Module 4: Staying safe · Lesson 12 of 14
Securing your exchange account
3 min read
You secure an exchange account by layering protections: a unique strong password, two-factor authentication, an anti-phishing code and a withdrawal allowlist. Just as important, you never share your password, codes or API keys with anyone.
Start with the basics
- Unique password: use a long password that you do not use anywhere else, ideally stored in a reputable password manager.
- Secure email: your email account can reset your exchange password, so protect it with its own strong password and two-factor authentication.
Two-factor authentication
Two-factor authentication (2FA) asks for a second proof, beyond your password, when you log in or withdraw. Options usually include:
- Authenticator apps, which generate a fresh six-digit code every 30 seconds.
- Hardware security keys, small physical devices that are very resistant to phishing.
- SMS codes, which are better than nothing but vulnerable to SIM-swap attacks, where a criminal takes over your phone number.
Prefer an authenticator app or hardware key, and store your backup codes offline somewhere safe.
Anti-phishing code
Many exchanges let you set a personal anti-phishing code that appears in every genuine email they send. If an email claiming to be from your exchange does not show your code, treat it as fake.
Withdrawal allowlist
A withdrawal allowlist (sometimes called a whitelist) restricts withdrawals to addresses you have approved in advance. Adding a new address often triggers a waiting period. If someone does break into your account, they cannot simply send your funds to their own wallet.
Example: for example, an attacker steals your password and somehow passes 2FA. With an allowlist and a 24-hour delay on new addresses, you have a day to spot the alert email, lock the account and contact support before any coins can leave.
API keys
API keys let trading bots and tools connect to your account. Treat them like passwords. Grant only the permissions needed, never enable withdrawals for a bot, restrict keys to specific IP addresses where possible, and delete keys you no longer use.
Risk: no genuine exchange employee will ever ask for your password, 2FA codes or API secret. Anyone who does is attempting to steal from you.
Key takeaways
- Use a unique password and protect your email account as carefully as the exchange.
- Choose an authenticator app or hardware key over SMS for 2FA.
- An anti-phishing code and withdrawal allowlist add strong extra layers.
- Never share passwords, 2FA codes or API keys, and never give bots withdrawal rights.
Create a free account to save your progress, take the module quiz and earn a certificate.
Sign up freeEducational content only — not investment advice. Leveraged trading carries a high risk of loss.