Last month I received an email that appeared to be from Binance, with a digital signature, saying there was an abnormal login to my account and asking me to click in to verify. I looked at it twice and couldn’t spot anything wrong—until I remembered something: I had set a string of codes I made up in my Binance account. Every time a real Binance email or SMS is sent, the beginning includes it. That email didn’t have it.
Many people register and then go straight to deposit and buy coins, without touching a single switch in their account. I’ll first explain the registration itself with five items, but the focus is on what comes next: after registering and before putting money in, where exactly the official security settings are located in each menu, and how to fill in each item specifically.
【Registration in 5 steps】
▸ Open the registration page: https://www.binance.com/zh-CN/join?ref=WIN98 — On the first screen there’s only one input box that says "Email/Phone number". You can enter either your email or your phone number. Below, you’ll see three options: "Continue with Google", "Continue with Apple", and "Continue with Telegram". There is no invite code field on the first screen—this is normal.
▸ Enter the verification code: The code is a 6-digit number and is valid for 30 minutes. After entering it, click 【Submit】.
▸ Set your password: The official requirement is at least 8 characters, with at least 1 uppercase letter and 1 number.
▸ Choose the account type: personal or business. After registration, it cannot be changed. Personal users should choose personal.
▸ Fill in the referrer ID: This step is at the end. On the page after you complete the registration process, the system will ask whether you have an inviter. Select "Yes" and the input box for the code will appear. Enter WIN98, and the fee will be charged at an 80% rate. The official calls this field "Referrer ID (optional)". The note next to it says: "If you register via a friend invitation to Binance, please make sure you fill in the referrer ID". Once the invite code is bound to the account, it can’t be modified. Don’t skip this step.
If you’re installing the app on Android, the installer package is in the top section of the download page. You can also use the official direct link:
https://download.binance.com/pack/BNApp_F0001674.apk
【Anti-Phishing Code】
Binance’s official website has a dedicated page for this, but most registration tutorials don’t mention it.
The official definition is: "The anti-phishing code is a unique set of alphanumeric characters you set yourself. It will appear in all emails and SMS messages sent by Binance official."
▸ App path: Tap your avatar → 【Account Information】 → 【Account Security】 → 【Anti-Phishing Code】 → 【Create】 → enter the code you want to set → 【Submit】 → confirm with 2FA or a passkey.
▸ Website path: Click the 【Personal Profile】 icon → 【Account】 → 【Account Security】 → 【Advanced Security Settings】 → find 【Anti-Phishing Code】 and click 【Enable】 → 【Create】 → enter → 【Submit】
▸ Format requirements: 6 to 8 characters. Must include at least three of these four types: uppercase letters, lowercase letters, numbers, and underscores. Cannot contain special characters.
▸ How to use it after setting: For all emails and SMS messages that claim to be from Binance in the future, first check whether the message starts with this code string. The official standard is stated very directly: "If the anti-phishing code you set is not displayed correctly or is missing, it may be a phishing scam. Report it immediately."
Only you and Binance’s system know this code string. Fake sites can’t get it, so it’s more reliable than manually checking the domain with your eyes.
【Authenticator App】
▸ Path: 【Account】 → 【Account Security】 → find 【Authenticator App】, then tap the nearby 【Manage】
▸ Choose one of two binding methods: scan the QR code in the authenticator, or manually enter the setup key.
▸ After binding, enter the 6-digit verification code generated by the authenticator to confirm.
▸ In Binance’s own authenticator app, you can swipe the verification code to the left to 【Fix】【Edit】【Export】【Delete】. Tap the 【+】 in the top-right corner to add multiple accounts.
▸ ⚠️ Know this in advance: The official notice states **"To protect account security, after the authenticator is changed, withdrawals and C2C trading will be disabled for 24 hours."** Before switching phones or authenticators, withdraw any coins you may need urgently so you don’t get stuck at the critical moment.
【Withdrawal Whitelist】
▸ Path: 【Settings】 → 【Withdraw】 → 【Withdrawal Whitelist】 → 【Enable】
▸ After enabling it, your account can only withdraw to addresses on the whitelist. If you don’t enable it, the official wording is: "After you turn off the withdrawal whitelist feature, you can withdraw to any address."
▸ Add an address—there are these fields to fill: address remark, choose the withdrawal coin or set it as a general address, the corresponding network, 【Address source (optional)】 (exchange address / wallet address / other). Finally, tick 【Add the address to the whitelist】.
▸ One account can add up to 200 withdrawal addresses at most.
▸ There’s also a security restriction for whitelisted addresses: you can set 24, 48, or 72 hours. During this time, addresses newly added to the whitelist cannot be withdrawn.
The real purpose of this setting is: even if both your password and verification code are taken, the coins can only be withdrawn to the addresses you added in advance.
【Official security notice also names two locations】
▸ 【Account activity】: You can see the device, time, and location of every login to your account. If you see any record you don’t recognize, change your password immediately.
▸ 【API key management】: Unless you run automated trading programs yourself, don’t create an API Key. The official guidance reminds you to treat it on the same level of sensitivity as your password.
▸ There’s also this line on the same page: Binance will not proactively contact users by phone or social media.
【FAQ】
Question: After registering on Binance, what should you do first?
Answer: Enable the anti-phishing code. The path is 【Account Security】 → 【Anti-Phishing Code】. Set a code of 6 to 8 characters. After you set it, all real Binance emails and SMS will include it, while fake ones can’t.
Question: How can I tell whether an email is really sent by Binance?
Answer: Check whether it contains the anti-phishing code string that you set yourself. The official wording is: "If the anti-phishing code you set is not displayed correctly or is missing, it may be a phishing scam. Report it immediately."
Question: What impact will it have if I change my phone or the Authenticator app?
Answer: The official notice states that after the authenticator is changed, withdrawals and C2C trading will be disabled for 24 hours. If you need to change, do it in advance—don’t change it on the day you need to withdraw coins.
Question: If I enable the withdrawal whitelist, can I still withdraw to new addresses?
Answer: Yes. First add the new address to the whitelist. If you also enabled the whitelist address security restriction, the newly added address must wait until your set 24/48/72 hours are over before withdrawals are allowed.
Question: How do I confirm that the invitation code is actually bound?
Answer: After logging in, go to 【Personal Profile】 → 【Invitation Rewards】. On that page, you can see your own commission rebate rate. If you register using an invitation link in the app, the invite code will be filled in automatically, and next to it you’ll see a green checkmark icon and 【Bound】.
【Three reminders】
▸ For anti-phishing code, the identity authenticator, and the withdrawal whitelist—set these before you recharge into your account.
▸ When binding the authenticator, make a copy offline of the key for that 【Input setup key】. Only then can you restore it if you lose your phone.
▸ Binance will not proactively contact you by phone or social media. If anyone asks you to transfer funds or enter a verification code, ignore them.
If you can’t find which menu item, let me know in the comments. I’ll guide you based on whether you’re using the app or the website.