How to secure your crypto exchange account in 2026
A step-by-step hardening guide for Binance, OKX, Coinbase and any other exchange: 2FA, anti-phishing codes, withdrawal whitelists, API keys and session hygiene.
Exchange accounts are the most attacked asset in crypto because one login gives access to everything you hold there. The good news: five settings block the overwhelming majority of account takeovers, and they take under 30 minutes.
1. Replace SMS with strong two-factor authentication
Every major exchange supports at least one of these, from strongest to weakest:
- Hardware security key or passkey (YubiKey, phone passkey). Phishing-resistant: the key only works on the genuine domain.
- Authenticator app (Aegis, Google Authenticator, Authy). Codes rotate every 30 seconds; back up the seed offline.
- SMS. Vulnerable to SIM swapping. Disable it once a stronger method is set.
Set 2FA separately for login, withdrawals and API key creation if the exchange offers granular options. Store the recovery codes on paper, not in your email.
2. Use a dedicated email address
Attackers start with your email. Create an address used only for exchanges, protect it with its own strong 2FA, and never publish it. If your exchange email is not in any public breach (check it), phishing campaigns simply cannot find you.
3. Turn on the anti-phishing code
In security settings, set an anti-phishing code: a phrase that appears in every legitimate email and notification. From then on, any “urgent security alert” email without your phrase is a scam. This single setting defeats the most common attack against exchange users.
4. Lock down withdrawals
- Address whitelist: only pre-approved addresses can receive withdrawals. New addresses take 24 hours to activate, so even a compromised account cannot drain funds instantly.
- Withdrawal 2FA and email confirmation: keep both enabled.
- Daily withdrawal limit: set it to what you realistically need.
Check the whitelist after any suspicious login. Attackers who gain access often add their own address and wait.
5. Treat API keys like passwords
Trading bots and portfolio trackers ask for API keys. The 2019 Binance hack used phished API keys to withdraw 7,000 BTC.
- Create a separate key per application.
- Never enable withdrawal permission unless the tool genuinely needs it (almost none do).
- Restrict by IP address whenever the application has a fixed IP.
- Delete keys for tools you no longer use.
6. Review devices and sessions monthly
Under Security > Device management, remove anything you do not recognise. Enable login notifications and new-device confirmation so a login from an unknown browser needs email approval.
7. Keep the balance small
The most reliable protection is not being a target. Keep only active trading capital on any exchange; move the rest to a hardware wallet. Prefer exchanges with proof of reserves and insurance funds, and read the incident timeline before choosing one.
Quick checklist
| Setting | Where | Status you want |
|---|---|---|
| 2FA method | Security | Authenticator app, passkey or hardware key |
| SMS 2FA | Security | Disabled |
| Anti-phishing code | Security | Set |
| Withdrawal whitelist | Withdrawals | Enabled, 24h lock |
| API keys | API management | IP-restricted, no withdrawal permission |
| Login notifications | Security | Enabled |
| Devices | Device management | Only your own |
Tick these off in the interactive security checklist.
Questions
Is SMS two-factor authentication safe enough for a crypto exchange?
No. SMS codes can be intercepted through SIM swapping, where an attacker convinces your carrier to move your number to their SIM. Use an authenticator app, a passkey or a hardware security key, and remove SMS as a fallback where the exchange allows it.
What is an anti-phishing code?
A short phrase you choose that the exchange includes in every genuine email. If an email claiming to be from the exchange does not contain your phrase, it is fake. Binance, OKX, Bybit, Bitget, KuCoin and most large exchanges support it.
Should I keep my coins on an exchange?
Keep only what you actively trade. Exchanges are honeypots for attackers and, as FTX showed, can fail as businesses. Move long-term holdings to a hardware wallet you control.