CoinFeeHub reference
Set up your exchange account security in 15 minutes: feature by feature for 8 exchanges
Four settings do most of the work on a custodial exchange: an authenticator app or passkey, a withdrawal whitelist, an anti-phishing code and a unique password. All six custodial exchanges below document an authenticator app and an address whitelist; anti-phishing codes and passkeys are documented on five of them. Hyperliquid and Aster are wallet-based, so security there means protecting the wallet itself. “Not documented” means we did not find it on the official pages checked — not that the feature is absent.
Feature matrix
| Exchange | Authenticator app | Passkey / security key | Withdrawal whitelist | Anti-phishing code | Withdrawal lock after changes | Official source |
|---|---|---|---|---|---|---|
| Binance | Yes | Passkey; can be required for login and withdrawals. Security keys (e.g. YubiKey) supported | Yes; optional 24/48/72-hour hold on new whitelist addresses | Yes | 24–48 hours after some security changes, such as a password change | Whitelist · Passkey · Lock · Code |
| Bybit | Yes (Google 2FA) | Passkey (FIDO) | Yes; address-book-only mode and a 24-hour lock on new addresses | Yes | 24 hours on newly added addresses; optional withdrawal delay | Security (updated 2026-05-23) · Withdrawals |
| OKX | Yes | Passkey (Face ID / fingerprint) | Allowlist; new addresses verified for 30 days | Yes | Optional 24-hour lock on new allowlist addresses | Security · Allowlist (updated 2026-08-14) |
| Gate | Yes (Google Authenticator) | Passkey, including FIDO2 USB keys | Yes; saved and trusted addresses | Yes | 24 hours after setting, changing or resetting any security setting | Security · Passkey · Whitelist · Lock |
| BingX | Yes (two of email, phone, Google Authenticator) | Passkey; required for login since 2025-07-18 | Yes; address book | Yes | Not documented | Safety guide · Passkey 2025-07-18 |
| MAX | Yes; 2FA mandatory for login and withdrawals | Not documented | Yes | Not documented | Not documented | Security measures · 2FA |
| Hyperliquid | Not applicable — your wallet signs | Hardware wallet suggested (Ledger, Trezor, Keystone) | Not applicable | Not applicable | Not applicable | Docs · API wallets |
| Aster | Not applicable — wallet login | Not documented | Not documented | Not documented | Not documented; bind API keys to a fixed IP | API key docs |
Pages checked 2026-10-07. Step timings are estimates and exclude creating a wallet. Exchanges change settings and menu names; the in-app security centre is authoritative.
The 15-minute checklist
- Authenticator or passkey (3 min). Add an authenticator app or create a passkey, save its backup or recovery codes, sign out and back in to confirm it works, then remove SMS as a 2FA method where the exchange allows it.
- Anti-phishing code (1 min). Choose a code; the exchange then shows it in its emails to you. An email without it is fake — but a correct code does not make a link in that email safe.
- Withdrawal whitelist (4 min). Turn it on, add only addresses you control and enable the new-address lock if offered. No withdrawal address yet? Skip this and do it before your first withdrawal.
- Unique password (2 min). Generate one in a password manager. Expect a 24–48-hour withdrawal hold on Binance and 24 hours on Gate after the change.
- Devices, sessions and API keys (3 min). Remove unknown devices; delete unused API keys; never give an API key withdrawal permission; bind keys to an IP.
- Official channels (1 min). Bookmark the exchange’s site and its verification page (for example Binance Verify or Bybit’s authenticity check).
- Wallet-based exchanges (Hyperliquid, Aster). Keep the main wallet on a hardware device and revoke approvals you no longer use.
Why each step matters: six takeover patterns. If something already went wrong: first-hour response.
Common questions
Passkey or authenticator app?
A passkey is bound to the real site, so a phishing page cannot reuse it. An authenticator code can still be typed into a fake page. Use a passkey where offered and keep the authenticator as backup.
Why can’t I withdraw after changing my password?
Binance suspends withdrawals for 24–48 hours and Gate for 24 hours after security changes, so an attacker who changes your settings cannot withdraw at once.
Does a whitelist stop all theft?
It stops withdrawals to new addresses unless the attacker can also change the whitelist, which usually needs your 2FA and may trigger a lock. Protect the 2FA first.
What if my exchange is “not documented” for a feature?
Check the security centre in the app or ask official support. We list only what the official pages state.
Sources and editorial notes
Official help pages checked 2026-10-07; dates shown where the page states one. The checklist order and timings are CoinFeeHub editorial guidance.
- Binance · Withdrawal settings and whitelist · updated 2025-03-03
- Binance · Must verify using passkey · updated 2024-02-27
- Binance · Withdrawal reactivation after security changes
- Binance · Anti-phishing code
- Binance · Security tips (security keys) · 2024-10-08
- Bybit · Account security · updated 2026-05-23; Withdrawal security
- OKX · Account security guide; Allowlist · updated 2026-08-14
- Gate · Security settings; Passkey · 2026-04-15; Whitelist; 24-hour withdrawal block
- BingX · Safety user guide; Passkey requirement · 2025-07-18
- MAX · Security measures; Google Authenticator 2FA
- Hyperliquid · “I got scammed/hacked”; API wallets
- Aster · How to create an API key
Change note
2026-10-07 · Page created: 8 exchanges × 5 features from official help pages.