How to Complete Security Initialization After Signing Up on the OKX iPhone App
The first hour after opening an account is the best window to set up account security — while there are no funds and you are still relaxed. Focus on three core tasks: bind Google Authenticator, enable the withdrawal address whitelist, and set an anti-phishing code. Once these three are done, even if a hacker gets your password, they won't be able to withdraw your assets smoothly.
1. Set a Login Password and Two-Factor Authentication (2FA)
What to do: Create a strong, unique login password for your account and bind Google Authenticator as a second layer of protection.
How to do it:
Scenario A: You haven't set a login password yet. The system will ask you to set a password during registration. Use a combination of upper- and lowercase letters, numbers, and symbols, at least 8 characters long. The most important rule: do not reuse this password for your email or any other platform.
Scenario B: You have already registered and are now adding 2FA. Open the OKX App, tap the user center icon in the top-left corner, and go to [Security Center]. Find [Authenticator], and tap to enable it. The system will show a QR code; scan it with Google Authenticator or Microsoft Authenticator to bind.
During binding you will be asked to enter the 6-digit dynamic code just generated to confirm. Once verified, that dynamic code becomes your second lock.
When is it complete: When logging in, besides entering your password, the system will ask for the 6-digit code from Google Authenticator — seeing this screen means 2FA is active.
Prerequisites: An authenticator app like Google Authenticator or Microsoft Authenticator installed on your phone.
Common failure: Failing to back up the recovery key after binding 2FA. A string called the Recovery Key is shown in the app — be sure to write it down or save a screenshot. This key is needed to restore your authenticator when you switch phones. If you lose it, you will have to go through the identity verification process again, which is time-consuming and tedious.
Risk reminder: SMS verification codes may be convenient but carry the risk of SIM-swap attacks, making them less secure than an authenticator app. It is recommended to prioritize an authenticator app.
2. Set an Anti-Phishing Code to Avoid Fake Emails
What to do: Create a custom "anti-phishing code" that will appear in every genuine email from OKX. If you receive an "OKX email" without this code, treat it as a phishing attempt.
How to do it:
In [Security Center] find the [Anti-phishing Code] option. Enter a string you can remember (e.g., "R32ysTz"). After confirming, all official email notifications from OKX will automatically include this code.
When is it complete: You will see a system message "Anti-phishing code enabled".
Prerequisites: None.
Common failure: Forgetting the code you set, and then mistaking a genuine email without immediately spotting your code for a phishing email. Save the code in your phone's notes app.
3. Enable the Withdrawal Address Whitelist
What to do: With whitelist mode enabled, you can only withdraw funds to addresses already saved in your address book. Even if a hacker logs into your account, they cannot transfer assets to an unfamiliar wallet.
How to do it:
Path: Open the App, go to [Assets] — [Withdraw] — [Address Book], tap "Address Settings" in the top-right corner, and turn on the [Address Whitelist Mode] toggle.
Scenario A: You already have frequently used withdrawal addresses. After enabling whitelist mode, add these addresses to your address book so that you can continue withdrawing normally.
Scenario B: You do not have any frequently used addresses yet. You can still enable whitelist mode first. When you need to withdraw, manually add the destination address to the address book before initiating the withdrawal. In whitelist mode, entering a new address directly is not supported.
When is it complete: The [Address Whitelist Mode] toggle is green (on).
Prerequisites: None.
Risk reminder: Once whitelist mode is on, attempts to withdraw to a new address will fail. This is by design — it blocks unfamiliar addresses, increasing the security of the withdrawal process. When you need to use a new address, manually add it to the address book first, then withdraw. Some platforms lock withdrawals to new addresses for 24 hours, so be sure to plan ahead.
4. Manage Login Devices: Keep an Eye on Who Has Accessed Your Account
What to do: Regularly check the device management list to make sure only your own phone and computer can log in.
How to do it:
Path: Go to [Security Center], find [Device Management] or [Login Devices]. Check if there are any device models or login times you do not recognize. If so, remove them immediately and consider changing your password.
When is it complete: Only the phone and computer you are currently using appear in the device list.
Prerequisites: None.
Common failure: Forgetting to log out after accessing your account on a public computer or someone else's phone. Always manually clear the login session after using a public device.
What to do next:
Open the OKX App today and spend 10 minutes checking these three things in order:
Is the authenticator bound? Open the app and check if you are required to enter a 6-digit dynamic code at login.
Is the whitelist on? Go to the withdrawal page and see if the "Address Whitelist" toggle is green.
Is the device list clean? Check for any unfamiliar devices.
Once these three items are confirmed, the foundation of your account security is set — far stronger than a password alone. Completing them on the same day you open your account is the easiest route; trying to add them later when funds are already in the account will bring much more psychological pressure.
