The first thing you should do after your account is hacked is not change your password. It is to block the withdrawal channel and lock your funds. As long as your assets have not been moved out of Binance, you still have a chance.

The world's largest cryptocurrency exchange by trading volume,leading in security and liquidity.
New user benefit: Enjoy 20% off trading fees upon registration!
Step 1: Freeze All Withdrawals Immediately (Most Critical)
[What to do]: Turn on Binance's "Withdrawal Protection" feature. This is a security tool designed specifically for emergency lockouts.
[How to do it]: Open the Binance app or website, go to Security Settings, find the Withdrawal Protection option, and enable withdrawal lockout immediately. You can choose to freeze the account for 1 to 7 days, with 48 hours as the default. During the lockout period, no one can make on-chain withdrawals, including you. If the situation is more urgent, you can also go directly to the Security Center and select "Freeze Account."
[Completion standard]: The account withdrawal function is locked, and the page shows "Withdrawals Disabled" or a similar status. This means the attacker cannot immediately transfer your assets out.
Step 2: Reset Your Password and Force Logout on All Devices
[What to do]: Cut off the attacker's access to your account and change every entry point that may have been compromised.
[How to do it]:
Reset your login password: Go to Security Settings, then Login Password, then Manage, and change your password immediately. If you cannot log in, use the "Forgot Password" function to reset it through your registered email.
Log out all devices: In Security Settings, go to Device Management or Account Activity, check the list of currently logged-in devices, and remove all devices you do not recognize.
Check your email security: Make sure your registered email has not been hacked. If there is any suspicious login, change your email password immediately and enable two-factor authentication.
[Completion standard]: Your password has been changed, and only the device you are currently using remains in the device management list.
Step 3: Check and Remove Hidden Backdoors
[What to do]: Look for hidden entry points the attacker may have set up in your account, such as API keys.
[How to do it]: Go to the API Management page and check all existing API keys. If you find any API key you do not recognize, delete it and regenerate keys immediately, because the attacker may have created an API key to bypass your login and withdrawal verification.
[Completion standard]: Only keys you have confirmed remain in the API key list, with no unfamiliar entries.
Step 4: Contact Binance Official Support
[What to do]: Report the security incident so official support can help with further investigation and protection.
[How to do it]: Open the Binance app or website and submit a ticket through the Contact Support option in the lower right corner or the online customer service entry in the Help Center. Provide all suspicious login records, transaction screenshots, and other evidence.
[Completion standard]: You have submitted a formal security incident report, and customer service has accepted it and given you a ticket number.

The world's largest cryptocurrency exchange by trading volume,leading in security and liquidity.
New user benefit: Enjoy 20% off trading fees upon registration!
Step 5: Strengthen Security Afterward
[What to do]: Prevent being hacked again.
[How to do it]: Enable or reset two-factor authentication, also called 2FA. In security settings, check and turn on all available security notifications, such as login alerts. Consider setting up the "Emergency Contact" feature so Binance can reach a trusted person if unusual activity is detected.
Risk reminder: Once an on-chain transfer is confirmed, it cannot be reversed. An attacker may only need a few minutes from logging in to moving assets out. "Withdrawal Protection" is your most valuable time window. You must lock your assets first, then fix the account. If the order is reversed, it may be too late.
How to verify completion: After finishing all steps, log in again and confirm that "Withdrawal Protection" is active, the device list is clean, and the API key list is safe. Then keep watching the account for any abnormal login alerts over the next 48 hours.


