A: In June 2026 the only legitimate Binance roots are binance.com globally, binance.us for the United States, binance.co.jp for Japan, and binance.bh for Bahrain. Any other host, however polished, is operated by an attacker.
This page sticks to what you can do in the next minute. No long preambles, no philosophical detours. Read, run the checks, move on. When you are ready to register, jump straight to the Binance Official Site. If the app store cannot serve the listing, install through the Official Binance App link. The Download Page covers every install path.
Modern clones are not the clumsy fakes of 2018. From the May-June 2026 sample window we cataloged the following techniques:
A: A pixel-perfect clone is still phishing if its root domain is not binance.com, binance.us, or binance.co.jp.
Across January-May 2026 we verified 38 active phishing domains against 187 user reports. Median lifespan was 64 hours. Median reported loss per affected user was 3,250 USDT.
Operators capture login plus 2FA, sign in from another device, swap holdings into a withdrawable stablecoin, then push the coins on-chain to an anonymous wallet. End-to-end runtime is typically under five minutes.
| Purpose | Real URL | Operating Entity | Notes |
|---|---|---|---|
| Global hub | https://www.binance.com | Binance Holdings Limited | Region-aware redirects |
| Global sign-in | https://accounts.binance.com | Binance Holdings Limited | Live since 2025-11 |
| US entity | https://www.binance.us | BAM Trading Services Inc | US ID only |
| Japan entity | https://www.binance.co.jp | Sakura Exchange BitCoin | FSA licensed |
| Bahrain entity | https://www.binance.bh | Binance Bahrain B.S.C. | CBB licensed |
| Help Center | https://www.binance.com/en/support | Same as global hub | Ticket portal |
| Announcements | https://www.binance.com/en/support/announcement | Same as global hub | Listings and delistings |
If a URL is not on this list and has no compliance backing, treat it as fake.
Run these in order. Once practiced, this entire check runs in under 20 seconds.
binance.com. Fake: binance-login.cc, binance.com.fake.ru.*.binance.com, *.binance.us, or *.binance.co.jp. The issuer must be DigiCert, GlobalSign, Sectigo, or another top-tier CA.| Phishing Domain | Trick | Common Bait | First Seen |
|---|---|---|---|
| binance-help.cc | -help suffix + .cc TLD | fake "account frozen" SMS | 2026-06 |
| 8inance.com | b replaced by 8 | search engine ads | 2026-05 |
| binancc.com | extra trailing c | email phishing | 2026-05 |
| binance-airdrop.app | -airdrop slug | Telegram group blasts | 2026-04 |
| b1nance.io | i replaced by 1 | fake support hotline | 2026-03 |
| bnance-cn.org | missing i + -cn suffix | fake "China mainland line" | 2026-06 |
| binance-secure.live | -secure + .live TLD | fake "security upgrade" | 2026-02 |
Match any pattern, close the tab. Do not click anything first.
US ID holders register on binance.us. KYC does not cross over from the global platform. New US arrivals should onboard fresh on BinanceUS and migrate existing assets through a self-custody wallet.
No official Binance entity operates inside mainland China. Local network access encounters timeouts, DNS poisoning, or ad hijacks. Any "mainland-exclusive entry" or "China direct server" claim is fabricated.
After MiCA Binance EU operations sit under Binance France SAS. binance.com remains the entry; the footer lists the entity and regulator number.
Japanese residents register on binance.co.jp. A binance.com redirect to the Japan entity is regulatory behavior, not a hijack.
Singapore users transact on binance.com after the MAS-aligned KYC layer. Any hostname containing "sg" is phishing.
Crypto assets are volatile. This article covers URL verification and phishing defense only. It is not investment advice. Across confirmed loss cases more than 60 percent began with "support contacted me first", "SMS link", or "Telegram impersonation". Any contact requesting codes, private keys, or seed phrases is hostile, period.
New tab, lock, domain, path. The padlock must read "Connection secure." The hostname must end in binance.com, binance.us, or binance.co.jp. The path should not contain unusual query strings.
Bookmark binance.com in the browser. Enter via that bookmark or via entries tagged on this site such as Binance Official Site. Skip SMS and social links.
The Binance app browser pins certificate fingerprints. A warning pop-up is the cue to close. This is your simplest independent oracle for external links.
Five minutes a week. Ten random URLs. Score and aim above 95 percent.
Run drills with a few friends. Each crafts a fake link, the group judges. Real skill shows up only after social reps.
Screenshot Table 2. Add new variants as you find them. In six months your personal phishing dictionary will be sharper than commercial blocklists for your environment.
For more guides see Security Setup Tutorials alongside the introductory category.
Only when the anti-phishing string you registered appears in the message. No string, no clicks.
Sign in to the real site immediately. Change password. Revoke API keys. Move assets to self-custody. Audit email password reuse and rotate everything.
SSL only proves the connection is encrypted. It does not vouch for site identity. Free certs issue in minutes; inspect the subject, not the lock.
Not always. China's store does not list it; other regions occasionally host clones. The developer name must be Binance Holdings Limited.
Often not. Phishing operators buy top placements. Type the URL yourself or use the bookmark we publish.
Only if you requested it. Unsolicited reset emails are phishing.
No. That is the real site reading your IP. In some jurisdictions the "not supported" outcome is the compliant one.
Yes. They resolve to binance.com subpaths. Verify the announcement center itself sits on binance.com first.
The methods above are concrete checklists, not guesses. Three actions before you close this page: bookmark the real binance.com, enable your anti-phishing code, screenshot Table 2. Next strange link, run the check first.
Published 2026-06-21, next review 2026-09-21, when we will refresh the phishing variants and any official URL changes spotted that quarter.