SECURE YOUR BITGET ACCOUNT

Build multiple layers of protection around your exchange account.

Bitget provides several security controls that work together. Start with strong authentication, then add anti-phishing protection, withdrawal controls and device security.

Bitget exchange security is not the same as Bitget Wallet security.

This guide covers your Bitget exchange account. We will create a separate Bitget Wallet guide for self-custody assets and wallet credentials.

Never give anyone your password, verification code, Fund Code, authenticator code, private key or recovery phrase.

What should I never share?
Never share your Bitget password, Google Authenticator code, verification code, Fund Code, private key or recovery phrase. Someone claiming to be support does not need these secrets to legitimately help you.
What is the anti-phishing code?
Bitget's anti-phishing code is a unique identifier you configure in your security settings. Bitget says it can appear in official emails and SMS messages, helping you distinguish legitimate communications from phishing attempts.
Why did Bitget temporarily restrict my withdrawals?
Certain security changes can trigger a temporary security hold. For example, Bitget states that changing the login password, Fund Code or Google Authenticator can temporarily restrict financial functions. This is designed to protect the account after sensitive security changes.
What if someone contacts me claiming to be Bitget Support?
Do not give them your security secrets. Stop communicating through the unsolicited channel and independently open the official Bitget app or website to contact support.
BITGET EXCHANGE SECURITY

Secure the account before putting serious value into it.

Work through the controls below one at a time. After changing a setting, verify that the protection is actually active.

Use a strong, unique Bitget password

Your Bitget login password protects access to an account that may control valuable assets. Never reuse it on another important service.

Click to see protection steps

Step-by-step

  1. Open Bitget through the official app or website.
  2. Open your Security settings.
  3. Find the option for your login password.
  4. Create a strong password using a combination of uppercase and lowercase letters, numbers and symbols.
  5. Make the password unique to Bitget.
  6. Store it in a trusted password manager rather than reusing it elsewhere.

VERIFY: Confirm that your Bitget password is unique and is not reused for your email, banking or other important accounts.

Enable Google Authenticator

Bitget recommends Google Authenticator as a stronger authentication method than relying only on SMS verification.

Click to see protection steps

Step-by-step

  1. Open your Bitget account and enter Security.
  2. Find Google Authenticator and select Configure.
  3. Open the Google Authenticator app on your phone.
  4. Scan the QR code displayed by Bitget or manually enter the setup key.
  5. Enter the current 6-digit authenticator code.
  6. Complete any additional Bitget verification requested during setup.
  7. Store the authenticator backup key securely offline.

VERIFY: Return to Bitget Security and confirm that Google Authenticator is shown as enabled.

Protect your account with a passkey

Bitget supports passkeys as an additional authentication method and recommends them alongside Google Authenticator.

Click to see protection steps

Step-by-step

  1. First confirm that Google Authenticator is already configured.
  2. Open Security in Bitget.
  3. Find Passkey and select Configure.
  4. Follow the device prompts to create the passkey.
  5. Depending on your device, verify using your fingerprint, face recognition, device PIN or security key.
  6. Give the passkey a recognizable name if Bitget provides that option.

VERIFY: Confirm that the passkey shown in Bitget belongs to a device or security key that you personally control.

Set an anti-phishing code

Bitget's anti-phishing code helps you distinguish genuine Bitget emails and messages from phishing communications.

Click to see protection steps

Step-by-step

  1. Open Profile → Security.
  2. Find Anti-Phishing Code.
  3. Create a unique code that you can recognize.
  4. Complete the requested security verification.
  5. Remember what your code looks like.
  6. Check for the correct code when you receive Bitget communications.
  7. If an alleged Bitget message is missing your expected code or shows the wrong code, stop interacting with it.

VERIFY: Confirm that your anti-phishing code is enabled and that you know what the correct code should look like.

Set a Fund Code

The Fund Code provides an additional layer of protection for transactions and payments on Bitget.

Click to see protection steps

Step-by-step

  1. Open Security in your Bitget account.
  2. Find the Fund Code option.
  3. Create a code that is different from your login password.
  4. Avoid using your banking PIN, birthday or other easily guessed information.
  5. Complete Bitget's security verification.
  6. Store the code securely and never give it to another person.

VERIFY: Confirm that the Fund Code is enabled and that it is different from your Bitget login password.

Enable withdrawal whitelist protection

A withdrawal whitelist limits withdrawals to addresses that you have intentionally approved.

Click to see protection steps

Step-by-step

  1. Open the withdrawal address management area in Bitget.
  2. Review the addresses currently saved.
  3. Remove addresses you no longer recognize or need.
  4. Enable the Withdrawal Whitelist if available for your account.
  5. Add only addresses that you have independently verified.
  6. Never add a destination simply because someone sent it to you in a message.

VERIFY: Confirm that withdrawals are restricted to addresses you intentionally added and verified.

Enable cross-device withdrawal verification

Bitget can require withdrawal-address confirmation from your mobile device when you initiate a withdrawal on the website.

Click to see protection steps

Step-by-step

  1. Open your Bitget Security settings.
  2. Find Cross-Device Withdrawal Verification.
  3. Enable the feature if it is available for your account.
  4. When prompted during a website withdrawal, use the Bitget mobile app to verify the withdrawal address.
  5. Do not approve a withdrawal on your phone if you did not initiate it.

VERIFY: Confirm that a website withdrawal requires the additional device verification when the feature is enabled.

Keep withdrawal cancellation protection enabled

Bitget provides a withdrawal-cancellation feature that can allow you to cancel a withdrawal shortly after initiating it.

Click to see protection steps

Step-by-step

  1. Open your Bitget Security settings.
  2. Locate the withdrawal security controls.
  3. Confirm that the Cancel Withdrawals protection is enabled where available.
  4. Understand the cancellation window before relying on it as a safety measure.
  5. Remember that cancellation is an additional protection, not a reason to stop verifying withdrawals before confirming them.

VERIFY: Confirm that the withdrawal cancellation feature is enabled and understand the time available to cancel a withdrawal.

Verify every withdrawal

Crypto withdrawals can be irreversible. Always verify the destination, asset, network and amount before confirming.

Click to see protection steps

Step-by-step

  1. Confirm the recipient address from a trusted source.
  2. Verify the asset you are sending.
  3. Verify the network selected on Bitget.
  4. Confirm that the receiving wallet or exchange supports that exact network.
  5. Check the amount.
  6. Check whether the destination requires a memo or tag.
  7. Review all withdrawal-security prompts before confirming.
  8. For a high-value transfer, consider a small test transaction first when practical.

VERIFY: Before approving the withdrawal, independently verify the recipient, asset, network, amount and any required memo or tag.

Review your email and phone security

Your email address and phone number can form part of the authentication chain around your Bitget account.

Click to see protection steps

Step-by-step

  1. Confirm that the email address linked to Bitget is still yours.
  2. Protect that email account with a unique password and MFA.
  3. Confirm that your linked phone number is current.
  4. Review the email account's active sessions and recovery methods.
  5. Never give a Bitget verification code to another person.
  6. Treat unexpected password-reset or verification messages as potentially suspicious.

VERIFY: Confirm that the email and phone channels connected to Bitget are secure and under your control.

Protect your Bitget account from phishing

Fake Bitget websites, fake support agents, malicious QR codes and phishing links can steal credentials or verification information.

Click to see protection steps

Step-by-step

  1. Do not click Bitget links from unexpected messages.
  2. Do not scan QR codes received from unknown people or unofficial websites.
  3. Check the website domain carefully before entering credentials.
  4. Use Bitget's official verification channel when you are unsure whether a website or communication is genuine.
  5. Never give your password, 2FA code, Fund Code or private key to someone claiming to be Bitget Support.
  6. Remember that a message appearing to come from Bitget can still be fraudulent.

VERIFY: Before entering credentials or approving a transaction, independently verify that you are using an official Bitget channel.

Review connected devices and account activity

Regularly reviewing account activity can help you detect access you do not recognize.

Click to see protection steps

Step-by-step

  1. Open your Bitget Security settings.
  2. Review the available device, login and activity information.
  3. Look for devices or sessions that you do not recognize.
  4. Remove or sign out unfamiliar access where Bitget provides the option.
  5. If something looks suspicious, change your password and review your authentication methods.

VERIFY: Every device or login activity associated with your Bitget account should be explainable and under your control.

Protect your phone and computer

Strong Bitget settings cannot fully protect an account if the device used to access it is compromised.

Click to see protection steps

Step-by-step

  1. Keep your operating system updated.
  2. Install Bitget only from an official source.
  3. Use a strong screen lock on your phone or computer.
  4. Remove suspicious applications and browser extensions.
  5. Be cautious with applications requesting unnecessary accessibility or device-control permissions.
  6. Avoid sensitive account recovery actions on a device you suspect may be compromised.

VERIFY: Confirm that the device you use for Bitget is updated, locked and free from suspicious software.

Understand security holds after changing settings

Bitget may temporarily restrict payments, withdrawals or P2P activity after certain security changes. This is a security measure, not necessarily an account problem.

Click to see protection steps

Step-by-step

  1. Before changing a major security control, check whether Bitget warns about a temporary withdrawal or payment restriction.
  2. Changing the login password may trigger a 24-hour restriction.
  3. Changing or disabling the Fund Code may also trigger a 24-hour restriction.
  4. Changing Google Authenticator can temporarily disable withdrawals and P2P trading.
  5. Do not repeatedly change security settings because you think the temporary restriction means the setup failed.
  6. Wait for the stated security period to expire and then verify the account again.

VERIFY: After a security change, confirm the new setting is active and understand any temporary restrictions before attempting another change.

Secure the account after suspicious activity

An unfamiliar login, device, withdrawal address or security change should be treated as a possible compromise.

Click to see protection steps

Step-by-step

  1. Stop unnecessary trading and withdrawals.
  2. Move to a trusted device if possible.
  3. Change your Bitget password.
  4. Review and remove unfamiliar devices or sessions.
  5. Review your Google Authenticator and passkey settings.
  6. Review your withdrawal whitelist and saved addresses.
  7. Review your Fund Code and anti-phishing code.
  8. Preserve suspicious transaction information and other evidence.
  9. Use only Bitget's official support channel for help.

VERIFY: Do not return to normal activity until you have identified and addressed the source of the suspicious access.

Something does not look right?

If you find an unfamiliar login, changed recovery information, unexpected security alerts or another sign that someone may have accessed your account, stop the normal security check and move to the recovery process.

I think my account is compromised →
Still need help?

If you have worked through the relevant settings and something still looks wrong, do not give your security secrets to someone promising to fix the account. Use the service's official support and recovery resources for service-specific account problems.

For broader cybersecurity problems, you can also use the professional assistance pathway on this platform.

Need Professional Help? →
Bitget security is not a one-time task.

Review important account settings periodically, especially after a password change, device change, suspicious message or unexpected login alert.

VERIFY BEFORE YOU TRUST.

← Back to Secure Your Accounts