2FA is not decoration. SMS can follow a number port. An authenticator keeps the seed on a device you hold. Binance Security commonly offers Google Authenticator or another TOTP app. After it is bound, login and withdrawals want one more confirm.
The flow is short: open the authenticator, scan or type the seed, enter the current six digits. What actually hurts is backup codes tossed aside, and deleting the old phone first.
Do not photograph the seed into a chat app “as a backup.” That is leaving the key in someone else’s hallway.
The bind sequence
Log in, open Security, pick authenticator. The page gives a QR and a seed string. Scan with the authenticator; if the scan fails, type the seed. The app shows six digits. Type them back into the page. Bound.
It does not have to be the Google app. A TOTP-compatible authenticator usually works. Follow the bind page’s live list. If the page also offers a passkey, follow that screen. Do not install a “security app” from a random search ad.
I stalled on the scan: laptop brightness too low, phone could not lock on. Typing the seed worked once. The seed only appears whole on that screen. You will not get a second equally clear look. Copy it while it is there.
- Confirm you can log in, then start the bind. If you drop mid-bind, do not delete anything yet.
- Scan or type, wait until the authenticator starts rolling digits.
- Type the current six back into the page. Too much clock drift, the code expires. Wait for the next one.
- If the page shows backup codes, take them now, then do anything else.
Public wording lives in the help centre. You can check Binance Support FAQ. Do not follow a search-ad “authenticator download.”
Do not open two Security windows during a bind. Binding in one and tapping Enable again in the other can void the old seed before you have copied the new one. Finish one window, take the backup codes, then close. I once had two tabs. The later one overwrote the earlier codes. I had no paper to hand, so I bound again on the spot.
What backup codes do, and what the seed does
The seed is what the authenticator uses to produce codes. Backup codes are a one-time door when the authenticator is not there. Both belong offline. A camera roll syncs to a cloud. Chat lands on someone else’s servers. Neither is offline.
Backup codes are usually one-use. Use one, strike one. Do not leave the whole picture on a desktop for months. Paper, an offline password book, an encrypted disk that is not networked — those beat a cloud roll.
I write backup codes on a sheet that is not networked, and I do not keep them in the same envelope as a passport copy. That is not a ritual. It is one fewer “both gone at once.”
Authenticator only, no backup codes: a phone swap or a smash leaves you with an appeal. Backup codes only, authenticator sitting on someone else’s phone: you lent the keycard. You want both, and not both on the same phone.
People put the seed in a notes title called “bank.” If that notes app syncs, it is the same class of risk as a camera roll. Offline means: this device is off, this cloud is down, you can still produce the string. If you cannot, it is not stored.
Take the backup codes at bind time. After a smashed old phone is when people discover they never stored them. This site cannot find that sheet for you.
How to move phones
Install the authenticator on the new phone, scan the same seed or use the app’s transfer, confirm the new phone already produces codes and can log in, then delete the entry on the old phone. Reverse the order and you lock yourself out.
Some authenticators export a QR. Do not point that export at a camera, and do not cast it onto a meeting-room screen. After the move, delete the old-phone entry, and delete the export image.
When I moved, the old phone was still on. The new one produced codes, login worked, then I deleted the old entry. For half an hour both could produce codes. Duplicate beats blank.
The new phone’s clock has to be right. Clock drift makes the six digits miss. Turn automatic time on before you blame a “lost bind.”
Old phone still powers on, screen smashed, cannot scan: take the paper with the typed seed, add the same account on the new phone. Codes match, then delete the old entry. A smashed screen is not a smashed seed — if you copied the seed at the time.
If the authenticator is gone, can you still log in
If you can produce a backup code, log in with it, then bind a new authenticator. If backup codes are gone too, only a platform appeal remains. Prepare identity files and submit through Help inside the account. This site cannot reset someone else’s 2FA.
After a lost authenticator, do not type a password into a strange link. Phishing pages love hurry. Enter from an address you already use, or from a genuine mail in a mailbox you already opened. Do not tap a short link in a DM.
Appeals take time, and the result is the platform’s review. This site cannot print “you will be back in by then.” What you can do, if you have not lost it yet, is write the backup codes down.
SMS still works, authenticator gone: some flows let SMS help. SMS can follow a number port, which is why you bound an authenticator. After you are in, bind an authenticator again soon. Do not sit on SMS only for long.
Appeal files are what the page asks: ID, a face, steps that show you control the mailbox. Do not photograph backup codes for a “helpful stranger” to type. Whoever holds the backup codes can enter. This site will not type them either.
An authenticator and a funds password are not one thing. A funds password confirms an outgoing. An authenticator confirms “you are sitting at this device.” Turn both on. Lose one, the other still sits there. Funds password only, authenticator empty, and a ported SMS makes the outgoing rail looser. Look at these Security items the same day. Do not “trade first, bind later.” Futures and leveraged positions can lose 100%. They are a worse idea while the authenticator is still loose.
A public bind, someone next to you can scan the same QR with another phone. A café, a shared desk: typing the seed is sturdier than holding the QR up. After you copy the seed, close that screen. One scan, and your six digits work for them too.
Do not uninstall the authenticator while a session is still live. An export QR left on a lock screen is a copied seed — unbind and bind a new one if you can still log in. If codes miss after an update, check automatic time before you delete the entry.
Do I uninstall the old authenticator before I move phones?
No. Let the new phone produce codes and confirm you can log in, then delete the entry on the old phone.
Can backup codes live in a cloud camera roll?
A cloud roll syncs. Write them on offline paper or an offline password book.
If I lose the authenticator, can this site reset it?
No. Use the appeal inside your Binance account. This site does not hold or reset someone else’s authenticator.