How to Complete Security Initialization on the OKX Android App After Registration

 / 
OKX
 / 
1

Within the first hour after registering your account on an Android phone, the core security setup consists of four steps: set a strong login password, bind a Google Authenticator (or similar), enable withdrawal address whitelist, and set up an anti-phishing code. Once all four are done, the difficulty of having your account compromised will increase significantly.

1. Set a Login Password

What to do: Create a unique, high-strength login password for your account that is different from your email password and any other platform passwords.

How to do it:

Path: OKX App → upper-left [User Center] → [Security Settings] → [Login Password].

The password should contain a mix of uppercase and lowercase letters, numbers, and special characters, and be at least 8 characters long. OKX officially recommends not using the same password as your email account.

What counts as done: The password has been changed successfully, and the system prompts "Login password updated".

Prerequisite: You have completed registration and can log in normally.

Common failure reason: Using a password that is too simple or identical to your email password.

Risk reminder: After changing the login password, withdrawals will be paused for 24 hours. If you need to withdraw urgently, plan your password change accordingly.

2. Bind an Authenticator App (2FA)

What to do: Bind an authenticator app such as Google Authenticator or Microsoft Authenticator to provide a second layer of verification during login and withdrawals.

How to do it:

  1. First, download an authenticator app on your phone. Android users can download it from Google Play, Huawei AppGallery, Xiaomi GetApps, etc.

  2. Open the OKX App, path: [User Center] → [Security Settings] → [Authenticator App].

  3. Follow the on-screen instructions: use the authenticator app to scan the QR code or manually enter the setup key, then complete the binding.

  4. Enter the 6-digit dynamic verification code generated by the authenticator to confirm the binding.

What counts as done: In [Security Settings], "Authenticator App" shows as "Bound", and the system asks for a dynamic code during login.

Prerequisite: The authenticator app has been downloaded, and the phone can access Google services or local app stores normally.

Common failure reason: Not backing up the setup key. It is strongly recommended to take a screenshot of the key during setup so you can restore the authenticator on a new device. If you lose your phone and do not have the backup key, recovering 2FA will be very difficult.

Risk reminder: After modifying or resetting the authenticator app, withdrawals are disabled for 24 hours. Avoid unbinding and rebinding frequently.

3. Enable Withdrawal Address Whitelist

What to do: Once whitelist mode is enabled, withdrawals can only be made to addresses already saved in your address book. Even if an attacker steals your login credentials, they cannot send funds to an unknown wallet.

How to do it:

Path: [Assets] → [Withdraw] → [Address Book] → top-right [Address Settings] → turn on the [Address Whitelist Mode] switch.

If you do not yet have any frequently used withdrawal addresses, you can enable whitelist mode first and add addresses manually later when needed. In whitelist mode, you cannot withdraw directly by entering a new address.

What counts as done: The [Address Whitelist Mode] switch appears green (enabled).

Prerequisite: None.

Common failure reason: Forgetting which addresses have been added to the whitelist, and then having a withdrawal rejected because the target address is not on the list. Save 1–2 commonly used wallet addresses in the address book in advance.

Risk reminder: Once the whitelist is enabled, attempting to withdraw to a new address on the spot will fail. This is by design – it blocks unfamiliar addresses. If you genuinely need to withdraw to a new address, add it to the address book first. Some newly added addresses may trigger a 24-hour withdrawal lock, so plan ahead.

4. Set an Anti-Phishing Code

What to do: Create a unique code that will appear in every genuine email from OKX. If you receive an "OKX email" without this code, treat it as a phishing attempt immediately.

How to do it:

Path: [User Center] → [Security Settings] → [Anti-Phishing Code]. Enter a string of characters you can remember (e.g., "R32ysTz"). Once set, all official email notifications will automatically include this code.

What counts as done: The system prompts "Anti-phishing code enabled", and the Security Center shows it has been set.

Prerequisite: None.

Common failure reason: Forgetting the code after setting it, and then mistaking a genuine email for a fake one because you expected to see the code. Store the code in your phone's memo app.

What to do next:

Spend 10 minutes today to check these four items in order: Did you change your password? Is the authenticator bound? Is the whitelist enabled? Is the anti-phishing code set? Confirm the status of each in the Security Center. Once all four steps are done, your account's security foundation is in place. If you leave these until after you've deposited substantial funds, the psychological pressure will be much greater.