Differences Between OKX Whitelist and Address Book: A Security Comparison

 / 
OKX
 / 
1

The whitelist and address book are products at completely different functional levels. The address book is a tool for storing addresses, while the whitelist is a switch that restricts withdrawal operations. You only need to enable it when you decide to "only allow withdrawals to addresses from the address book." In other words, the address book is a list of frequently used addresses, while the whitelist is a feature that restricts operations. The two are independent and can be configured separately.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

What the Address Book Is: An Address Storage and Categorization Tool

The core function of the address book is to save frequently used addresses, allowing you to quickly select them for future withdrawals without re-entering or pasting them. The address book itself does not impose any restrictions on withdrawal operations. Basic usage: When adding an address, simply fill in the address and a note. After saving, it can be quickly selected on the withdrawal page. Upgraded feature: After the address book update in 2025, network scope and token scope settings have been added. You can configure whether an individual address applies to all EVM networks or a single network, and whether it supports all tokens or specific tokens. During withdrawals, the system will automatically filter matching addresses, reducing the risk of selecting the wrong network or token.

What the Whitelist Is: A Withdrawal Permission Restriction Switch

The whitelist mode is an independent permission switch. Once enabled, it directly restricts the available scope of all withdrawal operations. When whitelist mode is off (default), you can withdraw to any address—by manually entering an address or selecting one from the address book. The address book only serves as a quick-selection tool and imposes no restrictions. When whitelist mode is on, you can only withdraw to addresses already saved in the address book. Even if you know a complete address that is not in the address book, you cannot enter it to initiate a withdrawal. High-risk warning: After enabling whitelist mode, if all addresses in the address book are deleted, or if the address you need is not there, you will be temporarily unable to withdraw funds. Disabling the whitelist requires dual verification via email and mobile phone. If you lose access to both your phone and email, the withdrawal function will be completely halted.

Security Mechanism Comparison

Core security logic of the whitelist:

  • In whitelist mode, even if your account password and email are compromised, an attacker cannot withdraw to a new address that has not been added in advance.
  • Adding a new whitelist address requires 2FA verification, including multi-factor checks such as Google Authenticator, email, or mobile phone.
  • After the platform upgraded its security policy, withdrawals no longer use pure mobile verification codes; instead, email + authenticator dual verification is required. Withdrawals are disabled for 24 hours after resetting security items.

Core security logic of the address book:

  • Each address can be set to 30-day verification-free or permanent verification-free, streamlining frequent withdrawal processes.
  • In the 30-day verification-free state, if the address is not used for withdrawal within 30 days, the verification-free privilege automatically expires, and identity verification is required again for the next withdrawal.
  • Newly added whitelist addresses cannot be used for withdrawals within 24 hours, allowing sufficient time for risk review.

Common Misunderstandings

The most common pitfall is treating the address book's save function as the whitelist—thinking that saving an address in the address book means whitelist protection is active. In reality, the address book only stores addresses; the whitelist switch is the core restriction. Another common mistake is forgetting to turn off whitelist mode after enabling it. Later, when you need to withdraw to a new address, you realize you can't and must go through the whitelist deactivation verification process.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

How to Check and Recommended Practices

How to check whitelist status: Open the OKX withdrawal page and try entering a new address manually. If you see a prompt saying "Cannot enter a new address in whitelist mode," it means the whitelist is on. If you can enter an address normally, the whitelist is off or has been disabled. If your account holds significant assets, it is recommended to enable whitelist mode and add your frequently used addresses to the address book in advance. When adding addresses, it is advisable to set 30-day verification-free instead of permanent verification-free. If an address is saved by mistake, the verification-free permission will expire after 30 days, providing an extra layer of review. The configuration entry is in the OKX App: [Assets] > [Withdraw] > [Address Book], where you can directly view the status of the "Address Whitelist mode" toggle.