How do I secure my account on a crypto trading platform (security keys, withdrawal allowlists, alerts)?
Company-reported Published 4 min read
Short answer
The US Federal Trade Commission (September 2022) ranks security keys as the strongest two-factor authentication method and says authenticator apps are safer than text-message codes, which are open to SIM card swap attacks. Coinbase says its staff will never ask for your password, 2-step codes or email access.
The full answer
XRP held on a trading platform has two layers of protection. The platform guards the coins, and you guard the account that can move them. Kraken puts the split this way on its own help page: “No amount of security on our end can make up for inadequate personal security.”[1] This page covers the part you control. It names two platforms only because their help pages document each feature; it does not recommend either one, and other platforms use other names for similar settings.
Which login check should protect the account?
Government security agencies rank the options the same way. CISA says “the only widely available phishing-resistant authentication is FIDO/WebAuthn authentication,” and rates text-message and voice codes as vulnerable to phishing, SS7 and SIM-swap attacks.[3] It also gives an example of an authenticator app’s six-digit code being phished: a fake login page collects “the 6-digit code from their mobile phone’s authenticator app” along with the password.[3] The FTC says an authenticator app is still safer than a texted code, and that “security keys are the strongest method of two-factor authentication.”[4] NIST’s identity guidelines say that “at the time of publication” codes sent over the phone network are the one “restricted” authenticator.[5]
The platforms say the same. Coinbase recommends “a security key or passkey” for two-step verification.[2] Kraken tells customers to replace text-message codes with passkeys, hardware keys or authenticator apps, and notes that “unlike authenticator apps, Passkeys are resistant to phishing.”[1] How criminals beat texted codes by taking a phone number is on SIM-swap theft.
A stronger key brings a new risk: losing it. Canada’s Cyber Centre tells organizations deploying MFA to give users “a backup MFA factor that is identical in strength as the primary one.”[9] Our reading: a backup weaker than the main key would become the easier way in.
What does a withdrawal allowlist stop?
An allowlist limits where your crypto can go. Coinbase describes it as “a security feature that limits sends to the addresses in your address book,” and says a newly added address “becomes available for sends after 48 hours.”[6] Switching the allowlist off also takes 48 hours, unless done within 8 hours of turning it on.[6] With the allowlist on, our reading of these rules is that someone who steals your login cannot send your XRP to a new address at once. They must add it and wait, and that wait gives you time to notice, if the alert reaches you.
Kraken’s Global Settings Lock works along similar lines. Kraken says it “acts as the last line of defense if your sign-in password and sign-in 2FA are compromised,” blocks new withdrawal addresses and other settings changes, and, depending on the account’s settings, takes “a minimum of 24 hours (or up to 30 days)” to unlock without a Master Key; Kraken says it emails the owner about any attempted unlock.[7] In Kraken’s example, an attacker who logs in “cannot add a withdrawal address because the GSL is on,” asks to unlock, and the owner has the waiting period to respond.[7] Kraken also states the cost: the waiting period is “the amount of time you’ll have to wait yourself if you lose your Master Key.”[8]
Why does the email account matter so much?
The platform trusts your email. Coinbase says it uses email “to confirm new devices, send important alerts, and communicate with you if you need support,” and advises checking that inbox for forwarding rules and recovery phone numbers you did not add.[2] Kraken says a compromised account email “can be used to request your username, reset your password and approve withdrawals,” and recommends an email address used only for Kraken.[1] On that basis, the email account needs as strong a login as the platform account. For people who create their own passwords, the FTC advises at least 15 characters.[10]
Coinbase lets users review active sessions and devices and remove any they do not recognize.[2]
How do criminals get in without breaking the login?
Often by asking. In May 2025 Coinbase said criminals bribed overseas support agents to copy customer data on less than 1% of its monthly transacting users, and that the aim was “to gather a customer list they could contact while pretending to be Coinbase—tricking people into handing over their crypto.”[11] Coinbase said no passwords, private keys or funds were exposed.[11] Coinbase says its staff will never ask for your password, two-step codes or email access, and will not “call you directly to handle account support or troubleshooting issues.”[2] Kraken tells customers never to install remote-access software, which it calls “a favorite technique of scammers.”[1] What leaked customer data can mean offline is covered on physical attacks on crypto holders.
What do these controls not protect against?
They protect the login and stop there. On September 24, 2026, Bitget detected unauthorized transfers from parts of its own hot and warm wallet infrastructure in a breach of about $351.6 million, according to CNBC.[13] Our analysis: no customer setting could have stopped transfers out of the platform’s own wallets. Bitget told CNBC that customer balances were accurate and that the loss was fully covered by its User Protection Fund.[13] In Canada, the OSC says the Canadian Investor Protection Fund “does not cover losses of crypto assets if a crypto asset trading platform goes insolvent.”[12] It also says that currently a platform may not hold all clients’ crypto in its own wallets and must have an acceptable third-party custodian hold at least 80% of it.[12] How platforms themselves are breached is on how exchanges get hacked.
This is the strongest argument against relying on account settings alone. Our analysis: a well-secured account does not protect coins held by a platform that becomes insolvent, and CIPF does not cover that loss.[12] Holding XRP yourself removes that platform risk and adds the risk of losing your own keys. That trade-off is weighed on exchange or own wallet.
What we know
- October 2022: CISA called FIDO/WebAuthn the only widely available phishing-resistant login method and rated SMS codes vulnerable to phishing, SS7 and SIM-swap attacks.
- The FTC says an authenticator app is safer than a texted code and a security key is the strongest two-factor method (page dated September 2022, checked September 29, 2026).
- Checked September 29, 2026: Coinbase’s help pages say its allowlist limits sends to saved addresses, with a 48-hour wait before a new address can be used and a 48-hour wait to switch the allowlist off.
- Kraken’s help pages, checked September 29, 2026, say its Global Settings Lock blocks new withdrawal addresses and settings changes, and that, depending on settings, unlocking without a Master Key takes at least 24 hours or up to 30 days.
- May 15, 2025: Coinbase said bribed overseas support agents copied data on less than 1% of its monthly transacting users so criminals could pose as Coinbase and trick customers into handing over crypto; it said no passwords, private keys or funds were exposed.
- September 24, 2026: Bitget detected unauthorized transfers from parts of its hot and warm wallet infrastructure in a breach of about $351.6 million; Bitget said customer balances were accurate and the loss was covered by its User Protection Fund (CNBC, September 25, 2026).
What we reason Analysis
- A waiting period on new withdrawal addresses turns a stolen login into a race the account owner can win, provided the owner sees the alert in time. This follows from Kraken’s own example of an attacker blocked by the lock and warned by email, and Coinbase’s 48-hour hold on new allowlist addresses.
- The email account is part of the platform account’s security, since platforms use it for resets, new-device checks and, at Kraken, withdrawal approval. It draws on the Coinbase and Kraken help pages.
- No customer login setting could have stopped the Bitget transfers, because they came from the platform’s own wallet infrastructure. It rests on CNBC’s report of Bitget’s statement on the September 24, 2026 breach.
- Every stronger control adds a way to lock yourself out: a lost security key, a lost Master Key, or a long unlock period. It draws on the Canadian Cyber Centre’s advice to organizations to give users a backup factor as strong as the main one, and on Kraken’s warning that its waiting period also applies to the owner.
What's still open
- Which Canadian and US platforms offer security keys, allowlists or withdrawal locks is not known; only two platforms’ help pages were checked as of September 29, 2026. Readers should check their own platform’s security settings page.
- Whether platforms that offer these controls have lower account-takeover losses is not reported by CISA, the FTC, NIST, the Canadian Cyber Centre, the OSC, Coinbase or Kraken as of September 29, 2026.
In plain English
When your XRP sits on a trading platform, the platform guards the coins and you guard the login. The strongest login check US government agencies name is a small physical security key. Codes sent by text message are the weakest, because a criminal can take over your phone number. Some platforms also let you lock your withdrawal addresses, so a thief who gets in has to wait before sending your coins somewhere new. None of this helps if the platform itself is hacked or fails.
Key terms
Sources
- Securing your Kraken account and digital life — Kraken (Payward), undated (checked September 29, 2026) Company-reported
- Make your account more secure — Coinbase, undated (checked September 29, 2026) Company-reported
- Implementing Phishing-Resistant MFA (fact sheet) — Cybersecurity and Infrastructure Security Agency (CISA), October 2022 Primary
- Use Two-Factor Authentication To Protect Your Accounts — Federal Trade Commission, September 2022 (checked September 29, 2026) Primary
- NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management — National Institute of Standards and Technology, undated (checked September 29, 2026) Primary
- Add an allowlist address — Coinbase, undated (checked September 29, 2026) Company-reported
- What is the Global Settings Lock (GSL)? — Kraken (Payward), undated (checked September 29, 2026) Company-reported
- How to prevent unwanted withdrawals — Kraken (Payward), undated (checked September 29, 2026) Company-reported
- Steps for effectively deploying multi-factor authentication (MFA) (ITSAP.00.105) — Canadian Centre for Cyber Security, May 2023 Primary
- Protect Your Personal Information From Hackers and Scammers — Federal Trade Commission, November 2024 (checked September 29, 2026) Primary
- Protecting Our Customers - Standing Up to Extortionists — Coinbase, May 15, 2025 Company-reported
- Understanding crypto asset trading platforms — Ontario Securities Commission (GetSmarterAboutMoney.ca), September 8, 2025 Primary
- Crypto platform Bitget suspects North Korea in $352 million hack — CNBC, September 25, 2026 Secondary
- How to Protect Your Crypto in 2026: Complete Safety Guide — Coin Bureau, August 7th, 2026 Secondary
- The Crypto Security Protocol — Crypto XLNC, Last updated June 12, 2026 Secondary
- Bitget Security Incident (Hack) — Official Progress Update — Bitget, 2026-09-30 Primary
- [SECURITY NOTICE] Bitget exchange hot wallets Incident — September 24, 2026 — Bitget Support Center, 2026-09-24 Primary
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
