Most crypto is lost not by breaking the blockchain but by breaking into an account. An exchange gives you a set of controls — layers of defense you can switch on — that decide how hard your account is to steal from. Here are the ones that matter most and why turning them on is the cheapest security you will ever buy.
What account risk controls are
Account risk controls are the settings an exchange offers to limit what an attacker can do even if they reach your login. They do not replace the exchange's own security; they add your personal layer on top. The logic is simple: assume a password can leak, and make sure a leaked password alone is not enough to move your funds. Every control below closes one door an attacker would otherwise walk through.
Two-factor authentication
Two-factor authentication (2FA) requires a second proof beyond your password — usually a rotating code from an authenticator app. It is the single most important control, because it defeats the most common attack: a stolen or reused password. Prefer an app-based authenticator or a hardware security key over SMS codes, since phone numbers can be hijacked through SIM-swap attacks. If you enable one thing, enable 2FA.
Withdrawal whitelists and the address book
A withdrawal whitelist, or address allowlist, restricts withdrawals to a short list of addresses you have pre-approved. Even if an attacker fully controls your account, they cannot send funds to their own address without first adding it — and good exchanges impose a waiting period before a new address becomes usable. Combined with an address book of your own trusted destinations, this turns account theft from a disaster into a delay.
Anti-phishing codes and login alerts
An anti-phishing code is a personal phrase you set that the exchange includes in every genuine email, so a fake email lacking it is exposed instantly. Login and withdrawal alerts notify you the moment a new device signs in or a withdrawal is requested, giving you a chance to react before damage is done. These controls do not block attackers directly, but they make an intrusion visible while there is still time to act.
API keys and device management
If you use trading bots or third-party tools, API keys are a hidden risk surface. Grant each key only the permissions it needs — read-only where possible — and never enable withdrawal permission unless you truly require it. Review your list of active devices and sessions periodically and revoke anything unfamiliar. The goal is least privilege: every connection to your account should have the minimum power required and nothing more.
The bottom line
Exchange account controls are free, fast to set up, and far cheaper than the loss they prevent. Enable strong app-based 2FA, turn on a withdrawal whitelist with a waiting period, set an anti-phishing code, and keep API keys and devices on a tight leash. No single setting is perfect, but layered together they mean a leaked password is an inconvenience rather than a catastrophe.
Disclaimer: This article is educational content from Bitbase Academy, provided for informational purposes only. It is not investment, trading, tax, or financial advice. Written as of July 2026; rely on the latest official information.
References
[1] Kraken, "Account security features" kraken.com
[2] Binance, "How to secure your account" binance.com






