If you keep coins on an exchange, your account is a vault door with an email address for a key. Crypto scams and hacks have cost victims well over $10 billion in recent years, and exchange logins are the most concentrated target of all: one password controls everything you hold there. The good news is that account security is a solved problem — a specific, boring checklist. This is that checklist, in priority order.
Two-factor authentication: app, never SMS
Two-factor authentication (2FA) means logging in requires something you know (your password) plus something you have (a code only your device can generate). Every major exchange offers it; turn it on before anything else. But the type matters enormously:
- Authenticator app or hardware key. Codes are generated on your device by an app (Google Authenticator, Authy, 1Password) or a physical key. Nothing travels over the phone network. This is the standard.
- SMS codes. Better than nothing, and dangerously weak. The attack is the SIM swap: the criminal calls your mobile carrier, impersonates you using scraps of leaked personal data, and convinces support to port your number to a SIM they control. Your “secure” codes now arrive on the attacker’s phone. Notice that nothing about this requires hacking you — it’s social engineering of the carrier, which is why careful people still lose accounts this way.
Switch to app-based 2FA today, then ask your carrier for a port-out PIN (a code required before your number can be transferred). If an exchange only offers SMS 2FA in 2026, that tells you something about their security budget.
A unique password, kept in a password manager
Exchange passwords fall two ways: phishing, and credential stuffing — attackers trying email/password pairs leaked in other sites’ data breaches. If your exchange password exists anywhere else, assume it’s already sitting in a text file on someone’s server. The fix is unglamorous: a long random password, unique to that exchange, generated and stored by a password manager (Bitwarden, 1Password, and similar). You’ll never type it, so it can be 30 characters of gibberish. Bonus: a password manager won’t autofill your credentials on a lookalike phishing domain — a quiet, effective tripwire.
Your email is the real vault
Here’s what most people miss: whoever controls your email controls every account attached to it. Password resets, withdrawal confirmations, new-device approvals — they all flow through your inbox. An attacker inside your email can walk through your exchange’s account recovery, no exchange 2FA required. So your email account needs its own unique password and its own app-based 2FA, configured before the exchange’s. If you can tolerate one more inbox, use a dedicated email address for crypto only: it shrinks your exposure to random breach lists, and it makes phishing obvious — a “security alert from your exchange” arriving at your personal address is fake by definition.
Turn on the exchange’s own security features
Most users never open the security settings page. It takes ten minutes:
- Anti-phishing code. You set a personal phrase in settings; every genuine email from the exchange then includes it. Any message claiming to be from the exchange without your code is fake, full stop. This single feature neutralizes most phishing.
- Withdrawal address whitelist. Restrict withdrawals to addresses you’ve pre-approved, with a 24–48 hour time-lock on adding new ones. Even an attacker fully inside your account can’t send your coins to their wallet. Enable any “withdrawal lock after password/2FA changes” option too.
- Login and withdrawal alerts. Turn on email or push notifications for new logins, new devices, and every withdrawal. A surprise “new sign-in” email is the earliest warning you’ll ever get.
API keys: least privilege, or none
Trading bots and portfolio trackers connect via API keys — and a key is a bearer credential: whoever holds it can act as your account within its permissions. The rules are short. Never enable withdrawal permission on any API key (nothing legitimate needs it). Grant only what the tool actually requires — read-only for trackers. Restrict keys by IP address if the exchange allows it. And delete keys the day you stop using the tool; every year brings fresh “my old bot key leaked” stories ending in emptied accounts.
Device hygiene, briefly
- Keep your phone and computer updated — the updates you’re deferring are mostly security patches.
- Don’t install random “trading tools” or browser extensions; clipboard-hijacking malware that swaps copied wallet addresses is common.
- Bookmark your exchange and log in only via the bookmark. Search ads for exchange names are routinely bought by phishing operations — our scam-spotting guide shows what these lookalikes look like.
What support can and cannot undo
Know this before you need it. Exchange support can freeze your account when you report a compromise, reset credentials after identity verification, and sometimes reimburse users after a platform-wide hack. Support cannot reverse a blockchain transaction. If an attacker withdraws your BTC to their own address, that transfer is final the moment it confirms — the coins are gone, and no help desk on Earth can claw them back. That asymmetry is the entire argument for whitelists and time-locks: they convert “irreversible in minutes” into “impossible without a waiting period you’ll be alerted to.”
And the long-term answer to exchange risk is the oldest line in crypto: keep only what you’re actively trading on the platform, and move savings to a wallet you control — our wallet setup guide walks through it.
Where to go next
Choosing where to trade? Our exchange comparison tracks volumes and trust scores across 30 major platforms. Then read how to spot crypto scams for the phishing patterns that bypass everything above, and set up your own wallet for anything you’re holding long-term.
This guide is educational only and is not financial advice. Good security reduces risk; it cannot eliminate it. Read our full disclaimer.