Short answer up front: once the Binance withdrawal address whitelist is enabled, your account can only withdraw to addresses you've added in advance — adding a new address requires email verification, 2FA, and a 24-hour cooling-off period. Even if your account gets hacked, the attacker won't have time to withdraw your coins. This is Binance's last line of defense against coin theft, and we strongly recommend every user turn it on. Enable it in security settings on the Binance Official Site first; the same path is available on mobile in the Official Binance App; iPhone users, see our iOS Installation Guide to get the app installed.

Plenty of hacked users, looking back afterward, realize they had 2FA on and an anti-phishing code set — but never turned on the whitelist, and once the hacker got login access, the coins were gone within 5 minutes. The whitelist's 24-hour cooling-off period effectively gives you a 24-hour "revival window" if your account is ever compromised.

How the Whitelist Works

Once the whitelist is enabled, withdrawals from your account follow three rules:

Rule one: You can only withdraw to addresses on the whitelist.

Rule two: Adding a new address to the whitelist requires triple verification: an email code, an SMS code, and a Google Authenticator 2FA code.

Rule three: A newly added whitelist address goes through a 24-hour cooling-off period, during which it cannot be used for withdrawals.

Put these three rules together and here's what it means: even if a hacker gets your password, email, phone number, and 2FA app all at once, any new address they add has to wait 24 hours before it can receive a withdrawal. During that 24 hours, you have a real chance to notice something's wrong and lock the account.

Step 1: Log Into Binance and Open Whitelist Settings

Open the Binance official site and log in → your avatar in the top-right corner → "Account" → "Security" in the left-hand menu.

Scroll down to find "Withdrawal Address Management" or "Whitelist Address Management." App users can find this under "Security Settings" → "Address Management."

The page will show all currently added withdrawal addresses (if this is your first time, it'll be empty).

Step 2: Turn On the "Whitelist" Toggle

In the top-right corner or top of the page there's an "Only allow withdrawals to whitelisted addresses" toggle, off by default. Click to turn it on.

Enabling it requires:

Once all three codes are entered correctly, the whitelist feature takes effect. From that point on, your account can only withdraw to addresses on the whitelist.

Step 3: Add Your Frequently Used Withdrawal Addresses

The first thing to do after enabling the whitelist is add the wallet addresses you use regularly.

Click "Add Address" and fill in:

The address must be completely accurate — even one extra or missing character can cause your coins to be lost forever. It's best to copy it directly from your wallet app rather than typing it by hand.

After filling everything in, click "Submit," then enter your email + SMS + 2FA codes again. The address then enters its 24-hour cooling-off period.

Step 4: Wait Out the 24-Hour Cooling-Off Period

A newly added address will show as "Pending" or with a "24-hour countdown" in the whitelist list. It can't be used for withdrawals during this window.

After 24 hours, the status changes to "Active," and it can be used for withdrawals normally.

If you urgently need to withdraw to a particular address, Binance offers an "Accelerated Activation" option, but it requires stricter video verification or a support review. This isn't recommended for most users — it's usually simpler to just wait the 24 hours.

Step 5: Test That the Whitelist Is Working

Once the cooling-off period has passed, make a small test withdrawal to confirm the whitelist is functioning correctly:

  1. Go to "Spot Wallet" → "Withdraw"
  2. Select the coin → select the network → select "Address Book"
  3. You should see the address you just added on the whitelist
  4. Select it, enter the amount, and submit

If the withdrawal can be initiated normally, the whitelist is working. If you try to manually enter an address that isn't on the whitelist, Binance will reject it outright.

The 5-Step Setup Process at a Glance

Step Action Time Needed Verification Required
1 Go to Security → Address Management 30 seconds Already logged in
2 Turn on the whitelist toggle 1 minute Email + SMS + 2FA
3 Add your frequently used addresses 2 minutes each Email + SMS + 2FA
4 Wait out the 24-hour cooling-off period 24 hours Takes effect automatically
5 Test a withdrawal 1 minute Standard withdrawal flow

Which Addresses Should You Add to the Whitelist

More isn't better with the whitelist — fewer entries is safer. We recommend only adding:

1. Your hardware wallet address (Ledger/Trezor)

Storing BTC, ETH, and USDT you're holding long-term in a hardware wallet is the safest form of cold storage. Once your hardware wallet address is whitelisted, you can regularly move assets from your Binance account into cold storage.

2. Your hot wallet address (TP Wallet/MetaMask, etc.)

The wallet you use for everyday DeFi activity. Keep the number of these addresses to 3-5 at most.

3. An address at another exchange you use regularly (OKX/Bybit, etc.)

If you move funds between exchanges or spread holdings across multiple platforms, whitelist that exchange's deposit address. Note that deposit addresses at other exchanges can change periodically, so you'll need to keep the whitelist updated.

4. Don't add:

Limitations of the Whitelist

The whitelist is powerful, but it isn't a silver bullet.

Limitation one: It doesn't protect "internal transfers." Transfers between Binance accounts (an internal transfer to another Binance user) don't go through the whitelist. If an attacker controls a sub-account linked to your main Binance account, they can move coins to the sub-account and operate from there.

Limitation two: It doesn't protect against API trading abuse. API permissions have a "withdrawal" toggle, and if that's on, API withdrawals are also subject to the whitelist. But if the API only has "spot trading" permission enabled, an attacker could still use the API to wash-trade, converting your assets into a coin they control and then selling it to themselves at a low price.

Limitation three: It doesn't protect against a scam that gets you to withdraw voluntarily. If you're tricked by a fake customer service agent into adding their address to your whitelist yourself and waiting the 24 hours to withdraw, the whitelist can't save you there.

So the whitelist needs to work together with Google Authenticator 2FA, an anti-phishing code, and API IP binding to form a complete security system.

Emergency: What If the Whitelist Is Blocking a Legitimate Withdrawal

Sometimes you urgently need to withdraw, but the destination address isn't on the whitelist yet. You have 3 options in this case:

Option one: Add it now and wait 24 hours

The safest method, but you have to wait 24 hours. Pick this if you're not in a hurry.

Option two: Temporarily disable the whitelist

Go to "Address Management" → turn off the whitelist toggle → enter your email + SMS + 2FA codes. Once disabled, you're no longer restricted and can withdraw immediately. But you must turn it back on right after you're done withdrawing.

Option three: Apply for Accelerated Activation

Go to the whitelist page and find the "Accelerated Activation" option, submit facial video verification, and once Binance support approves it, the address is activated immediately. Review typically takes 1-3 hours.

FAQ

Q: What's the difference between the whitelist and Google Authenticator? A: 2FA prevents your account from being logged into; the whitelist prevents your assets from being withdrawn. They protect different layers: 2FA blocks unauthorized access, and the whitelist blocks funds from leaving even if access is compromised. You should enable both.

Q: Does enabling the whitelist affect internal deposits? A: No. The whitelist only restricts "withdrawals" — it has no effect on "deposits." Any address can still deposit into your Binance account.

Q: Can the whitelist cooling-off period be shortened? A: Not by the user. Binance fixes it at 24 hours. However, you can apply for "Accelerated Activation," which lets support review and activate it immediately after video verification.

Q: Does deleting a whitelist address require a cooling-off period? A: No, deletion takes effect immediately. But you still need email + SMS + 2FA verification to delete an address.

Q: Do I need to whitelist each coin separately? A: Yes. For the same wallet address, if you want to use it for withdrawing both USDT and ETH, you need to add it to the whitelist twice (once for USDT-TRC20, once for ETH-ERC20). Different coin/network combinations count as separate entries on the whitelist.

Q: How many addresses can I add to the whitelist? A: Each coin/network combination allows up to 50-100 addresses (the exact limit varies by coin), which is more than enough for individual users.

Q: If I turn the whitelist off and back on, are my old addresses still there? A: Yes. The address list is stored independently and won't be cleared just because the toggle is turned off. And once you turn it back on, your existing addresses don't need to go through the 24-hour cooling-off period again.

Q: Is the whitelist synced between the mobile app and the web? A: Yes, it's the same whitelist — the app and web are fully interconnected. Wherever you add an address, it goes into the same account-level whitelist.

Q: Does selling for fiat currency get affected by the whitelist? A: No. The whitelist only governs "on-chain withdrawals," not "P2P fiat sales." Fiat trading follows a separate set of rules.

The best time to turn on the whitelist is right now. Even if your account only holds a few hundred USDT, an account with the whitelist enabled and one without it are on completely different security levels in a hacker's eyes.