Skip to content
BrokerSift

How to Keep Crypto Safe on an Exchange in 2026

7 min read
How to Keep Crypto Safe on an Exchange in 2026
On this page

Keeping crypto safe on an exchange comes down to three things: picking a platform that can be checked, locking your account down properly, and not leaving more on the exchange than you need for active trading. No exchange security measure protects you from a compromised email password or a fake support agent, so account hygiene matters as much as the platform's own track record.

Start with the exchange, not the settings menu

Before anything else, check which regulator actually oversees the exchange and what happened the last time it was attacked. This isn't paranoia — it's public record. Coinbase runs under US state money-transmitter licenses and FDIC pass-through insurance on cash balances, and reported no direct customer-fund theft even during its 2025 support-contractor data breach. Kraken has operated since 2011 with no reported customer-fund breach; a 2024 exploit hit its corporate treasury for about $3 million, not user accounts. Bybit, by contrast, lost roughly $1.5 billion in ETH from a cold wallet in February 2025 after attackers compromised a Safe{Wallet} multisig transaction — the largest exchange hack on record — though Bybit stayed solvent and reimbursed users in full within 72 hours.

  • Search "[exchange name] hack" and read what actually happened, not just the headline
  • Check whether the exchange publishes proof of reserves and how often
  • Confirm the entity you're signing up with is the regulated one, not an unregulated regional mirror

Use an authenticator app, not SMS

SIM-swap attacks — where a criminal ports your phone number to their own device — remain one of the most common ways crypto accounts get drained. An SMS code sent to a hijacked number does nothing to stop a thief. Every major exchange, including Binance, Coinbase, and Kraken, supports app-based two-factor authentication (Google Authenticator, Authy) or a hardware security key (YubiKey), and both are far harder to intercept than a text message. Set this up the day you open an account, and store the backup codes somewhere offline, not in a screenshot on your phone.

Withdraw whitelisting closes the biggest loophole

Most major exchanges let you lock withdrawals to a pre-approved list of addresses, with a mandatory delay (often 24-48 hours) before a new address becomes active. This single setting defeats a huge share of account-takeover attacks, because even if someone gets past your password and 2FA, they can't redirect funds to a new address without waiting out the delay — giving you a window to notice and freeze the account. Turn it on for any exchange holding more than pocket-change amounts.

Don't confuse 'proof of reserves' with a guarantee

Proof-of-reserves reports (covered in more depth in our companion piece on the topic) show that an exchange holds enough crypto to cover customer balances at a single point in time, using a Merkle-tree snapshot. Binance, Kraken, OKX, Bybit, KuCoin, Bitget, MEXC, Gate.io, Crypto.com, and Bitfinex all publish some form of this. It's a useful signal of solvency, but it says nothing about liabilities (what the exchange owes elsewhere), nothing about hot-wallet security, and nothing about whether the exchange will still exist next year. Coinbase and CoinEx do not currently publish a standard proof-of-reserves report, which isn't automatically disqualifying — Coinbase is a listed public company with SEC-audited financials instead — but it does mean you're relying on a different kind of transparency.

Know what backstops you if something goes wrong

Ask what happens if the exchange itself is hacked, not just what happens if your account is compromised. Binance maintains SAFU, an insurance fund reported at over $1 billion; it fully reimbursed users after a 2019 hot-wallet breach. Bitget reports a protection fund of roughly 5,500 BTC, and MEXC states a $100 million Guardian Fund. Many exchanges without a dedicated public fund still have a history of reimbursing users out of company reserves — KuCoin covered the remainder of its 2020 breach after industry recovery efforts, and CoinEx reimbursed 100% of losses from its 2023 hack without diluting its token supply. A named insurance fund is reassuring, but a track record of paying out matters more than the marketing page.

  • Binance: SAFU fund, reported over $1 billion
  • Bitget: protection fund, reported ~5,500 BTC
  • MEXC: stated $100 million Guardian Fund
  • Kraken, KuCoin, Bybit, Gate.io, Crypto.com, Bitfinex: no named public fund, but each has a documented history of covering user losses after past incidents

KYC isn't just paperwork — it's part of your recovery path

Full identity verification feels like friction, but it's also what lets an exchange restore your access if your account is compromised or you lose your 2FA device. Exchanges that skip meaningful KYC tend to attract exactly the kind of account-takeover fraud that's hardest to reverse, because there's no verified identity behind the account to confirm ownership against. When comparing platforms, treat a thorough KYC process as a point in the exchange's favor, not an inconvenience to route around, and complete it fully rather than leaving your account in a lower, unverified tier with reduced support options.

This also affects withdrawal limits. Unverified or partially verified accounts on most exchanges are capped at low daily withdrawal amounts specifically to limit the damage from a compromised account — another reason to finish verification before you move meaningful sums onto the platform, rather than during an emergency.

Move long-term holdings off the exchange

The single biggest risk reduction available to any crypto holder is simple: don't leave coins you're not actively trading on an exchange. Exchange accounts are custodial — you don't hold the private keys, the exchange does — which is exactly why hot-wallet breaches (Binance 2019, KuCoin 2020, Crypto.com 2022, CoinEx 2023, Bybit 2025) keep happening across the industry regardless of how well-run the platform is. A hardware wallet (Ledger, Trezor) or even a well-secured software wallet removes your funds from that attack surface entirely. Treat the exchange balance as working capital for trades in progress, not a savings account.

Watch for the human-side attacks, not just the technical ones

Coinbase's 2025 incident is the clearest recent example of why this matters: attackers didn't breach any system, they bribed overseas support contractors to leak customer data, then used that data for targeted phishing and social-engineering calls impersonating Coinbase support. No legitimate exchange support agent will ever ask for your password, your 2FA code, or ask you to move funds to a "safe wallet" during a support call. Treat any unsolicited call, DM, or email claiming to be exchange support as hostile until proven otherwise, and verify through the exchange's official app or website, never through a link in the message itself.

A short pre-flight checklist

  • Regulated entity confirmed, and you know the jurisdiction it falls under
  • App-based 2FA or hardware key enabled, backup codes stored offline
  • Withdrawal address whitelisting turned on with a delay period
  • You've read (even briefly) the exchange's most recent security incident, if any
  • Long-term holdings moved to a wallet you control
  • You know how to reach official support directly, not through a search-engine ad or DM

Frequently asked questions

Is it safe to keep crypto on an exchange long-term?

It's riskier than self-custody because you don't control the private keys. Even well-run, regulated exchanges have suffered hot-wallet breaches. Keep only what you're actively trading on the exchange, and move larger, long-term holdings to a hardware or self-custody wallet.

Does proof of reserves mean my funds are 100% safe?

No. It shows the exchange held enough assets to cover balances at one snapshot in time, but says nothing about liabilities, ongoing solvency, or hot-wallet security. It's one useful signal among several, not a guarantee.

What's the single most effective security step I can take?

App-based two-factor authentication (not SMS) combined with withdrawal address whitelisting. Together they block the two most common attack paths: account takeover and fund redirection, even if your password is compromised.

Which exchanges have insurance funds?

Binance (SAFU, reported over $1 billion), Bitget (protection fund, roughly 5,500 BTC), and MEXC (stated $100 million Guardian Fund) all publish named funds. Others without a public fund, including Kraken and KuCoin, still have documented histories of reimbursing user losses after past incidents.

How do I know if an exchange has been hacked before?

Search the exchange's name alongside "hack" or "security incident" and read the outcome, not just the headline figure. Focus on whether customer funds were ultimately lost, how fast the exchange responded, and whether it changed its security practices afterward.

Should I avoid an exchange just because it was hacked once?

Not automatically. What matters more is how the exchange responded: whether customer funds were made whole, how fast it happened, and what changed afterward. Bitfinex, KuCoin, and CoinEx all fully reimbursed users after past breaches and remain widely used today.

All guides