exchanges

Exchange Account Security: The Settings Worth Ten Minutes

Six settings on a trading account, most of which are off by default. Together they defeat the attacks that actually happen.

C
Chris DelaneySeptember 9, 2026 · 2 min read

Most account compromises do not involve breaking the platform. They involve reaching your account through your email, your phone number, or a page that looked like the login screen.

These six settings address that, and most are not enabled by default.

1. Replace SMS two-factor

An authenticator application at minimum, a hardware security key where supported.

SMS is defeated by a phone call to your carrier, which is a documented and repeated attack. A hardware key additionally defeats phishing, because it verifies the site before responding, which no other method does.

Back up the authenticator setup secrets when enabling. Losing the phone without them means a recovery process measured in weeks.

2. Remove the phone number as a recovery option

The most common configuration error. A stronger second factor is undermined by leaving a weaker fallback attached to the same account.

If the platform requires a number, set a carrier port-out PIN as well, which prevents number transfer without an additional code and takes five minutes.

3. Enable a withdrawal address allowlist

Where offered, this restricts withdrawals to addresses you have pre-approved, usually with a delay before a new address becomes usable.

It converts an instant theft into a delayed one you may be able to interrupt. This is the single most effective setting on the list.

4. Use a dedicated email address

Not published, not reused anywhere, protected by a hardware key.

Email is the recovery path for everything else. An attacker with email access can reset most things, which makes it the actual perimeter.

5. Set an anti-phishing code, if available

Some platforms let you set a phrase included in every legitimate email. Messages without it are fraudulent, which is a fast and reliable filter against the most common approach.

6. Review active sessions and API keys

Sessions on devices you no longer use, and API keys created for tools you have stopped using, both persist indefinitely.

Any API key with trading or withdrawal permission is a standing risk. Read-only is the correct level for anything that only needs to observe.

The habits that go with them

Navigate by typing the address or a bookmark you created. Never through a link in an email or a message. Search advertisements for exchange names have been used to deliver phishing pages.

Treat unsolicited contact as fraudulent. Real platforms do not send the first direct message, and real support never needs your recovery phrase.

Keep the balance small. All of the above reduces the probability of compromise. Sizing the account so that losing it entirely would be an annoyance is the part that limits the consequence.

What good platform security looks like from outside

Support for authenticator applications and hardware keys, address allowlists with a delay, session management, granular API permissions, and published documentation describing all of it.

Venues meeting that standard, including venues supporting external addresses, document these in their security pages, and reading that page before opening an account is a two-minute filter that is worth applying.

How this review was done

Products covered here are bought at full retail price and used for real transactions before anything is written. There are no affiliate links on this site, no sponsored placements and no review units. If that ever changes, it will be disclosed at the top of the article.