Account Security Best Practices

Account Security Best Practices

Protecting your ByteExchange account requires multiple layers of security. Follow these best practices to minimize your risk.

Essential Security Features

1. Two-Factor Authentication (2FA)

Enable 2FA using Google Authenticator or a compatible TOTP app. This is the single most important step.

2. Anti-Phishing Code

Set a unique code that appears in all legitimate ByteExchange emails to identify phishing attempts.

3. Withdrawal Address Whitelist

Only allow withdrawals to pre-approved addresses:

  1. Go to Settings > Security > Withdrawal Whitelist.
  2. Enable the feature and add your trusted addresses.
  3. New addresses require a 24-hour cooling period before becoming active.
4. IP Whitelist for Login

Restrict account access to specific IP addresses:

  1. Go to Settings > Security > IP Whitelist.
  2. Add the IP addresses you trust.
  3. When enabled, login attempts from non-whitelisted IPs are blocked.

Passkeys (WebAuthn)

ByteExchange supports passkeys as a modern, phishing-resistant authentication method:

  1. Go to Settings > Security > Passkeys.
  2. Click Add Passkey.
  3. Follow your browser or device prompt to register a passkey.
  4. Use your fingerprint, face ID, or hardware key for future logins.

Login Notifications

Enable notifications for every login to your account:

  • Email notification — Receive an email for each new login with IP and device details.
  • Suspicious login alert — Automatic alert for logins from new devices or locations.

Password Guidelines

  • Use at least 12 characters with mixed case, numbers, and symbols.
  • Never reuse passwords from other sites.
  • Change your password every 6 months.
  • Use a password manager like Bitwarden or 1Password.

Device Management

Review your authorized devices regularly:

  1. Go to Settings > Security > Device Management.
  2. Remove any devices you do not recognize.
  3. Click Log Out All Devices if you suspect unauthorized access.

Red Flags

  • Unexpected 2FA code requests
  • Emails without your anti-phishing code
  • Login notifications from unknown locations
  • Unexpected API keys in your account