Do this in the first ten minutes
Order matters. Secure the mailbox before the exchange account, because the mailbox is the recovery route for everything else.
- Sign in to the email inbox and change its password
- Enable or re-enrol 2FA on the mailbox itself
- Change the exchange account password
- Remove the old authenticator and enrol a new 2FA seed
- Save every new credential to a password manager
Do this in the first hour
Once the core credentials are yours, close every remaining door the previous holder might still have open.
- Revoke all active sessions and trusted devices
- Delete every existing API key
- Regenerate backup and recovery codes and store them offline
- Enable a withdrawal address whitelist
- Turn on login and withdrawal notifications
- Review and remove any linked third-party applications
Mistakes that cost people accounts
Most losses are avoidable and come from the same handful of habits.
- Leaving credentials sitting in chat history
- Reusing a password from another service
- Accepting a one-time 2FA code instead of the seed
- Signing in from wildly different regions in the first days
- Skipping API key deletion because the account looks clean
Keeping the account healthy long term
After the initial lockdown, consistency does most of the work. Use a stable connection, keep activity proportionate rather than sudden, review sessions monthly, and store recovery material somewhere separate from the device you sign in on.
Frequently asked
What is the single most important step?
Re-enrolling two-factor authentication with a seed only you hold. Without that, a password change alone is not enough.
Why delete API keys on a clean account?
API keys are invisible on the main dashboard and can allow activity without a login. Deleting them takes seconds and removes the risk entirely.
Should I move funds in immediately?
Complete the full checklist first, then start with a small test amount before anything meaningful.
How often should I review security settings?
A monthly check of sessions, devices, API keys and whitelists is enough for most users.