Security guide

Crypto Exchange Safety Checklist

No exchange or security setting can remove market, custody, or fraud risk. This checklist focuses on the account controls and habits that can reduce avoidable loss before funding, while trading, and after a suspected compromise.

Reviewed and last updated: June 15, 2026

1. Verify the provider before registering

Confirm the official domain, legal entity, regional availability, and app publisher. Search results, social posts, direct messages, and sponsored ads can lead to impersonation sites, so type or bookmark the verified address instead of trusting a message link.

Read current account, custody, and withdrawal terms. A familiar brand name does not guarantee that every product is available in your location or that assets receive bank-style protection.

  • Bookmark the verified domain
  • Check the app developer and download source
  • Confirm the legal entity serving your country
  • Review withdrawal and account recovery rules
  • Reject guaranteed return or urgent payment claims

2. Protect the email and password first

Use a unique password that is not shared with email, banking, social media, or another exchange. A reputable password manager can generate and store a long random password without relying on memorable patterns.

The email account used for exchange recovery deserves equally strong protection. Secure it with a unique password and multi-factor authentication, review forwarding rules and recovery methods, and remove unfamiliar sessions. An attacker who controls email may be able to reset exchange credentials.

3. Use the strongest practical authentication

Enable a security key or another phishing-resistant method where the exchange supports it. An authenticator app is generally preferable to relying only on SMS, but no method makes an account invulnerable.

Store backup or recovery codes offline in a protected place. Never read a one-time code to support, enter it after following an unsolicited link, or approve a login prompt you did not initiate.

  • Enable strong MFA on both exchange and email
  • Save recovery codes away from the logged-in device
  • Set an anti-phishing code if available
  • Review authorized devices and active sessions
  • Do not approve unexpected prompts

4. Add withdrawal and transfer controls

Configure a withdrawal address allowlist, withdrawal lock, or delayed address changes where available. These controls can add time to an attack response, but they only help when configured before an incident.

For every transfer, generate the deposit details from the receiving platform, then match the asset, exact network, address, and memo or tag. Send a small test when fees and minimums make it practical, and wait for it to be credited before sending more.

  • Check deposit and withdrawal status
  • Match the exact blockchain network
  • Verify the full address and memo or tag
  • Review the amount and fee
  • Keep the TXID and transaction record

5. Treat unexpected contact as hostile

Exchange support should not need your password, seed phrase, private key, or remote control of your device. Be skeptical of anyone claiming that an account is frozen, funds must be moved to a safe wallet, taxes must be prepaid in crypto, or an additional transfer will unlock a withdrawal.

The FTC warns that legitimate businesses and government agencies do not unexpectedly demand cryptocurrency to protect money or solve an account problem. Stop and independently contact the organization using a verified website or app.

6. Limit custody and monitor the account

Keep only the amount needed for your intended exchange activity, based on your ability to manage self-custody safely. Moving assets to a wallet introduces separate seed phrase, backup, device, and transfer risks, so it is not automatically safer for every beginner.

Turn on login, trade, API, and withdrawal notifications. Periodically review sessions, API keys, withdrawal addresses, security settings, and account history. Export records needed for reconciliation or taxes.

7. Respond quickly to a suspected compromise

Use a clean device and the bookmarked official domain. Change the exchange and email passwords, revoke unfamiliar sessions and API keys, freeze withdrawals if the platform provides that control, and contact official support with accurate timestamps and transaction details.

If funds were sent, preserve the TXID, addresses, messages, screenshots, and case numbers. Report impersonation or fraud to the relevant exchange and local authorities. Do not pay a recovery service that contacts you unexpectedly or promises a guaranteed reversal.

Common questions

Frequently asked questions

Is two-factor authentication enough to secure an exchange account?

No. Combine strong MFA with unique credentials, protected email, phishing awareness, session and API review, withdrawal controls, transfer checks, and careful custody decisions.

Should I leave crypto on an exchange?

Exchange custody can simplify trading and recovery but introduces counterparty and access risk. Self-custody adds full key-management and transfer responsibility. Choose only after understanding both risk models.

What should I do after entering details on a suspicious site?

Use a clean device and the bookmarked official services. Change affected passwords, secure email, revoke sessions and API keys, review withdrawal settings, freeze activity where possible, and contact official support.

Will exchange support ask for my seed phrase?

No legitimate exchange support process should require your wallet seed phrase or private key. Anyone who obtains it may control the wallet.

Is a small test transfer completely safe?

No. It can catch some address, network, memo, and operational mistakes, but it does not remove exchange, malware, address-replacement, or blockchain risk.

Primary references

Official sources checked

These official pages were reviewed on June 15, 2026. Exchange policies can change, so open the source before acting.

  1. FTCWhat To Know About Cryptocurrency and Scams
  2. BinanceGeneral Risk Warning