Your account and the provider can fail in different ways

An account takeover happens when someone obtains access to your login or withdrawal workflow. A custody loss can arise even when your account settings are perfect, for example if the provider is hacked, misuses assets, or fails financially.

Use account controls to reduce takeover risk and provider due diligence to decide how much exposure you accept. Keep only the balance you have a clear reason to leave with the exchange. Self-custody trades provider risk for your own key-management responsibility.

Set these controls before the first deposit

Secure the email account used for password resets as carefully as the exchange. Generate a unique password and use a supported security key, passkey, or authenticator app. Make sure recovery methods do not quietly rely on an unprotected phone number.

  • Review active sessions and remove devices you no longer recognize or use.
  • Enable notifications for logins, password changes, withdrawals, and new withdrawal addresses where available.
  • Use a verified bookmark for account access and a separate route to contact support.
  • Review trusted devices and saved payment methods periodically.
  • If an anti-phishing email code is available, use it as an extra check. Its presence alone does not prove a message is legitimate.

A withdrawal allowlist adds friction for an attacker

Some exchanges let you limit withdrawals to saved addresses. Obtain the address from your wallet, verify it on the device where possible, and choose the correct network and tag or memo. Follow the exchange’s confirmation and waiting-period rules.

Keep change notifications enabled. An unexpected address addition is a reason to freeze or secure the account and contact support. Allowlist behavior varies by provider and may be changed through recovery or account settings; it is an additional control, not an absolute guarantee.

Give connected tools the smallest useful permission

A tax importer or portfolio tracker typically needs to read balances and history, not trade or withdraw. Issue a separate key for each service, inspect its permissions, and use an IP restriction if compatible with the service’s documented setup.

Label keys with their purpose and creation date. Delete unused integrations and rotate a key after suspected exposure. A read-only key can still reveal sensitive financial information, so treat it as a credential even when it cannot move funds.

Check the entity and the asset protections

Read the agreement for your state and account type. Check which legal entity holds your assets, withdrawal limits, custody terms, and whether assets can be lent or pledged. Separate statements about cash held at banks from statements about crypto balances.

Registration, an insurance policy, and a proof-of-reserves report describe different things. Ask what is covered, who benefits, and what is excluded. A reserves snapshot alone does not establish every liability or prove the provider’s solvency.

If you see an unfamiliar login or withdrawal

Use a clean device and the official website. Change the password, revoke sessions and API keys, review recovery methods, and contact the provider to restrict the account if needed. Secure the associated email account as part of the same response.

Keep a record of timestamps, transaction IDs, communications, and the steps you took. Be wary of unsolicited help that asks you to move funds to a supposedly safe wallet controlled by someone else.

Sources & limits

Source review: Oct 1, 2026. Availability and provider terms can change.

Keep exploring