Most exchange account losses do not involve the exchange being hacked. They involve one account, one weak link, and settings that were never changed from the default. This is the list, in the order that removes the most risk per minute spent.
1. Replace SMS two-factor with an authenticator app
Do this first. SMS codes can be intercepted by taking over your phone number, and that attack is industrialised — an attacker persuades or bribes a carrier to move your number, then resets everything tied to it. An authenticator app generates codes on the device itself with no phone number involved. A hardware security key is better still where supported.
2. Use an email address that exists only for this
Your exchange email is a master key: it can usually reset the password. If it is the address you use for everything, it is already in breach databases. A separate address, with its own strong password and its own authenticator-app 2FA, breaks the chain.
3. Turn on a withdrawal address whitelist
This is the most underused setting on any exchange. Once enabled, funds can only leave to addresses you pre-approved, and adding a new one triggers a delay. An attacker with full account access still cannot send anywhere useful. Combined with 2FA it removes most of the value of a compromised login.
4. Enable the withdrawal time lock
Where offered, a mandatory delay on new withdrawal addresses gives you a window to notice and cancel. Attackers move fast precisely because delays defeat them.
5. Set an anti-phishing code
Several exchanges let you set a phrase included in every genuine email. Any message without it is fake. This is a two-minute change that neutralises the most common attack of all — a convincing email leading to a convincing fake login page.
6. Check active sessions and API keys
Log out every session you do not recognise. Then look at API keys, which people forget entirely: a key created for a trading bot or a portfolio tracker may still have withdrawal permission. Delete what you do not use, and make sure anything remaining is read-only unless it genuinely needs more.
7. Turn on every login notification available
Alerts for logins, new devices, password changes and withdrawals. These do not prevent anything — they shorten the time between something happening and you knowing, which is usually what determines whether it can be stopped.
8. Verify the domain, every time
Bookmark the real one and use only the bookmark. Search-result ads for exchange names have repeatedly pointed at lookalike domains. Typing the name into a search box and clicking the top result is how a lot of people arrive at a phishing site with a valid-looking padlock.
9. Do not keep long-term holdings on any exchange
An exchange balance is a claim on a company, not possession of an asset. Every major collapse in this industry took customer funds with it, and none of them announced it in advance. Keep trading balances on the exchange and long-term holdings in self-custody. Note what our exchange comparison shows about this: proof-of-reserves attestations prove assets existed at a moment in time and say nothing about liabilities — which is exactly what went wrong at the venues that failed.
10. Write down the recovery path before you need it
Which email, which authenticator, where the backup codes are, what identity documents the account was opened with. Losing access to an authenticator app with no backup codes locks you out of your own funds, and recovery on some venues takes weeks. This is not a security setting so much as insurance against the security settings working too well.
The shape of the risk
None of this protects against the exchange itself failing, and no setting can. That is a different risk, addressed by not leaving more on any platform than you would be willing to lose — and by choosing venues with real regulatory accountability rather than the lowest fee. The ten items above address the risk you actually control: someone else getting into your account.
Fifteen minutes, once. It is the best return on time available anywhere in crypto.