Binance warned users on September 3, 2026, that phishing texts impersonating its support team are rising, with scammers using fake security alerts and spoofed sender IDs to push account holders toward malicious phone numbers and websites that harvest login credentials or reroute funds to attacker-controlled wallets.
Binance warns users as phishing texts increase
Binance has repeatedly emphasized that customers should rely on its official channels when checking account activity. A fraudulent text message can create the impression that an account has been compromised, prompting a user to act before verifying whether the alert is genuine.
The campaign described in the Binance warning relies heavily on urgency. Messages can claim that an unfamiliar device has accessed an account, that a withdrawal is being processed or that immediate action is required to prevent a security problem.
The objective is to push the recipient toward a phone number or website controlled by the scammer.
The exchange’s security guidance states: “Binance will never send you an SMS asking you to call a number and speak to a customer support or a security department.”
How Binance phishing texts can trap investors
The danger with Binance phishing texts is that they do not necessarily look like obvious scams. Attackers can manipulate sender information so fraudulent messages appear to come from a recognizable source.
In some cases, spoofed messages can even appear alongside legitimate communications in a user’s SMS conversation.
That familiarity can make the scam more convincing. A user who receives what appears to be an urgent account-security warning may call the number supplied in the message or follow a link to investigate.
The conversation can then move from the fake SMS to a fraudulent customer-support interaction.
Scammers may claim that an account has been compromised and instruct the victim to move cryptocurrency into a supposedly secure wallet. In reality, the destination wallet can be controlled by the attacker.
Other schemes attempt to capture login credentials through counterfeit websites. Once a victim enters a username, password or authentication information, criminals may use those details to gain access to the account.
Binance’s official security guidance warns that SMS spoofing is specifically designed to exploit trust in familiar brands. The company also warns users not to click suspicious links received through text messages.
Binance warns users to verify every suspicious message
The latest Binance phishing texts warning places particular importance on verification rather than simply trusting the sender name displayed on a phone.
Binance provides an official verification service that allows users to check whether a domain, email address, telephone number or other contact is associated with the company.
Investors who receive an unexpected security message should independently open the Binance app or official website rather than using the link or telephone number supplied in the message.
The exchange has also promoted its Anti-Phishing Code as an additional security layer. According to Binance Support, once activated, the user’s unique code appears in genuine Binance emails and SMS messages. If the expected code is missing or incorrect, the communication may be fraudulent.
A message can use the company’s branding, familiar language or an apparently legitimate sender name and still be fraudulent.
Binance has also advised users to activate withdrawal-address whitelisting, which can restrict withdrawals to previously approved addresses.
What Binance phishing texts mean for crypto investors
The rise of Binance phishing texts is significant because cryptocurrency transactions generally cannot be reversed once funds have been transferred to an attacker-controlled wallet.
Traditional financial institutions may have mechanisms for disputing or reversing certain transactions, but crypto transfers can be considerably harder to recover.
The warning also illustrates why account security should extend beyond passwords. Users should enable available two-factor authentication, establish an Anti-Phishing Code and avoid interacting with unexpected links or telephone numbers received through SMS.
Binance has separately described SMS spoofing as a technique in which attackers manipulate sender identities so fraudulent messages appear to originate from trusted organizations.
The exchange recommends verifying communications through official channels rather than relying on the appearance of the message itself.
A suspicious alert does not become legitimate merely because it appears in the same SMS thread as previous Binance notifications. Investors should independently access their accounts, review recent transactions and contact support through official channels if something appears wrong.
The Binance phishing texts warning also reinforces a broader issue for the cryptocurrency sector: attackers increasingly target people rather than attempting to break the underlying blockchain technology.
As crypto adoption expands, social engineering remains a major security challenge. The Binance phishing texts campaign demonstrates how criminals can combine spoofed communications, psychological pressure and fraudulent websites to bypass the caution of otherwise sophisticated investors.
For anyone holding digital assets on an exchange, the safest approach is to slow down when a message creates urgency. Verify the source, avoid unsolicited links, never disclose passwords or recovery information, and use only official support channels.