After registering on Binance, enable security settings in this order: Google Authenticator > Anti-Phishing Code > Withdrawal Whitelist > Device Management. Do not skip any of them. Missing even one can lead to problems.
Why This Order
Google Authenticator comes first for a reason. SMS codes can be intercepted through SIM card hijacking. The dynamic codes generated by Google Authenticator are stored locally on your phone, so they are much more secure. The other items add extra protection on top of it.
Step 1: Set Up Google Authenticator (Most Important)
What you do: Link your Binance account to Google Authenticator. You will use it for login, withdrawals, and security setting changes.
How to do it:
Download the app first: Search for "Google Authenticator" in your phone's app store. Use the official one, not a copycat version.
Go to Binance settings: Open the Binance app → tap "Account" in the bottom right → "Security" → find "Google Authenticator" and tap "Enable".
Scan the QR code: Binance will show a QR code. Scan it with Google Authenticator.
Write down the recovery key: During setup, the system will give you a string of characters (the recovery key). Write it down and keep it somewhere safe. Do not save it as a screenshot on your phone.
Enter the 6-digit code: Google Authenticator will show a 6-digit dynamic code. Enter it back in Binance to confirm the setup.
Done when: The Binance security page shows "Enabled" next to Google Authenticator.
Risk warning: The recovery key is the only way to restore Google Authenticator. If you lose your phone and did not write down the key, you cannot recover Google Authenticator yourself. You will need to go through customer service, which takes time and is complicated.
Step 2: Set Up an Anti-Phishing Code
What you do: Choose a code you can remember. Binance will include it in every email it sends you, so you can tell real emails from fake ones.
How to do it: Go to Security → "Anti-Phishing Code" → enter a string you can remember (for example, your nickname plus numbers), then save.
Done when: Binance emails show this code at the top of the message. Any Binance email that does not have this code is a phishing email.
Step 3: Turn On the Withdrawal Whitelist
What you do: Restrict withdrawals so you can only send funds to addresses you have approved in advance. New addresses must be added to the whitelist before they can be used.
How to do it: Go to Security → "Withdrawal Address Whitelist" → turn it on, then add your commonly used wallet addresses. You will need to verify your email and Google Authenticator.
Done when: The withdrawal page only shows whitelisted addresses. You cannot manually enter any other address.
Step 4: Check Device Management Regularly
What you do: Check which devices are logged into your Binance account and remove any that you do not recognize or no longer use.
How to do it: Go to Security → "Device Management" → look at the device list and tap "Remove" on any device that looks unusual.
Done when: The device list only shows the device you are currently using.
Additional Notes
To enable the two-factor authentication policy, your account must first complete identity verification (KYC) and hold more than 100 USDT in assets. If you have not done KYC yet, go to the "Identity Verification" page first. After enabling it, you can customize which verification method is required for login, withdrawals, and other actions in the "Two-Factor Authentication Policy" section of the security page.
Next Steps
Go to the security page and set up Google Authenticator. Write down the recovery key and keep it at home. Then turn on the anti-phishing code and the withdrawal whitelist in order. When everything is done, log out of your account and log back in using Google Authenticator to confirm each security feature works properly.


