Security

Crypto Exchange Security Checklist: 2FA, Anti-Phishing, and Withdrawals

A practical exchange security checklist covering passkeys, 2FA, anti-phishing codes, withdrawal allowlists, device reviews, and the first actions after suspected compromise.

Crypto Exchange Security Checklist: 2FA, Anti-Phishing, and Withdrawals

Exchange account risk comes from more than the platform itself. Email compromise, fake support, malicious apps, SIM swaps, and reused passwords can all expose funds. Use this checklist as a minimum security baseline.

Information checked: 2026-07-12 (UTC+8). Menu names vary by platform; follow the official app or website shown for your account.

15-Minute Security Baseline

  • Use a dedicated email address for financial accounts and secure that mailbox with 2FA
  • Create a unique, long password and store it in a trusted password manager
  • Prefer a passkey or authenticator app; do not rely on SMS alone
  • Set an anti-phishing code to help identify genuine platform email
  • Enable a withdrawal address allowlist and new-address lock when available
  • Remove unfamiliar devices, API keys, and third-party authorizations

When an Account Alert Arrives

Do not click the link in the message. Open the installed official app or manually enter a bookmarked official domain, then check notifications and sign-in history. Legitimate support will not ask you to:

  • Reveal a seed phrase, private key, or full one-time code
  • Install remote-control software
  • Move funds to a so-called safe address
  • Leave the platform for Telegram, LINE, or WhatsApp support

60-Second Withdrawal Check

  1. Confirm asset, network, and receiving platform match exactly.
  2. Compare the beginning and end of the address with the destination page.
  3. Check whether a memo or tag is required.
  4. Send a small test to a new address, confirm receipt, then send the balance.
  5. Check fees and minimum credit amounts so the test is not below the threshold.

If Compromise Is Suspected

  1. From a clean device, change the email and exchange passwords.
  2. Freeze the account or contact official support immediately and cancel pending withdrawals.
  3. Revoke unfamiliar API keys, devices, and third-party access.
  4. Preserve sign-in times, IP details, transaction IDs, email, and chat evidence.
  5. If a seed phrase or private key may be exposed, create a new wallet on a clean device and move remaining assets. Never reuse the old recovery phrase.

Custodial and Self-Custody Risks Differ

An exchange may provide account recovery, but the user accepts platform custody risk. Self-custody gives control of keys, but a lost recovery phrase is normally unrecoverable. Do not assume a small balance is automatically safe; choose based on use, operational skill, and acceptable loss. See crypto wallet types.

Official References

⚠️ No setting removes every risk. Test high-impact actions with a small amount and distrust anyone pressuring you to transfer immediately.