Security guide · 5 min read

Crypto Account Security Checklist for a New Verified Account

The first hour with a new account decides how safe it stays. This checklist covers exactly what to change, in what order, so the account ends up under your sole control with nothing left behind from the previous holder.

Do this in the first ten minutes

Order matters. Secure the mailbox before the exchange account, because the mailbox is the recovery route for everything else.

  • Sign in to the email inbox and change its password
  • Enable or re-enrol 2FA on the mailbox itself
  • Change the exchange account password
  • Remove the old authenticator and enrol a new 2FA seed
  • Save every new credential to a password manager

Do this in the first hour

Once the core credentials are yours, close every remaining door the previous holder might still have open.

  • Revoke all active sessions and trusted devices
  • Delete every existing API key
  • Regenerate backup and recovery codes and store them offline
  • Enable a withdrawal address whitelist
  • Turn on login and withdrawal notifications
  • Review and remove any linked third-party applications

Mistakes that cost people accounts

Most losses are avoidable and come from the same handful of habits.

  • Leaving credentials sitting in chat history
  • Reusing a password from another service
  • Accepting a one-time 2FA code instead of the seed
  • Signing in from wildly different regions in the first days
  • Skipping API key deletion because the account looks clean

Keeping the account healthy long term

After the initial lockdown, consistency does most of the work. Use a stable connection, keep activity proportionate rather than sudden, review sessions monthly, and store recovery material somewhere separate from the device you sign in on.

Frequently asked

What is the single most important step?

Re-enrolling two-factor authentication with a seed only you hold. Without that, a password change alone is not enough.

Why delete API keys on a clean account?

API keys are invisible on the main dashboard and can allow activity without a login. Deleting them takes seconds and removes the risk entirely.

Should I move funds in immediately?

Complete the full checklist first, then start with a small test amount before anything meaningful.

How often should I review security settings?

A monthly check of sessions, devices, API keys and whitelists is enough for most users.