New install or new browser | Low-medium |
| Your usual country, new IP | VPN or network switch | Low-medium |
| Unfamiliar country + unfamiliar device | Genuine unfamiliar login | Extreme |
| Multiple locations in a short time | Account compromised | Extreme |
| Unfamiliar device + large withdrawal | Actively being drained | Extreme |
If you've confirmed it's a genuine unfamiliar login, immediately go to "Account - Security - Logged-in Devices" and kick the unfamiliar device offline with one tap. This step doesn't require a password — any logged-in user can kick any device offline.
After kicking the device offline, immediately go to "Account - Security - Emergency Freeze." This freezes withdrawals, internal transfers, API key creation, and changes to security settings or KYC information on your account, while keeping login, account viewing, and spot trading available.
The emergency freeze is a temporary measure — you can unfreeze it yourself once you've finished your follow-up review. While frozen, your funds are 100% safe from being stolen.
Once the emergency freeze is in place, the next step is changing your password. Your new password should:
After changing your password, go to "Security - Google Authenticator" and reset your 2FA. This invalidates your old 2FA entirely, so even if the attacker has your old 6-digit code, it won't work anymore.
If the attacker recovered your password through your email, you need to confirm your email itself hasn't been compromised. Check your email's "logged-in devices" and "recently sent" folder. If your email has also been breached, secure your email first before dealing with Binance.
Go to "Wallet - Transaction History - Withdrawal History." Look at the past 24-72 hours for any withdrawal requests you don't recognize. If you find one, immediately hit "Cancel" on that withdrawal's detail page — as long as it's still under review.
Here are the stages a Binance withdrawal goes through:
| Withdrawal Status | Cancelable? | Funds Safe? |
|---|---|---|
| Under risk review | Yes | Yes |
| Awaiting email confirmation | Yes (don't click the confirmation link) | Yes |
| On-chain transaction initiated | No | No |
| Confirming on-chain | No | No |
| Completed | No | No |
Binance withdrawals require a second confirmation by email, so even if an attacker is logged into your account, they can't withdraw funds without access to your email. That's exactly why "email security ≥ Binance account security." If your email password is weak or matches your Binance password, change both right away.
Once an attacker gains access to an account, they may attempt to:
Go through and restore each one:
| Item to Check | Path | Expected State |
|---|---|---|
| API list | Account - API Management | No unfamiliar API keys |
| Withdrawal whitelist | Wallet - Withdraw - Address Management | Only addresses you recognize |
| Payment methods | Fiat - Payment Methods | Only your own bank card |
| Account - Security - Email | Your own email | |
| Anti-phishing code | Account - Security - Anti-Phishing Code | Still set correctly |
| Sub-accounts | Account - Sub-Accounts | No unknown sub-accounts |
If you find anything that's been changed, restore it item by item and change your password and 2FA again. Only lift the emergency freeze once everything checks out.
Even after handling everything yourself, it's worth filing a ticket with Binance support to document the incident. Explain what happened so support can flag your account internally as "recently attacked." That way, any unusual activity over the next 30 days triggers stricter review automatically.
Your ticket should include: the time of the incident, the attacker's IP address, whether you suffered any financial loss, and the steps you've already taken. Binance support typically responds within 1-3 business days to confirm your account status.
If you did suffer a financial loss, Binance will launch a "fund tracing" process. Binance runs its own anti-money-laundering system and can sometimes trace which address the attacker moved the funds to. For significant losses, you can apply for compensation from the SAFU fund (subject to specific conditions).
Q: Is the unfamiliar login alert really from Binance, or could it be a phishing attempt?
A genuine Binance email will include the anti-phishing code you set up yourself. An email with no anti-phishing code, or the wrong one, is phishing. If you haven't set an anti-phishing code yet, go set one right now — it makes telling real from fake far easier going forward.
Q: Does switching my own IP trigger an unfamiliar login alert too?
Yes. If you switch Wi-Fi networks or carriers and your IP range shifts enough to cross Binance's "anomaly threshold," it'll trigger the alert. This is normal behavior — once you've confirmed it's you, just ignore it.
Q: How long does an emergency freeze last before I can lift it?
Whenever you want. Go to the "Security - Emergency Freeze" page and tap "Lift Freeze," which requires a second email confirmation (to prevent an attacker from lifting it themselves). Once lifted, all functions are restored.
Q: How long does it take to recover a hacked Binance account?
If you follow the process in this article for an unfamiliar login alert, your account itself basically never gets "lost." Even if funds are stolen, the account remains yours. How long — and how likely — fund recovery is depends on the loss amount and the attacker's on-chain behavior, typically averaging 7-30 business days.
Q: How do I avoid my email getting compromised and taking down my Binance account with it?
Use a strong password plus 2FA plus a backup email for your email account. Gmail users can enable the Advanced Protection Program for an extra layer with a hardware security key. Never reuse your email password on a site you don't fully trust.
Q: I lost $10,000 after an unfamiliar login — will Binance compensate me?
It depends on the cause of the loss. If it resulted from a genuine Binance system vulnerability, Binance will compensate you in full. If it happened because your password leaked or you clicked a phishing link, you're generally responsible on your own. The SAFU fund can provide relief for some users' losses, but it isn't unconditional compensation. It's worth filing a detailed support ticket and letting the support team make the call.