Learn

Enable 2FA & withdrawal allowlists

Harden a Tier-1 CEX account with authenticator 2FA, anti-phishing codes, withdrawal allowlists, and a first self-custody test withdrawal.

· 7 min read · 564 words

Baseline account hygiene

1. Open your exchange via bookmarked URL after How to Buy Crypto on a Centralized Exchange—never from email or Discord ads.

2. Use a unique strong password stored in a password manager. Complete KYC accurately; mismatched names delay fiat and crypto withdrawals later.

3. Enable email login alerts if offered. Review active sessions and revoke unknown devices.

Two-factor authentication

4. Prefer **authenticator app** (TOTP) over SMS—SIM-swap risk is real in crypto. Save backup codes offline on paper, not in cloud notes synced everywhere.

5. Add an **anti-phishing phrase** if the exchange supports it—helps spot fake login pages in emails.

6. Never give 2FA codes to “support” in chat. Real support does not ask for TOTP live codes or your seed phrase.

Withdrawal allowlists and address books

7. Enable withdrawal **allowlist / whitelist** mode if available—new addresses require a timelock or email confirmation. This slows attackers even if password leaks.

8. Pre-add your self-custody receive address after verifying it on a block explorer—Create Your First Self-Custody Wallet.

9. For first withdrawal, send a test amount, wait for confirmations, then send remainder—Send and Receive Without Losing Funds.

Ongoing operator habits

10. Separate exchange login browser profile from faucet or DeFi experimentation to reduce cookie-stealer blast radius.

11. Export trade history periodically for taxes—How to Calculate Capital Gains.

12. If you rotate phones, migrate authenticator seeds carefully before wiping old devices. Losing 2FA without backup codes locks you into painful recovery flows—prepare before upgrades.

Recovery drills and first withdrawal rehearsal

13. Before you fund size, rehearse recovery: confirm you can locate 2FA backup codes, that the anti-phishing phrase appears on official emails, and that allowlisted addresses match your self-custody receive address on a block explorer. A dry run costs nothing; discovering missing backup codes after a phone wipe costs weeks.

14. Perform a full small-withdrawal rehearsal on the allowlisted address: withdraw a test amount, wait for the required confirmations, verify receipt, then withdraw a second modest amount. Only after both succeed should you treat the exchange as an on-ramp you trust operationally. Wrong-network mistakes are common when users copy addresses from chat history—always copy from the wallet receive screen.

15. Harden the human layer. Support scammers will impersonate exchange staff in Telegram or email and ask for 2FA codes, remote desktop access, or your seed phrase (exchanges never need your self-custody seed). Hang up, navigate from bookmarks, and open tickets only inside the official account portal.

16. Ongoing: review allowlisted addresses quarterly, remove unused ones, and keep trade/export history for taxes. Separate the browser profile used for the CEX from faucet and DeFi profiles so a malicious extension has a smaller blast radius. Account security is boring checklist work—that is the point.

17. Treat allowlists as living policy: when you rotate a self-custody address, add the new one, confirm the timelock/email gate, test a tiny withdrawal, then remove the retired address so an attacker cannot reuse an old entry. Document which exchange account maps to which hardware or software wallet label—confusion here causes wrong-network sends more often than malware does. Pair exchange hardening with the broader onboarding guide How to Buy Crypto on a Centralized Exchange so fiat deposits never land in an account that still lacks 2FA and withdrawal controls.

All Learn how-tos · Home

GetFreeBit earns a referral commission when you register via our verified partner links at no additional cost to you.