The short answer: set the anti-phishing code first, then enable the withdrawal whitelist. Think of the anti-phishing code as checking the name on the door. The whitelist is like locking your safe at home. First confirm the door is real, then add the final lock.
Why This Order?
The anti-phishing code helps you recognize official Binance messages. After you set it, emails and some SMS messages from Binance will include your code. This lets you confirm the message is real.
The point of the anti-phishing code is to stop phishing sites from stealing your login details. If a fake email looks very real and you cannot tell it apart, other security features may not help because scammers may still trick you into giving them codes.
The withdrawal whitelist is the last step in protecting your funds. It only allows withdrawals to addresses you already approved. All other addresses are blocked. But it works only if your login details and verification methods are already safe.
Risk note: After you turn on the withdrawal whitelist, adding a new address usually has a waiting period of 24, 48, or 72 hours. During this time, you cannot withdraw to that address. So add your whitelist address early. Do not wait until the day you need to withdraw.
Anti-Phishing Code vs Withdrawal Whitelist
| Point | Anti-Phishing Code | Withdrawal Whitelist |
|---|---|---|
| What it solves | Email/SMS authenticity | Control of fund withdrawals |
| Scope | All official messages | Withdrawal transactions |
| Setup time | A few seconds | Needs address setup in advance and has a waiting period |
| Order | Step 1 | Step 2 |
Step 1: Set the Anti-Phishing Code (Do This First)
[What it does] Add a personal code to your account that helps you tell real Binance messages from fake ones.
[How to do it] Open the Binance App → "Account" or "More" at the bottom right → "Security" → find "Anti-Phishing Code". Enter a code you can remember (6-8 characters, numbers + letters recommended) and save it.
[Done when] Binance emails show your code at the top or bottom. Treat any email without it as a scam.
Step 2: Enable the Withdrawal Whitelist (Do This Second)
[What it does] Restricts withdrawals to addresses you pre-approved. New addresses must be added to the whitelist before use.
[How to do it] Go to Security → "Withdrawal Address Management" → "Enable Whitelist". Then add your common wallet addresses as prompted. After you enable it, only whitelisted addresses can receive withdrawals. The system will block withdrawals to other addresses. New addresses have a waiting period of 24-72 hours, and you cannot withdraw to them during this time.
[Done when] The withdrawal page only shows whitelisted addresses. You cannot enter a new address manually. The system will not let you add a new address at withdrawal time.
Common Mistakes
You set the anti-phishing code but never check it in emails. You receive a phishing email without the code and still treat it as real.
You enable the whitelist too late. You need funds, add a new address at the last minute, and get stuck in the 24-hour waiting period.
You turn on both features but forget to review your security settings. Old addresses pile up in the whitelist and are not removed.
Next Steps
First, go to Security and set your anti-phishing code. Then enable the withdrawal whitelist and add 2-3 addresses you use often. When done, log out and log back in using Google Authenticator. Check that your whitelist addresses appear normally on the withdrawal page.


