Checklist before choosing an exchange
This first checklist focuses on the exchange itself—how it handles assets, communicates risk, and responds to incidents. You can use it alongside our reviews and regional guides when deciding where to open an account.
Platform-side checks
- Proof of Reserves or equivalent transparency reports, clearly explained and refreshed regularly.
- Clear separation of customer assets from company operating funds and trading accounts.
- Documented incident history, with explanations of what happened and how affected users were treated.
- Public security documentation: 2FA support, passkeys or hardware key support, withdrawal controls, device management.
- Terms of use and risk disclosures that are actually readable—not hidden or overly vague.
- Regional access and compliance that match your country, so you are not forced into gray-area usage.
Basic red flags to avoid
- No visible Proof of Reserves, or only vague marketing claims about “backed 1:1” without detail.
- Long unexplained outages, delayed withdrawals, or frequent “maintenance” around volatile market events.
- Aggressive return promises, guaranteed profits, or pressure to deposit quickly.
- No clear incident page, despite public reports of past hacks or losses.
- Support or staff pushing you to move conversations off official channels.
You can combine this checklist with our Best Crypto Exchanges 2026 guide and the Proof of Reserves explainer to get a fuller picture of how different platforms approach transparency.
Account-level security settings
Even on a well-run exchange, your account is only as safe as its weakest setting. Before you deposit meaningful funds, walk through these steps:
Essential protections
- Use a strong, unique password or passphrase—never reused from email, social media, or bank accounts.
- Turn on two-factor authentication (2FA), ideally via hardware security key or authenticator app rather than SMS.
- Enable withdrawal allowlists / address whitelists where possible, and lock changes behind 2FA and cooling-off periods.
- Review active devices and sessions, and revoke any that you do not recognize.
- Disable or tightly scope API keys if you use bots or third-party tools, and never give them withdrawal permission.
Extra protections (recommended)
- Use a separate email address for exchange accounts, with its own strong password and 2FA.
- Lock your SIM with a PIN and ensure mobile provider accounts use strong authentication to reduce SIM-swap risk.
- Configure login alerts and withdrawal alerts so you get notified of important activity.
- Consider passkeys or hardware keys where supported; they resist many phishing and credential-theft attempts.
Everyday habits that prevent mistakes
Most losses come from a mix of social engineering and hurried decisions. The following habits dramatically cut those risks:
- Always check the URL and certificate in your browser before logging in—avoid links in emails and DMs; type the domain manually or use a trusted bookmark.
- Never share screenshots of your security settings, recovery codes, or internal IDs on social media.
- Treat unsolicited support messages (email, chat, Telegram) as suspicious by default, especially if they ask you to “verify” codes or move funds.
- Keep your devices updated, with reputable antivirus or endpoint protection if possible.
- Regularly review your exchange balances and recent transactions so you notice unexpected changes early.
What not to do (common pitfalls)
Avoid the following behaviors. They show up again and again in real-world scam and compromise reports:
- Reusing passwords between exchanges, email, banks, and social media.
- Logging into your exchange on shared, public, or unknown devices.
- Disabling 2FA because it feels inconvenient.
- Storing seed phrases, backup codes, or security keys in cloud notes, screenshots, or unencrypted files.
- Keeping all long-term savings on exchanges instead of moving them to wallets you control.
Printable checklist
If you prefer a physical copy, you can print this section and tick items off before funding any new account:
- Platform has clear PoR / transparency and incident pages.
- Strong unique password/passphrase + 2FA/passkeys enabled.
- Withdrawal allowlist and alerts configured.
- API keys disabled or tightly scoped.
- Devices and sessions reviewed; login and withdrawal alerts enabled.
- Plan in place to move long-term savings into self-custody wallets.
For deeper self-custody practices, see our Seed Phrase Security guide, which focuses on protecting wallets you control.
FAQ: Crypto exchange security checklist
Should I keep all my crypto on exchanges?
No. Exchanges are useful for buying, selling, and short-term trading, but long-term holdings are generally safer in wallets you control, especially hardware wallets with good seed-phrase protection.
Is 2FA enough to protect my exchange account?
2FA is essential, but it is only one layer. You should also use strong unique passwords, passkeys or hardware 2FA when available, withdrawal allowlists, and careful phishing avoidance.
What is a withdrawal allowlist?
A withdrawal allowlist (or address whitelist) lets you lock withdrawals so funds can only be sent to a list of pre-approved wallet addresses, reducing the impact of account compromises.
How often should I review my exchange security settings?
At least every few months, and any time the exchange announces new security features, incident reports, or major changes to its policies or terms of use.
Do I need a hardware wallet if I use exchanges?
You don’t have to, but hardware wallets are strongly recommended for savings you plan to hold for longer periods. Exchanges are better treated as access ramps, not long-term vaults.
Ready to apply this checklist?
Compare exchanges, then combine this checklist with our Proof of Reserves guides before you decide where to keep your funds.