How-to guide · Before you place a trade

How to secure a crypto exchange account

By · Published

Quick answer. Secure the email inbox first, because it holds every reset link. Then set a unique password, turn on an authenticator app or passkey rather than SMS, and add an anti-phishing code. Finally restrict withdrawals to saved addresses and put a delay on new ones — reading what each switch does, since the row named “whitelist” restricts nothing on some exchanges. Prove it all with one small test withdrawal.

Most security checklists are a list of switches to flip, which is fine until you discover that two large exchanges use nearly the same word for switches that do opposite things. On one, turning on the “withdrawal whitelist” means coins can only ever leave to addresses you approved. On the other, it means the exchange stops asking for your two-factor code. Same words, and only one of them is the safety step people think they are taking. This guide walks the setup in the order the pieces actually depend on each other, and names the traps by exchange.

An exchange account security settings panel with five rows: Two-Factor Authentication, Anti-Phishing Code, Withdrawal Address List and New Address Lock switched on in teal, and Daily Limit still switched off in coral and outlined in gold as the one setting left to fix

KEY TAKEAWAYS

What actually has to fail before someone can take your coins?

Almost nobody loses an exchange balance to a broken password. They lose it because one of four separate things failed, and only one of them lives on the exchange at all: the password, the second factor, the email inbox that receives every alert and reset link, and the rule that decides which addresses are allowed to receive a withdrawal.

That last one is the least understood and does the most work. The first three decide whether a stranger can get in. The fourth decides whether getting in is worth anything — because if coins can only ever leave to an address you approved days ago, a hijacked account is an annoyance rather than a loss.

It is worth being precise about the threat this defends against, because it is not the one most people picture. The realistic modern attack is not someone guessing your password; it is malware or a convincing fake login page handing an attacker a live session, at which point the password and the login prompt have both already been passed. What stands between that session and your balance is only the checks applied at the moment of withdrawal.

WHAT ONE SWITCH IS WORTH

Checks standing between an already-hijacked session and coins leaving the account. Our own count, based on the behaviour each exchange documents — read Aug 2026.

Account stateChecks at the withdrawal stepTime you get to react
Password only, no second factor0none
Email code plus authenticator app2none
Binance, whitelist on, 72-hour limit set2, and an unknown address cannot be used at all72 hours
Bybit, only Withdrawal Address Whitelist on0 for whitelisted addresses — Bybit states the email code and 2FA are “no longer required”none
Bybit, address book plus new-address lock on2, and an unknown address cannot be used at all24 hours

The fourth row is the one to sit with. It is the row most people believe they are buying when they follow a generic security checklist.

Why does “turn on the withdrawal whitelist” mean opposite things on Binance and Bybit?

Because the two exchanges gave nearly the same name to switches that do different jobs, and no official page tells you so — each one honestly describes its own feature, and the mismatch only appears when you put them side by side.

On Binance there is one switch. Its help page says that when you enable it, “you can only withdraw to addresses on your whitelist.” Changing that list, or turning the feature off, suspends withdrawals for a period you choose: 24, 48 or 72 hours. One click buys you both a restriction and a delay.

On Bybit the switch with almost the same name does something else entirely. Its purpose, in Bybit's own words, is that “the email verification code and 2FA verification code will no longer be required when performing withdrawal requests.” It is a convenience feature. It removes friction from addresses you have verified; it does not stop coins going anywhere.

The word "whitelist" does two different jobsSide by side comparison. On Binance one switch named Withdrawal Whitelist limits destinations and adds a 24 to 72 hour delay. On Bybit the switch of nearly the same name instead removes the email code and 2FA prompt, while the limit and the delay sit on two separately named switches.BinanceBybitSwitch called "whitelist"Withdrawal WhitelistWithdrawal Address WhitelistWhat that switch doesLimits where coins may goDrops email code and 2FABlocks an unknown addressYesNoDelay on address changes24 / 48 / 72 hoursNone on this switchWhere the limit livesSame switchWithdraw via Address BookWhere the delay livesSame switchNew Address Withdrawal LockRead the row description, not the switch name.
Two exchanges, one word. On Binance the switch labelled Withdrawal Whitelist restricts destinations and adds the 24 to 72 hour delay. On Bybit the similarly named switch instead drops the email code and the 2FA prompt, and the restriction and the delay live on two other switches entirely.

Read carefully, this is not quite “Bybit is less safe.” Bybit does offer both missing pieces — they are just named differently. Withdraw via Address Book is the restriction: with it on, “traders will not be able to enter a new wallet address once they enter the withdrawal window.” New Address Withdrawal Lock is the delay: it bars withdrawals to freshly added addresses, and it leaves alone any address added at least 24 hours before you switched it on.

The real hazard is subtler than a missing feature, and worse. Someone who reads a generic checklist, opens Bybit, finds the row that matches the words “withdrawal whitelist” and flips it has done something that feels like the safety step and is not one. They now have fewer verification prompts than before and no restriction at all — and, because the task felt complete, they will not come back to it.

The lesson generalises past these two names. Judge every row by the sentence describing what it does, not by the noun on the switch. Bybit's own product design quietly admits the gap: the Daily Whitelist Withdrawal Limit exists precisely because the whitelist path skips verification, and something has to cap how much can leave that way.

Which second factor should you turn on, and what does each one actually stop?

Prefer an authenticator app or a passkey over SMS. The reason is specific rather than general: an SMS code is delivered to a phone number, and a phone number can be moved to another SIM card by someone who convinces a carrier's support agent. That attack never touches your password and never touches your device.

An authenticator app generates codes on the device itself, so there is nothing to intercept in transit and no carrier employee in the loop. A passkey goes further and ties the login to the genuine domain, which means it will simply refuse to work on a lookalike site — the one protection on this page that defends you even when you have been fooled.

Two practical points that guides tend to skip. First, whatever you enable, enable it on the email account too; Binance's own security tips list says so explicitly, and it is the step most often skipped because the email account does not feel like part of the exchange. Second, save your recovery codes somewhere you can reach without the phone — the failure mode nobody plans for is not being robbed, it is dropping the only device that can log you in.

What does an anti-phishing code catch, and what does it miss?

An anti-phishing code is a short phrase you set inside the exchange, which the exchange then prints in every genuine message it sends you. A message without it did not come from them. Binance includes the code in emails and SMS; Bybit does the same.

Binance's rules for the code are specific and worth knowing before you sit down: 6 to 8 characters, containing at least three of the four character types (uppercase, lowercase, digits, underscores), and no special characters at all. Bybit does not publish a character rule. These were the stated requirements when we read the pages in August 2026 — check the field's own hint text, since it is the thing that will reject you.

Now the limit, which matters more than the feature. The code proves a message is genuine. It does not prove a genuine message is safe to act on, and it does nothing at all about the attack that does not arrive by email — a fake site you reached through a search advert, a malicious browser extension, a support “agent” who messages you first. Treat a missing code as a definite red flag and a present code as no evidence of anything much.

What order should you do all of this in?

Order matters here more than it looks, because several of these steps protect each other. Securing the exchange before the email account is like fitting a deadbolt while leaving the window open: the email inbox can reset the exchange password, so it is the weaker of the two doors and has to be closed first.

Seven steps, in dependency orderA numbered list of seven setup steps. Each step assumes the step above it is already done, which is why working out of order leaves gaps that still feel like completion.1Secure the email account firstIt receives every alert and every reset link, so it is the weaker door.2Set a unique password, kept in a managerReuse is what turns someone else’s data breach into your loss.3Turn on an authenticator app or a passkeyA swapped SIM card defeats SMS codes without touching your password.4Set an anti-phishing codeBinance asks for 6 to 8 characters, at least three of four character types.5Restrict withdrawals to saved addressesCheck what the row does. The switch named whitelist does not always do this.6Lock newly added addresses for 24 hoursThis is the step that gives you time to act on an alert.7Send one small test withdrawalProves the settings still allow the transfer you will need later.Step 1 before step 3: 2FA on the exchange cannot protect an inbox anyone can open.
The seven steps in dependency order. Step 1 comes before step 3 for a concrete reason: two-factor authentication on the exchange cannot protect an inbox that anyone can open, and that inbox holds the reset link. The final step is marked as a caution because a test withdrawal is the only one that costs a fee.

Step seven is the one people skip and the only one that proves anything. Every setting above it is a claim; a small test withdrawal to an address you control is the check. It is also the moment you discover, cheaply, that you locked yourself out of a transfer you actually needed — which is a far better time to find out than during a rush.

That test costs real money, so it is fair to ask whether it is worth it. On a transfer of $10,000 with a network fee of roughly $1, sending a small test first adds exactly one more fee: about $1 on $10,000, or 0.01%. Use your own numbers rather than ours, since network fees move constantly — but at that order of magnitude the arithmetic rarely argues against testing.

What a withdrawal settings page is really askingThree rows, three different jobs. Only one of them stops a thief. What a withdrawal settings page is really asking Three rows, three different jobs. Only one of them stops a thief. Security Withdrawal API keys Address Management Whitelist Limits Restrict withdrawals to saved addresses ON The row that stops a thief Lock newly added addresses 24 hours Turns an alert into time Daily amount allowed to skip 2FA 0 Zero, not a convenient figure Enable Disable Wording differs by exchange. Judge each row by what it does, not what it is named. Every change here should send you an email you actually read.
What a withdrawal settings page is really asking, stripped of brand names. The top row restricts where coins may go, the middle row sets the delay on newly added addresses, and the bottom row caps the daily amount allowed to skip verification — shown at zero, which is the setting most people should want. Three rows, three different jobs.

When is this advice wrong?

Three situations, and they are common enough to name.

If you actively trade and withdraw often, a 72-hour lock on address changes is not a safety feature, it is an outage. Pick 24 hours, add the addresses you genuinely use while you are calm, and accept that the setting is tuned for someone who moves coins rarely.

If the address you whitelisted is one you might lose control of — a wallet on a phone you will replace, an account at a second exchange you may close — then the restriction is pointing at a destination that may not be yours by the time you need it. Whitelists want addresses whose keys you will still hold in a year.

If the balance is meant to sit still for years, none of this is the right answer. Every control here reduces the damage from a compromised exchange account; none of them removes the fact that the exchange holds the keys. At that point the question is not which switches to flip but whether the coins should be on an exchange at all.

Common mistakes

Flipping the switch whose name matches the checklist. The whole point of this page. Names differ between exchanges; the row's description is the thing to read.

Securing the exchange and not the email account. The inbox holds the reset link. An exchange with perfect settings and an unprotected inbox is protected by nothing.

Keeping SMS as the second factor because it was easier to set up. It is the one method that can be defeated without your password and without your device.

Storing recovery codes only on the phone that runs the authenticator. When that phone is the thing you lost, the backup is gone with it.

Treating a message as genuine because it carries your anti-phishing code. The code proves origin. It says nothing about whether the instruction inside is a good idea, and attacks that skip email entirely never touch it.

Setting the daily unverified limit to a “convenient” number. Whatever figure you pick is the amount that can leave without a prompt. For most people the right figure is zero.

Turning everything on and never testing it. Settings you have not tested are a belief, not a defence — and the cost of testing is roughly one extra network fee.

Frequently asked questions

Is SMS two-factor authentication good enough for a crypto exchange?

It is much better than nothing and much worse than the alternatives. Its specific weakness is that codes go to a phone number rather than a device, and a phone number can be transferred to a new SIM by someone who persuades a carrier's support staff — an attack that needs neither your password nor your phone. If your exchange requires SMS, keep it, add an authenticator app or passkey on top, and ask your carrier about a port-out PIN.

Does a withdrawal whitelist stop every theft?

No. It restricts destinations, which is a large share of the damage, but an attacker with a live session may try to add an address, exploit an API key you forgot about, or persuade you to approve an address yourself. It also does nothing about the exchange itself failing. It works best combined with a delay on new addresses and alerts you actually read.

What is the difference between Bybit's Withdrawal Address Whitelist and Withdraw via Address Book?

They sound alike and do opposite things. The Withdrawal Address Whitelist removes the email code and 2FA prompt for addresses you have verified — convenience. Withdraw via Address Book stops you entering any address that is not already saved — restriction. If you want the protection people usually mean by “whitelist”, the second one is the switch, and the New Address Withdrawal Lock adds the delay.

Should I keep recovery codes in my password manager?

It is a reasonable choice for most people, with one caveat: if the manager is protected by the same second factor you are backing up, the backup and the thing it backs up can fail together. Keep at least one copy somewhere that does not depend on any device you use daily, and never in a plain note, a photo library, an email draft or a chat.

How often should I review these settings?

Whenever something they depend on changes — a new phone, a new number, a new email address, a password change, or travel that triggers unusual-login alerts. Beyond that, a quick look once a month is enough for the settings themselves. Alerts are different: those are read the moment they arrive, from the app or a bookmark you saved, never by clicking a link in the message.

Go deeper: Lesson 5 — choosing a trustworthy exchange · How-to: withdraw crypto safely, open a Binance account, open a Bybit account, open an OKX account · Compare venues: exchanges
Risk reminder: this is education, not advice, and not individualised security consulting. These controls reduce the damage from a compromised exchange account; none of them removes the fact that the exchange holds the keys. Most retail traders lose money.
Written by the TradingPrimer Team · Published 2026-08-30 · Sources: Binance Support, How to Manage Withdrawal Settings for My Binance Account?, What Is an Anti-Phishing Code and How to Set It up on Binance? and Securing Your Trading Account; Bybit Help Centre, How to Manage Your Withdrawal Security and How to Set Up the Anti-Phishing Code — all read 30 Aug 2026. Interface labels, limits and availability change and vary by region — verify current details in the exchange’s own settings before relying on them. · Disclosure

← All how-to guides