Buying and withdrawing

Lock down the exchange account itself

Most people who lose bitcoin from a platform were not victims of an exchange hack. Their own account was opened by someone else — usually through email or a phone number.

Beginner About 20 minutes Updated Aug 17, 2026
2FAAccount securitySIM swap

When someone loses bitcoin from an exchange, the story is rarely that the exchange was breached. Far more often the account was simply opened by somebody else, using a password reset, a recycled password, or a phone number that stopped being theirs on a Tuesday afternoon.

That is good news, because it means the defences are things you control. It takes about twenty minutes to close the common routes, and none of it requires you to understand cryptography.

One thing to say plainly first: the strongest version of this advice is do not leave bitcoin on a platform you are not actively trading on. Everything below reduces risk. Withdrawing removes it. Treat this page as protection for the account and the balance that has to live there, not as an alternative to getting your bitcoin out.

A phone showing an authenticator app's rotating code beside a hardware security key on a desk, with an exchange login open on a laptop behind.

Image to come

The two upgrades that close most of the gap.

1Lock your email before you touch anything else

Your email account is the master key to every other account you own. It receives password resets, confirmation links, and withdrawal approvals. An attacker who controls it does not need your exchange password, because they can simply ask for a new one.

Securing the exchange while leaving the email weak is fitting a deadbolt to a door with an open window beside it.

  • Use a unique password on your email that appears nowhere else.
  • Turn on the strongest two-factor method your provider supports — a security key if available, an authenticator app otherwise.
  • Review the account's recovery options and remove anything stale: an old phone number, a defunct backup address, a recovery question with a publicly known answer.
  • Check for forwarding rules and connected apps you do not recognise. A quiet forwarding rule is a common way access is retained after a breach.
  • Consider an email address used only for financial accounts, never published, never used to sign up for anything else.

2Turn off SMS two-factor

Text-message codes feel like security and are the weakest common option, because your phone number is not really yours — it is a record at a carrier that a sufficiently persuasive person can have changed.

A SIM swap works by social engineering: someone contacts your carrier, poses as you with details gathered from data breaches and social media, and has your number moved to their SIM. Your phone quietly loses service, and every SMS code now arrives on their device. People have watched it happen while holding a phone that simply stopped working.

  • Remove SMS as a two-factor method wherever an alternative exists.
  • Remove your phone number as an account recovery option too — leaving it there keeps the back door open even after you switch methods.
  • Ask your mobile carrier to add port-out protection or an account PIN. Canadian carriers offer this, and it is usually a short call.
  • Do not publicise the number you use for financial accounts.

3Use the strongest method the platform offers

01
Weakest

SMS code

Defeated by

A SIM swap, which needs no technical skill.

Avoid where anything else exists
02
Good

Authenticator app

Defeated by

A convincing fake login page that relays your code in real time.

The sensible default
03
Strongest

Hardware security key

Defeated by

Very little—it verifies the real site, so a fake page gets nothing.

Best when supported

The distinction in that last row is the important one. An authenticator code can be phished: a fake site asks for it and forwards it to the real one within its short validity window. A security key cannot be tricked this way, because it verifies which website is actually asking before it responds. If a platform supports security keys, that is the single biggest upgrade available.

4Store your backup codes somewhere real

When you enable app-based two-factor, you are shown recovery codes. These exist so a lost phone does not lock you out permanently — and they bypass your two-factor entirely, so they are as sensitive as the password itself.

  • Write them down physically and store them somewhere secure. Losing them is a genuine and common way to lose account access.
  • Do not screenshot them into your photo library, where they will sync to the cloud.
  • Do not store them in the same place as the password for that account — one compromise should not yield both factors.
  • Set up your authenticator app on a second device if it supports it, so a dropped phone is an inconvenience rather than an incident.

5Whitelist withdrawal addresses

Many platforms let you pre-approve the addresses withdrawals can go to, usually with a delay before a newly added one becomes usable. Turn this on.

The delay is the feature. An attacker who gets into your account cannot immediately send funds to a fresh address of their own — they have to wait, and the platform emails you about the change in the meantime. That window is often the difference between an attempt and a loss.

  • Add only addresses from wallets you control, verified on your hardware device when you add them.
  • Enable any account-level setting that freezes changes for a cooling-off period.
  • Treat an unexpected email about a new whitelisted address as an emergency rather than a curiosity.

6Close the recovery back doors

Attackers rarely fight the front door. They use the paths built for people who have lost access, because those paths are designed to be forgiving.

  • Review every recovery method on the exchange account and remove what you do not need.
  • Remove old devices and active sessions you no longer recognise.
  • Revoke API keys you are not using. A forgotten key with withdrawal permission is a standing invitation.
  • Check whether the platform lets you require additional confirmation for withdrawals, and turn it on.

7Assume the login page is fake

Search adverts for exchange names routinely lead to convincing replicas that capture your password and your two-factor code and pass them straight through to the real site. The login appears to work. Nothing looks wrong until the balance moves.

  • Reach the exchange by a bookmark you created yourself, or by typing the address. Never from a search result, an email, or a message.
  • Use the platform's official app rather than a browser where practical.
  • Distrust urgency completely. Every message engineered to make you act quickly is engineered.
  • Nobody legitimate will ever contact you first and ask for a code, a password, or a recovery phrase.

If you think something is wrong

Speed matters more than certainty here. Acting on a false alarm costs you an afternoon; hesitating does not.

  • If your phone loses service unexpectedly, treat it as a SIM swap until proven otherwise and contact your carrier immediately from another line.
  • Withdraw to a wallet you control, if you still can.
  • Change the email password first, then the exchange password.
  • Revoke all active sessions and API keys.
  • Contact the platform through an address you typed yourself, never through a link in any message about the incident.

The version of this that actually works

Every measure on this page reduces the chance that someone else opens your account. None of them removes the underlying fact that a company holds your bitcoin and can freeze it, lose it, or fail while holding it.

Use the account for what it is good at — buying — and move the result somewhere only you control. A locked-down account holding nothing is a problem that has solved itself.

The next step

Withdrawing from a Canadian exchange covers the move itself: getting an address from your own wallet, verifying it properly, and starting with a test amount.

Do not guess

Stuck on a step?

If the screen in front of you does not match the guide, stop. Review the related walkthroughs or get a second set of eyes before exposing recovery words or approving a transaction.