BingX Security Guide 2026: How to Protect Your Account

A practical BingX security guide for 2026: 2FA, withdrawal whitelist, anti-phishing code, spotting scams, and self-custody — how to lock down your account.

BingX account security guide

Securing a crypto account is not optional — it’s the difference between keeping your funds and losing them, and unlike a bank there’s usually no one to reverse a theft. The good news is that a handful of settings, most of which take minutes to enable, close off almost every common attack. This guide walks through the security features BingX offers, in the order you should set them up, plus how to recognise the scams that target crypto users. None of it is complicated; it just has to be done before you need it.

If you don’t have an account yet, our registration guide covers opening one, and you can register on BingX with the fee discount so trading is cheaper from the start — the referral reduction is permanent and has no volume requirement.

The security checklist, in order

Set these up in roughly this order. Each one blocks a different attack, and together they’re far stronger than any single measure.

LayerWhat it protects againstEffort
Strong, unique passwordCredential reuse and guessingLow
Two-factor authentication (2FA)Someone with your password aloneLow
Withdrawal whitelistFunds being sent to an attacker’s addressLow
Anti-phishing codeFake “BingX” emailsLow
Biometric / device controlsPhysical access to your phoneLow
Self-custody for long-term holdingsExchange counterparty riskMedium

1. A strong, unique password

Start with the basics done properly. Use a long password that you use nowhere else — reused passwords are the single most common way accounts fall, because a breach on some unrelated site hands attackers your login. A password manager makes this painless: it generates and stores a unique password so you never have to remember it. Never share it, and never type it into a page you reached through a link.

2. Two-factor authentication (2FA)

2FA means that even someone who has your password can’t log in without a second code. Prefer an authenticator app (such as Google Authenticator or Authy) over SMS where possible, because SMS can be intercepted through SIM-swap attacks. Enable it in your security settings and store the backup codes somewhere safe and offline. This one step defeats the large majority of account-takeover attempts.

3. The withdrawal whitelist

This is the protection people most often skip and most regret skipping. A withdrawal whitelist restricts withdrawals so funds can only be sent to addresses you have pre-approved. Even if an attacker somehow got into your account, they could not withdraw to their own wallet — the destination simply isn’t allowed. Add your own wallet addresses, turn the whitelist on, and you’ve removed the worst-case outcome of a compromise. It’s especially important before you hold a meaningful balance.

4. An anti-phishing code

Phishing emails imitating exchanges are relentless. An anti-phishing code is a phrase you set that BingX then includes in every genuine email it sends you. Real emails show your code; fakes don’t. Once it’s set, spotting a phishing attempt becomes trivial — no code, not real. Set it up in security settings; it takes a minute and pays for itself the first time a convincing fake lands in your inbox.

5. Biometric login and device controls

On mobile, enable biometric login (fingerprint or face) so someone with physical access to an unlocked phone still can’t get into the app easily. Review the list of devices and sessions authorised on your account periodically, and remove any you don’t recognise. Log out on shared or public devices, and keep your phone itself protected with a strong lock screen.

6. Self-custody for the long term

Every custodial exchange carries counterparty risk — you’re trusting the platform to safeguard your funds. The account-security steps above protect against your account being attacked, but the ultimate protection for long-term holdings is to take custody yourself. Withdraw coins you intend to hold for the long run to a wallet you control, ideally a hardware wallet, where you hold the keys and no exchange event can touch them. A sensible pattern is to keep a working balance on the exchange for trading and self-custody the rest. The trade-off is responsibility: with self-custody, your seed phrase is everything — lose it and no one can restore access, so back it up offline and never enter it online.

How to recognise the common scams

Most losses come from social engineering, not technical hacking. Watch for these:

  • Phishing links. Emails or messages with a link to “log in” or “verify.” Never use them — go to the official app or type the address yourself. Your anti-phishing code helps you spot fakes.
  • Fake support. Anyone contacting you claiming to be BingX support and asking for your password, 2FA code or seed phrase is a scammer. Real staff never ask for these.
  • Guaranteed-return schemes. Promises of doubling your crypto, “signal groups,” or investment managers who need your funds or keys. These are scams without exception.
  • Seed-phrase requests. No legitimate service ever needs your wallet seed phrase. Entering it anywhere online, or giving it to anyone, hands over your funds.
  • Fake apps and sites. Download the app only from official stores or the official site, and check the address bar carefully — scammers register lookalike domains.

The common thread: slow down, and never let urgency push you into clicking a link, sharing a code, or revealing a seed phrase.

A quick word on what security can’t do

Good account hygiene protects you from the attacks aimed at you. It doesn’t remove the general risks of crypto itself — prices are volatile, and only self-custody removes exchange counterparty risk. Security and investment risk are separate things: locking down your account is essential, but you should still only hold and trade what you can afford to lose. Our Risk Disclaimer covers the market side, and our is BingX safe article looks at the platform’s own safeguards.

The five-minute version

If you do nothing else today: set a unique password, turn on 2FA with an authenticator app, enable the withdrawal whitelist with your own addresses, and set an anti-phishing code. Those four take about five minutes together and stop the overwhelming majority of attacks. Then, as your holdings grow, move the long-term portion to self-custody. If you haven’t opened an account yet, you can register with the fee discount and set all of this up from day one. Note that BingX is not available in the USA, UK, Netherlands, Singapore, Canada, mainland China or Hong Kong, among others, though it serves users across many high-growth markets in Asia, Africa, Latin America and the Middle East.

Frequently asked questions

How do I make my BingX account secure?

The essentials are: a strong, unique password; two-factor authentication (2FA) via an authenticator app; the withdrawal whitelist so funds can only leave to your own saved addresses; and an anti-phishing code so genuine BingX emails are recognisable. Add biometric login on mobile, and move long-term holdings to self-custody. Together these close off the common ways accounts are compromised.

What is a withdrawal whitelist and should I use it?

A withdrawal whitelist (address whitelist) restricts withdrawals so they can only go to addresses you've pre-approved. If an attacker ever got into your account, they still couldn't send funds to their own address. It's one of the strongest protections available and well worth enabling, especially before you hold a larger balance.

What is an anti-phishing code on BingX?

An anti-phishing code is a unique phrase you set that BingX then includes in its genuine emails to you. If an email claims to be from BingX but doesn't contain your code, it's a phishing attempt. It's a simple, effective way to tell real messages from fakes, and takes a minute to set up in security settings.

Is 2FA enough to protect my crypto?

2FA is essential but not sufficient on its own. Pair it with the withdrawal whitelist, an anti-phishing code, a strong unique password and vigilance against phishing. And remember that for long-term holdings, self-custody in a hardware wallet removes exchange counterparty risk entirely — no account security can protect against every scenario an exchange itself might face.

How do I avoid crypto scams and phishing on BingX?

Only ever log in through the official app or by typing the address yourself — never through a link in an email or message. Set an anti-phishing code, ignore anyone promising guaranteed returns or asking for your password or 2FA codes, and never enter your seed phrase anywhere online. BingX staff will never ask for your password, codes or seed phrase.

Should I keep my crypto on BingX or withdraw it?

For active trading, keeping funds on the exchange is convenient, and the security features above reduce the risk. For long-term holdings, withdrawing to a wallet you control — ideally a hardware wallet — removes exchange counterparty risk. A common approach is to keep a working balance on the exchange and self-custody the rest.

Ready to start trading?

Register with our referral code and save up to 20% on every trade — forever.

Create BingX Account →