# What happened
Binance alerted users to a recent increase in phishing attacks that arrive as text messages disguised as security alerts. According to the exchange, scammers craft messages that appear official — claiming account settings changed or suspicious activity was detected — and include shortened links that push recipients to "verify" or "secure" their account.
Binance emphasized it does not send SMS links asking customers to click to verify or secure accounts. The exchange urged users to be cautious and offered several concrete protections to reduce the risk of losing funds.
# How the phishing texts work
Scammers rely on urgency and credible-looking wording. Typical elements reported by Binance:
- Message content mimics Binance security notices (account settings change, suspicious login).
- Shortened or obfuscated links redirect recipients to fake pages that collect credentials or prompt unsafe actions.
- The language creates pressure to act immediately, increasing the chance that people click without verifying the sender.
A separate cybersecurity disclosure identified a broader SMS phishing campaign. Rapid7 called the operation "Operation Asterix" and reported it targeted roughly 885,000 phone numbers, showing that SMS-based attacks on crypto users are part of larger campaigns.
# What Binance recommends
Binance listed specific steps users can take right away:
- Do not tap links in text messages that claim to be Binance security alerts. Binance will not ask you to click an SMS link to verify or secure your account.
- Verify the destination of any link before entering credentials or approving requests. Prefer navigating to the official Binance site or app directly rather than following inbound links.
- Use Binance Verify or other official verification tools to check questionable communications before responding.
# Practical steps to reduce risk
- When you receive a security-related SMS: pause. Do not click any included link. Open your Binance app or go to the official site manually and check account activity.
- Lock down withdrawals: activate the Withdrawal Address Whitelist and review all whitelisted addresses regularly.
- Use strong authentication: keep two-factor authentication active and prefer app-based MFA rather than SMS where possible.
- Report suspicious messages: forward or report suspicious communications through Binance's official support channels rather than replying to the sender.
# Why this matters now
Phishing via SMS leverages two vulnerabilities: users' trust in urgent security messages and link-shortening tactics that conceal destination URLs. The existence of a high-volume campaign reported by Rapid7 suggests these attacks are widespread and automated, which raises the likelihood that more users will encounter them.
Taking the specific protections Binance lists reduces the chance that a single mistake leads to an immediate fund loss. The steps are practical and can be implemented quickly by most users.