Exchange Security Tips to Protect Your Crypto Accounts

tips for exchange security

Exchange Security Tips to Protect Your Crypto Accounts

Use hardware security keys for two-factor authentication, give each exchange its own email address, and store unique strong passwords in a password manager. Never use your phone number for 2FA, since phone-based codes are open to SIM-swapping attacks that can hand attackers your account.

Make your security key the only 2FA method allowed on your email account, because email is the recovery point for the rest of your services. Also turn on withdrawal whitelisting on every exchange so funds can only move to addresses you have pre-approved, and add your most-used wallets to reduce waiting time.

For coins you are not actively trading, move them to a hardware wallet such as a ledger for offline storage. Users also suggest pairing the hardware wallet with metamask to interact with dapps and protocols instead of creating a new metamask-based wallet.

Security checklist

  1. Get a YubiKey for 2FA Buy one plus a backup; use the YubiKey Authenticator app for TOTP where keys are not directly supported.
  2. Never use phone number 2FA Phone-based codes are susceptible to SIM-swapping attacks, even as a backup option.
  3. Lock email to a security key only Email is the recovery point for other services, so make the key the sole 2FA method.
  4. Use a unique email per exchange Applies to exchanges you use often, leave crypto on, or link your bank to.
  5. Set up a password manager Create unique strong passwords for everything; bitwarden is one recommendation, and secure the manager with a security key.
  6. Enable withdrawal whitelisting Restricts withdrawals to pre-approved wallet addresses; add your most-used wallets to minimize delays.
  7. Store holdings in a hardware wallet Keep funds you are not actively trading offline, and use the device with metamask for dapps instead of a new metamask-based wallet.
Exchange Security Tips to Protect Your Crypto Accounts — infographic

Multi-Factor Authentication

Use YubiKeys for 2FA where supported. YubiKeys provide a strong form of two-factor authentication, and for exchanges that don't directly support them, Users suggest using the YubiKey Authenticator for timed one-time passwords (TOTP). "Buy a yubikey and backups. Use it for 2 factor wherever its supported."
Avoid phone numbers for 2FA. Phone-based 2FA is susceptible to SIM-swapping attacks, which can compromise accounts. "NEVER EVER EVER USE YOUR PHONE NUMBER FOR 2 FACTOR AUTHENTICATION, EVEN AS A BACK UP OR SECONDARY OPTION."
Set security key as the sole 2FA for your email. Email accounts are often the recovery point for other services, so securing them with the strongest possible 2FA is crucial. "Set up your security key as the ONLY 2 factor method that can be used to get in your email."

Account Management

Use unique email addresses per exchange. This minimizes the risk of a breach on one exchange affecting others. "Use a unique email address for every exchange you use often, leave crypto on, or leave your bank linked to."
Implement a password manager with unique, strong passwords. A password manager helps create and store complex passwords, and it should also be secured with a security key. "Get a password manager and use unique passwords to everything. I highly recommend bitwarden but use what you like."
Enable whitelisting for withdrawals. Whitelisting withdrawal addresses ensures funds can only be sent to pre-approved wallets. "Turn on whitelisting for all exchanges and make sure and add your wallets that you most often use to minimize waiting."

Hardware Security

Utilize hardware wallets for storing cryptocurrency. For funds not actively being traded, a hardware wallet provides a more secure offline storage solution. "Get a ledger or other supported hardware wallet and use that to interact with dapps and protocols through metamask instead of using a new metamask based wallet."

Are you looking for security tips for cryptocurrency exchanges specifically?

Bottom line

For securing cryptocurrency exchanges, Users emphasize using hardware-based multi-factor authentication, unique email addresses, and strong password management.

FAQ

Is phone number 2FA safe for crypto exchanges?
No. Phone-based 2FA is vulnerable to SIM-swapping attacks, and users advise against using your phone number for 2FA even as a backup or secondary option.
What is the best 2FA method for crypto exchanges?
A hardware security key like a YubiKey, ideally with a backup key. For exchanges that do not support them directly, use the YubiKey Authenticator app for timed one-time passwords.
Why should I use a different email for each exchange?
A unique email address per exchange means a breach on one platform cannot spill over to others. Users recommend this especially for exchanges you use often, leave crypto on, or have your bank linked to.
What is withdrawal whitelisting on an exchange?
It restricts withdrawals to pre-approved wallet addresses only. Add the wallets you use most often so you also minimize waiting time when moving funds.
Should I keep crypto on an exchange long term?
Users suggest moving funds you are not actively trading to a hardware wallet, which keeps them offline and away from exchange risk. A ledger or other supported hardware wallet can also be used to interact with dapps and protocols through metamask.
What password manager should I use for exchange accounts?
Any reputable password manager works as long as it generates unique, strong passwords for every account. One user recommends bitwarden, and advises securing the password manager itself with a security key.

Comments (0)

No comments yet. Start the conversation.