If you notice a strange login record on your OKX account, the first thing you should do is contact official customer support immediately to freeze the account—not rush to change the password. Put the account into protection mode first to block any asset movement, then investigate and change the password. Doing it in the wrong order could give attackers time to act.
Step 1: Freeze Your Account Immediately, Block All Operations
After finding unusual activity, asset safety comes first. Put the account into a locked state that prevents any withdrawals or transfers.
What to do: Freeze the account through official channels or by yourself.
How to do it:
Self-freeze: In the OKX App, tap the grid icon in the top left → Account Settings → Security Settings → scroll to the very bottom → Account Management → Freeze Account, and follow the prompts. Verified users can use this feature. Once frozen, you cannot log in, and the linked email or phone number cannot be used to register again.
Contact support: Immediately reach out to online customer service through the OKX App or the official website and ask them to freeze your account to protect your assets.
Done when: The account is frozen or in protection mode, and no withdrawals or transfers can be made.
Step 2: Check Account Security Settings, Remove Unauthorized Access
After the account is frozen, in a safe environment, check and clean up any suspicious settings.
What to do: Do a full security check and remove all strange settings and device authorizations.
How to do it:
Check device management: Go to Security Center → Device Management, see if there are any devices you do not recognize, and remove them right away.
Check API keys: Find the API section in the app menu and delete any API keys that you did not create yourself.
Check third-party logins: Check linked accounts like Google, Apple ID, and Telegram, and remove any that are not yours.
Check address book: In the withdrawal address book, delete any addresses you did not add yourself.
Done when: All suspicious devices, API keys, third-party logins, and withdrawal addresses are cleaned out.
Step 3: Change Your Login Password and Reset 2FA
After the account environment is clean, update your core security credentials.
What to do: Change your login password and reset Google Authenticator (2FA).
How to do it:
Change password: In the app, go to Profile → Security Settings → Login Password, and follow the instructions. Use a strong password with upper and lower case letters, numbers, and special characters.
Reset 2FA: If Google Authenticator was bound by someone else, reset it immediately. Find Authenticator in Security Settings and follow the steps to rebind it. Note: Changing security settings will trigger a 24-hour withdrawal restriction.
Done when: Password is updated, authenticator is rebound, and all account security items are fully under your control.
Common Mistakes
When you see a strange login, the first instinct is often to change the password. If an attacker still has an active session, they might start withdrawing your funds while you are changing it. Always freeze the account first, then change the password.
After changing your password or resetting 2FA, a 24-hour withdrawal limit kicks in—this is the platform's risk control to protect fund security. Also, unverified accounts cannot self-freeze; you can only choose "Close Account." If you are concerned your device is compromised, use a clean, malware-free device to perform all security checks and updates. Avoid having a new password stolen right after you change it.
How to Verify Everything Is Safe
Log into your account, go to Security Settings and Device Management, and confirm that all security items are set by you and all logged-in devices are ones you normally use.
Next Steps
After unfreezing your account, enable "Withdrawal Address Whitelist" and "Fund Password" for an extra layer of protection. If strange device logins appear again later, repeat the steps above and consider switching your main device or checking whether your network is secure.


