Binance ගිණුම් මාර්ගෝපදේශ

Binance 2FA සහ Account Security: Passkey, Phishing ආරක්ෂාව

Account එකට මුදල් දැමීමට පෙර authenticator, passkey, anti-phishing code, device review සහ withdrawal controls සැකසීමේ ආරක්ෂක checklist එක.

Binance 2FA සහ Account Security: Passkey, Phishing ආරක්ෂාව

Google Play Binance official app පිටුවේ Data safety කොටසේ සැබෑ screenshot එක

Binance account එකක් සෑදීමෙන් පසු පළමු කාර්යය trade කිරීම නොව login, email සහ withdrawal ආරක්ෂාව ස්ථර කිහිපයකින් සැකසීමයි. ඉහත screenshot එක Google Play හි Binance app listing එකේ Data safety කොටස පෙන්වයි. Publisher සහ data disclosure පරීක්ෂා කිරීමට එය එක් පියවරක් වුවත්, app එකේ සියලු security controls independently audit කළ බවක් එයින් අදහස් නොවේ.

මෙම guide එකේ menu names කාලයත් සමඟ වෙනස් විය හැක. Security setting එකක් සක්‍රීය කරන විට ඔබේ live account එකේ description සහ confirmation message කියවන්න. Password, OTP, passkey, recovery key, API secret හෝ screen-sharing access කිසිවෙකුට නොදෙන්න.

1. Account එකට වෙනම email සහ password එකක්

වෙනත් site එකක නැවත භාවිතා නොකරන දිග, unique password එකක් trusted password manager එකක තබන්න. Password එක chat, note screenshot හෝ cloud photo එකක ගබඩා නොකරන්න. Password එක leaked වී ඇතැයි සැකයක් තිබේ නම් clean device එකකින් වෙනස් කරන්න.

Binance account recovery සහ security alerts email එක මත රඳා සිටිය හැකි නිසා email account එකටත් unique password සහ phishing-resistant 2FA සක්‍රීය කරන්න. Exchange account එක ශක්තිමත් වුවත් email එක අත්පත් වුවහොත් password reset සහ withdrawal-address confirmation අවදානම් විය හැක.

2. 2FA method එක තෝරන්න

SMS 2FA කිසිවක් නැතිව සිටීමට වඩා හොඳ විය හැකි නමුත් SIM-swap අවදානමක් ඇත. Authenticator app එකක් time-based one-time codes generate කරන නිසා mobile number එක පමණක් අත්පත් කරගත් attacker කෙනෙකුට ප්‍රමාණවත් නොවේ. TOTP recovery key එක offline සහ encrypted හෝ භෞතිකව ආරක්ෂිත ස්ථානයක තබන්න.

Passkey හෝ hardware security key option ලබාදේ නම් phishing resistance වැඩි කරන factor එකක් ලෙස සලකා බලන්න. Backup factor එකක් නැතිව single device එකකට පමණක් රඳා නොසිටින්න. Backup method එක set කර ඇති බව පරීක්ෂා කරන්න, නමුත් login credentials හෝ private recovery material cloud screenshot එකක් ලෙස නොතබන්න.

Binance Security settings පිටුවේ Two-Factor Authentication, passkey සහ authenticator විකල්ප පෙන්වන සැබෑ screenshot එක

මෙම screenshot එක Binance Academy හි 2026 ජූනි යාවත්කාලීන කළ account-security guide එකේ පෙන්වන Security settings interface එකයි. Menu layout, method names සහ ලබාගත හැකි controls කාලයත් සමඟ වෙනස් විය හැකි බැවින් ඔබේ current Security settings පිටුවේ විස්තර කියවන්න.

3. Recovery plan එක කලින් සකස් කරන්න

Phone එක නැති වීම, authenticator app reset වීම හෝ hardware key එක අහිමි වීම login emergency එකක් විය හැක. Account එකට මුදල් දැමීමට පෙර backup factor, recovery key location සහ account-recovery process එක ඔබට තේරෙනවාද පරීක්ෂා කරන්න.

Recovery key හෝ backup code එක test කරන විට එය වෙනත් පුද්ගලයෙකුට නොපෙන්වන්න. Support ලෙස පෙනී සිටින කෙනෙකු recovery code, remote-control access හෝ video verification පිටත channel එකක ඉල්ලන්නේ නම් process එක නවතා දමන්න.

4. Anti-phishing code සකසන්න

Anti-phishing code යනු ඔබම තෝරන phrase එකක් වන අතර genuine Binance notification emails තුළ එය පෙන්විය හැක. Code එක ඔබේ password එක නොවිය යුතු අතර public nickname එකක් වැනි පහසුවෙන් අනුමාන කළ හැකි වචනයක් නොවීම හොඳය.

Binance Create Anti-Phishing Code dialog එකේ හිස් code field, character rules සහ Submit button පෙන්වන සැබෑ screenshot එක

Email එකක code එක නොමැති හෝ වැරදි නම් එහි button හෝ link click නොකරන්න. Code එක නිවැරදි වුවත් sender account compromise හෝ copied email අවදානම සම්පූර්ණයෙන් ඉවත් නොවන නිසා sensitive action එක saved app/site entry එකෙන් ආරම්භ කරන්න. Anti-phishing code එක එක් signal එකක් මිස single proof එකක් නොවේ.

5. Devices, IP activity සහ sessions පරීක්ෂා කරන්න

Security settings හි authorized devices සහ recent account activity බලන්න. Device name, operating system, IP/region සහ login time ඔබේ activity සමඟ ගැළපේද පරීක්ෂා කරන්න. VPN හෝ mobile network නිසා region වෙනස් පෙනිය හැකි නමුත් හඳුනා නොගත් device එක ignore නොකරන්න.

පැරණි phone, shared computer හෝ භාවිතා නොකරන browser sessions revoke කරන්න. Public computer එකක login නොකරන්න. Browser extension සහ remote-access software account sessions හෝ clipboard data ලබාගත හැකි නිසා trading device එකේ අවශ්‍ය නොවන extensions ඉවත් කරන්න.

6. Withdrawal address allowlist භාවිතා කරන්න

Withdrawal address allowlist හෝ whitelist ලබාදේ නම්, ඔබ විශ්වාස කරන wallet addresses පමණක් pre-approve කිරීමට එය භාවිතා කළ හැක. New address එකක් add කරන විට email confirmation හෝ cooling period තිබිය හැක. Feature එකේ current rules live interface එකෙන් කියවන්න.

Allowlist එක email security මතද රඳා සිටිය හැකි නිසා email account එක දුර්වල නම් protection එක අඩුවේ. Address එක copy/paste කළ පසු මුල් සහ අවසාන characters කිහිපයක් පමණක් නොව network, memo/tag requirement සහ test amount එකත් පරීක්ෂා කරන්න. Malware clipboard address වෙනස් කළ හැක.

7. API key අවශ්‍ය නැත්නම් සාදන්න එපා

API key එක account access credential එකකි. Third-party bot හෝ portfolio service එකක් සම්බන්ධ කිරීමට පෙර අවශ්‍ය permissions මොනවාද කියා බලන්න. Read-only access ප්‍රමාණවත් නම් trading හෝ withdrawal permissions ලබා නොදෙන්න.

IP restriction ලබාදේ නම් known server IPs පමණක් allow කරන්න. API key සහ secret source code, public repository, screenshot, chat හෝ browser note එකක දමන්න එපා. Service එක භාවිතා නොකරන විට key revoke කරන්න; suspicious activity එකකදී සියලු keys review කිරීම emergency checklist එකේ තබන්න.

8. App සහ login page සත්‍යාපනය කරන්න

App store එකේ publisher name, install source, reviews පමණක් නොව permissions සහ update history බලන්න. Search advertisement එකකින් login page එකකට නොගොස් saved entry එකක් හෝ already installed app එක භාවිතා කරන්න. Password manager එක expected site එකේ පමණක් autofill නොකරනවා නම් domain mismatch එකක් ගැන warning signal එකක් විය හැක.

Browser URL bar එකේ spelling සහ connection status බලන්න. Secure-looking logo, padlock image හෝ cloned page design එකක් ownership proof එකක් නොවේ. QR code එකක් scan කිරීමට පෙර එය login, wallet connect හෝ withdrawal request එකක්ද කියවන්න.

9. Support impersonation හඳුනාගන්න

Scammer කෙනෙකු account freeze, KYC failure, withdrawal problem හෝ “safe wallet” කතාවක් භාවිතා කර urgency නිර්මාණය කළ හැක. මෙම requests red flags වේ:

  • private message එකකින් seed phrase, OTP හෝ recovery key ඉල්ලීම
  • remote-control හෝ screen-sharing app install කිරීමට කියීම
  • funds “verification wallet” එකකට යැවීමට කියීම
  • withdrawal unlock fee එකක් private wallet එකකට ඉල්ලීම
  • guaranteed recovery හෝ guaranteed profit පොරොන්දුව

Support conversation එකක් සැක සහිත නම් reply කිරීම නවතා account interface එකෙන් support channel එක නැවත ආරම්භ කරන්න. Scammer ට transaction screenshots යවන විට email, UID, balances සහ address history වැනි තොරතුරු leak විය හැක.

10. Withdrawal කිරීමට පෙර checklist එක

  1. Asset සහ network දෙක receiving wallet එක support කරනවාද?
  2. Address, memo/tag සහ chain එක නිවැරදිද?
  3. Clipboard paste පසු address එක වෙනස් වී නැද්ද?
  4. Large amount එකකට පෙර small test transfer එකක් කළාද?
  5. Fee සහ minimum withdrawal amount කියවුවාද?
  6. Device එක malware හෝ remote session එකකින් තොරද?

Crypto transfers බොහෝවිට ආපසු හැරවිය නොහැකි නිසා confirm button එකට පෙර pause එකක් තබන්න. Video call හෝ chat pressure අතර withdrawal නොකරන්න.

සැක සහිත login එකක් ලැබුණොත්

Clean, trusted device එකකින් account activity පරීක්ෂා කරන්න. හඳුනා නොගත් devices/sessions revoke කර, available emergency disable/freeze control එක භාවිතා කිරීමට current instructions අනුගමනය කරන්න. Password වෙනස් කර 2FA factors, email security, API keys සහ withdrawal addresses review කරන්න.

Unexpected withdrawal එකක් හෝ unauthorized change එකක් පෙනේ නම් account interface එකෙන් support contact කර timestamps, transaction IDs සහ screenshots සංරක්ෂණය කරන්න. Evidence screenshot එක share කිරීමට පෙර email, phone, UID, balances, QR codes, tokens සහ internal URLs mask කරන්න. Funds recover වන බවට පොරොන්දු දෙන private recovery service එකකට තොරතුරු හෝ මුදල් නොදෙන්න.

මාසික security review එක

මාසයකට වරක් හෝ sensitive change එකකට පසු මෙම items review කරන්න:

  • authorized devices සහ login activity
  • 2FA/passkey සහ backup factor status
  • email security සහ recovery options
  • withdrawal allowlist
  • API keys සහ permissions
  • installed browser extensions සහ apps
  • anti-phishing code email එකක නිවැරදිව පෙනෙනවාද

Security review එක credentials display කිරීමක් නොවේ. Recovery phrase හෝ OTP screenshot කර “backup test” නොකරන්න. Control එකක් තවම ක්‍රියා කරනවාද verify කරන අතර secret material හෙළි නොකිරීමයි අරමුණ.

නිල හා ප්‍රාථමික මූලාශ්‍ර: Binance Academy — Secure Your Binance Account, Binance — Account security video, Binance Academy — Common Scams, CBSL warning. මෙය ආරක්ෂක අධ්‍යාපනය පමණි. Menu names, available controls සහ regional access වෙනස් විය හැකි බැවින් live interface එකේ current instructions කියවන්න.

ආරක්ෂාවෙන් පසු මූලික පාඩම