How to Complete Security Initialization After Signing Up for OKX Web Platform
Don't rush to deposit funds immediately after finishing your OKX account registration. First, complete the core security configuration via the web platform to build a solid protection foundation. There are 4 key tasks to complete: set a high-strength login password, bind an authenticator app for 2-factor verification, set a unique anti-phishing code, and enable the withdrawal address whitelist. Completing these steps properly can significantly cut down the risk of your account being compromised.
Set a High-Strength Login Password
What you need to do: Set a unique, sufficiently strong login password for your OKX account that is not reused across any other online platforms.
How to set it up:
- After logging into the OKX official website, click [Profile] → [Security Center] at the top right corner of the page
- Find the [Login Password] section, and click the change button next to it
- Enter your new password and confirm the modification
It is recommended that your password be a combination of uppercase and lowercase letters, numbers and special symbols, with a minimum length of 8 characters. The most critical rule is: Never use the same password as your email account or passwords you use for other platforms.
How to confirm you have finished this step: The password is modified successfully, and the system shows the prompt "Login password updated".
Prerequisite: You can log into your OKX account normally.
Common setup mistakes: Setting a too simple password, or reusing the same password for your email, which leaves an easy access backdoor for attackers.
Risk reminder: After you modify your login password, the withdrawal function will be suspended for 24 hours. If you plan to withdraw funds soon, avoid changing your password right before that.
Bind Identity Verification App (2FA)
What you need to do: Bind Google Authenticator or Microsoft Authenticator as the second layer of verification for login and withdrawal operations. This is the most critical step to prevent account takeovers.
How to set it up:
- On the [Security Center] page, find [Identity Verification App] and click "Set Up"
- Download Google Authenticator or a compatible 2FA app on your mobile phone
- Scan the QR code displayed on the page, or manually enter the setup key to complete the binding
- Enter the 6-digit dynamic verification code generated by the authenticator to confirm the binding
A string of backup recovery keys will be displayed during the binding process. Make sure to write them down and store them offline securely. You will need these keys to restore access if you lose your phone or the authenticator app, otherwise you will have to go through a full identity verification process to regain access.
How to confirm you have finished this step: The "Identity Verification App" status in [Security Center] shows "Bound", and the system will require you to enter the dynamic 6-digit code when you log in.
Prerequisite: You have installed the Google Authenticator app on your mobile phone.
Common setup mistakes: Failing to back up the setup key, leading to permanent loss of access to the authenticator if your phone is lost, which makes account recovery extremely troublesome.
Risk reminder: After modifying or resetting your identity verification app, you will not be able to withdraw funds for 24 hours. Never use SMS verification to replace 2FA just for convenience — SMS messages are at risk of being intercepted, and have a far lower security level than dedicated authenticator apps.
Set Up Anti-Phishing Code
What you need to do: Set a unique custom string that will be included in every official email sent by OKX. Any "OKX" email that does not contain this code can be directly identified as a scam message.
How to set it up:
- On the [Security Center] page, find the [Anti-Phishing Code] section
- Set a memorable custom string, for example "R32ysTz"
- After confirmation, the system will prompt that the feature has been enabled
After setup, all official emails from OKX will automatically include this custom code.
How to confirm you have finished this step: The system shows the prompt "Anti-phishing code enabled", and the Security Center page displays that the feature is configured.
Prerequisite: No additional requirements.
Common setup mistakes: Forgetting your custom anti-phishing code after setting it up, leading you to mistake legitimate official emails for scam messages. Save the code in your phone memo for easy reference.
Enable Withdrawal Address Whitelist
What you need to do: After enabling the whitelist feature, you will only be able to withdraw crypto to addresses that have been pre-added to your address book. Even if hackers steal your account password, they will not be able to transfer your funds to unknown, unapproved wallets.
How to set it up: The setup path is: Log into the official website → [Assets] → [Withdraw] → [Address Book] → [Address Settings] → toggle on the [Address Whitelist Mode] switch.
Scenario A: You already have a frequently used withdrawal address. After enabling the whitelist, add the address to your address book first before submitting a withdrawal request.
Scenario B: You do not have a regular withdrawal address yet. You can enable the whitelist first, and manually add the target address to the address book when you need to make a withdrawal later. Under whitelist mode, you cannot make withdrawals by directly entering a new, unadded address.
How to confirm you have finished this step: The whitelist toggle shows as enabled, and there is at least one verified, pre-confirmed address in your address book.
Prerequisite: No additional requirements.
Risk reminder: After enabling the whitelist, any attempt to withdraw funds to a new unadded address will fail — this is exactly the security purpose of the feature. When you need to withdraw to a new address, add it to the address book first. Note that new addresses usually come with a 24-hour withdrawal lock on OKX, so plan your withdrawal operations in advance.
What to do next: Spend 10 minutes today checking the 4 security items in order: have you updated your login password? Is your authenticator app bound? Is your anti-phishing code set up? Is the withdrawal whitelist enabled? Confirm the status of each item in the [Security Center] page after completion. Once you finish all 4 steps, the core security protection of your OKX account is fully established. You will face much higher stress if you try to complete these security configurations after you have already deposited funds into the account.
