CoinFeeHub reference

Set up your exchange account security in 15 minutes: feature by feature for 8 exchanges

Four settings do most of the work on a custodial exchange: an authenticator app or passkey, a withdrawal whitelist, an anti-phishing code and a unique password. All six custodial exchanges below document an authenticator app and an address whitelist; anti-phishing codes and passkeys are documented on five of them. Hyperliquid and Aster are wallet-based, so security there means protecting the wallet itself. “Not documented” means we did not find it on the official pages checked — not that the feature is absent.

Feature matrix

ExchangeAuthenticator appPasskey / security keyWithdrawal whitelistAnti-phishing codeWithdrawal lock after changesOfficial source
BinanceYesPasskey; can be required for login and withdrawals. Security keys (e.g. YubiKey) supportedYes; optional 24/48/72-hour hold on new whitelist addressesYes24–48 hours after some security changes, such as a password changeWhitelist · Passkey · Lock · Code
BybitYes (Google 2FA)Passkey (FIDO)Yes; address-book-only mode and a 24-hour lock on new addressesYes24 hours on newly added addresses; optional withdrawal delaySecurity (updated 2026-05-23) · Withdrawals
OKXYesPasskey (Face ID / fingerprint)Allowlist; new addresses verified for 30 daysYesOptional 24-hour lock on new allowlist addressesSecurity · Allowlist (updated 2026-08-14)
GateYes (Google Authenticator)Passkey, including FIDO2 USB keysYes; saved and trusted addressesYes24 hours after setting, changing or resetting any security settingSecurity · Passkey · Whitelist · Lock
BingXYes (two of email, phone, Google Authenticator)Passkey; required for login since 2025-07-18Yes; address bookYesNot documentedSafety guide · Passkey 2025-07-18
MAXYes; 2FA mandatory for login and withdrawalsNot documentedYesNot documentedNot documentedSecurity measures · 2FA
HyperliquidNot applicable — your wallet signsHardware wallet suggested (Ledger, Trezor, Keystone)Not applicableNot applicableNot applicableDocs · API wallets
AsterNot applicable — wallet loginNot documentedNot documentedNot documentedNot documented; bind API keys to a fixed IPAPI key docs

Pages checked 2026-10-07. Step timings are estimates and exclude creating a wallet. Exchanges change settings and menu names; the in-app security centre is authoritative.

The 15-minute checklist

  1. Authenticator or passkey (3 min). Add an authenticator app or create a passkey, save its backup or recovery codes, sign out and back in to confirm it works, then remove SMS as a 2FA method where the exchange allows it.
  2. Anti-phishing code (1 min). Choose a code; the exchange then shows it in its emails to you. An email without it is fake — but a correct code does not make a link in that email safe.
  3. Withdrawal whitelist (4 min). Turn it on, add only addresses you control and enable the new-address lock if offered. No withdrawal address yet? Skip this and do it before your first withdrawal.
  4. Unique password (2 min). Generate one in a password manager. Expect a 24–48-hour withdrawal hold on Binance and 24 hours on Gate after the change.
  5. Devices, sessions and API keys (3 min). Remove unknown devices; delete unused API keys; never give an API key withdrawal permission; bind keys to an IP.
  6. Official channels (1 min). Bookmark the exchange’s site and its verification page (for example Binance Verify or Bybit’s authenticity check).
  7. Wallet-based exchanges (Hyperliquid, Aster). Keep the main wallet on a hardware device and revoke approvals you no longer use.

Why each step matters: six takeover patterns. If something already went wrong: first-hour response.

Common questions

Passkey or authenticator app?

A passkey is bound to the real site, so a phishing page cannot reuse it. An authenticator code can still be typed into a fake page. Use a passkey where offered and keep the authenticator as backup.

Why can’t I withdraw after changing my password?

Binance suspends withdrawals for 24–48 hours and Gate for 24 hours after security changes, so an attacker who changes your settings cannot withdraw at once.

Does a whitelist stop all theft?

It stops withdrawals to new addresses unless the attacker can also change the whitelist, which usually needs your 2FA and may trigger a lock. Protect the 2FA first.

What if my exchange is “not documented” for a feature?

Check the security centre in the app or ask official support. We list only what the official pages state.

Sources and editorial notes

Official help pages checked 2026-10-07; dates shown where the page states one. The checklist order and timings are CoinFeeHub editorial guidance.

Change note

2026-10-07 · Page created: 8 exchanges × 5 features from official help pages.