SECURE YOUR MEXC ACCOUNT

Build multiple layers of protection around your exchange account.

MEXC provides several security controls, including Google Authenticator, passkeys, anti-phishing protection, withdrawal whitelisting and withdrawal protection. Work through the controls below and verify each one after setup.

MEXC exchange security is different from wallet security.

This guide covers your MEXC exchange account. A separate self-custody wallet has a different security model and may involve recovery phrases or private keys.

Never give anyone your password, verification code, authenticator code, recovery phrase or private key.

What should I never share?
Never share your MEXC password, Google Authenticator code, verification code, recovery phrase or private key. Legitimate support should not require these secrets.
What is an anti-phishing code?
MEXC's anti-phishing code is a personalized identifier that you create in your account. Official MEXC emails can display your code, helping you identify phishing messages that impersonate MEXC.
What is withdrawal whitelist protection?
When whitelist-only withdrawals are enabled, MEXC restricts withdrawals to addresses that you have added to your whitelist. MEXC also provides a whitelist security restriction that can impose a 24-hour waiting period for newly added addresses.
What is Withdrawal Protection?
MEXC's current Withdrawal Protection setting can automatically reject on-chain withdrawals during a configured lock period. It is an additional layer of protection around withdrawals.
What if I find an unfamiliar login or passkey?
Treat it as a possible compromise. Secure the account from a trusted device, change your password, remove unauthorized access and review your withdrawal and API settings.
MEXC EXCHANGE SECURITY

Secure the account before putting serious value into it.

Work through the controls one at a time. After changing a setting, confirm that the protection is actually active.

Use a strong, unique MEXC password

Your MEXC password protects access to an account that may control valuable assets. Never reuse it on another important service.

Click to see protection steps

Step-by-step

  1. Open MEXC through the official app or website.
  2. Open your Security settings.
  3. Find the option to manage your login password.
  4. Create a strong password using a combination of uppercase and lowercase letters, numbers and symbols.
  5. Make the password unique to MEXC.
  6. Store it in a trusted password manager.

VERIFY: Confirm that your MEXC password is unique and is not reused for your email, banking or other important accounts.

Enable Google Authenticator

MEXC supports Google Authenticator as an additional authentication factor for account and withdrawal security.

Click to see protection steps

Step-by-step

  1. Open your MEXC account and go to Security.
  2. Find Google Authenticator.
  3. Start the setup process.
  4. Open Google Authenticator on your phone.
  5. Scan the QR code displayed by MEXC or enter the setup key manually.
  6. Enter the current 6-digit authenticator code.
  7. Store the setup or recovery information securely in case you need to migrate the authenticator to another device.

VERIFY: Return to MEXC Security and confirm that Google Authenticator is shown as enabled.

Set up a passkey

MEXC currently supports passkeys for account login and withdrawals. Passkeys can use your device's biometrics, PIN or screen lock.

Click to see protection steps

Step-by-step

  1. Open the MEXC Security settings.
  2. Find Passkeys.
  3. Select the option to Create or Add a Passkey.
  4. Follow the security prompt on your device.
  5. Complete verification using your fingerprint, face recognition, device PIN or screen lock.
  6. Give the passkey a recognizable name if MEXC provides that option.

VERIFY: Confirm that the passkey listed in MEXC belongs to a device you personally control.

Review and remove unknown passkeys

A passkey is stored on a device. An unfamiliar passkey should therefore be treated as a potential unauthorized access path.

Click to see protection steps

Step-by-step

  1. Open Security → Passkeys.
  2. Review every passkey associated with your account.
  3. Identify the device associated with each passkey.
  4. Remove any passkey you do not recognize.
  5. If you find an unauthorized passkey, change your password and review your other security settings.

VERIFY: Every passkey listed should correspond to a device or security key that you intentionally control.

Set an anti-phishing code

MEXC's anti-phishing code helps you distinguish legitimate MEXC communications from phishing messages pretending to be from MEXC.

Click to see protection steps

Step-by-step

  1. Open the MEXC Security settings.
  2. Find Anti-Phishing Code.
  3. Create a unique code that is easy for you to recognize.
  4. Complete the requested security verification.
  5. Remember what your code looks like.
  6. Check the code in future MEXC emails that claim to be official.
  7. If the code is missing or does not match, do not click links or provide information.

VERIFY: Confirm that your anti-phishing code is enabled and that you know the correct code.

Enable withdrawal whitelist

MEXC's whitelist-only withdrawal setting restricts withdrawals to addresses that you have intentionally added to your whitelist.

Click to see protection steps

Step-by-step

  1. Open Asset Security Settings or the withdrawal security settings.
  2. Open the Withdrawal Whitelist settings.
  3. Review the addresses already saved.
  4. Remove addresses that you do not recognize or no longer need.
  5. Enable Whitelist-only withdrawals.
  6. Add only addresses that you have independently verified.
  7. Never add a withdrawal address simply because someone sent it to you in a message.

VERIFY: Confirm that withdrawals are restricted to addresses you intentionally added and verified.

Keep the whitelist security restriction enabled

MEXC provides a security restriction that can impose a waiting period before newly added withdrawal addresses can receive funds.

Click to see protection steps

Step-by-step

  1. Open your Withdrawal Whitelist settings.
  2. Locate the Whitelist Security Restriction option.
  3. Enable the restriction where available.
  4. Understand that newly added addresses may require a 24-hour waiting period before withdrawals can be made.
  5. Do not disable the restriction simply because it delays a withdrawal.

VERIFY: Confirm that the whitelist security restriction remains enabled after you finish configuring withdrawal protection.

Use withdrawal protection

MEXC's current withdrawal settings include Withdrawal Protection, which can automatically reject on-chain withdrawals during a configured lock period.

Click to see protection steps

Step-by-step

  1. Open Security → Asset Security Settings.
  2. Find Withdrawal Protection.
  3. Select an appropriate lock period.
  4. Review the effect of the setting before confirming it.
  5. Enable the protection and complete the required security verification.
  6. If MEXC provides an Unlock Early option, understand the implications before enabling it.

VERIFY: Confirm that Withdrawal Protection is enabled and that you understand when withdrawals will be permitted.

Verify every withdrawal

Crypto withdrawals can be irreversible. Always verify the recipient, asset, network, amount and any required memo or tag.

Click to see protection steps

Step-by-step

  1. Confirm the recipient address from a trusted source.
  2. Verify the asset.
  3. Verify the network selected on MEXC.
  4. Confirm that the receiving wallet or exchange supports that exact network.
  5. Check the amount.
  6. Check whether the destination requires a memo or tag.
  7. Review all security prompts before confirming the withdrawal.
  8. For a high-value transfer, consider a small test transaction first when practical.

VERIFY: Before confirming, independently verify the recipient, asset, network, amount and any required memo or tag.

Review recent login history

MEXC recommends checking recent login activity so unfamiliar devices, IP addresses or login times can be identified.

Click to see protection steps

Step-by-step

  1. Open your MEXC Security or account activity area.
  2. Find recent login history.
  3. Review the listed devices, IP addresses and login times.
  4. Look for activity you cannot explain.
  5. Remove or sign out unfamiliar devices where MEXC provides that option.
  6. If you see suspicious activity, change your password and review your authentication methods.

VERIFY: Every recent login should correspond to activity you recognize and a device you control.

Secure your email and phone

The email address and phone number connected to MEXC form part of your account-security chain and need their own protection.

Click to see protection steps

Step-by-step

  1. Confirm that the email address linked to MEXC is still yours.
  2. Protect the email account with a unique password and MFA.
  3. Confirm that your linked phone number is current.
  4. Review the email account's active sessions and recovery methods.
  5. Never give an MEXC verification code to another person.
  6. Treat unexpected password-reset or verification messages as possible warning signs.

VERIFY: Confirm that the email and phone channels connected to MEXC are secure and under your control.

Protect MEXC from phishing

Fake MEXC websites, messages and support agents can attempt to steal passwords, verification codes or other account information.

Click to see protection steps

Step-by-step

  1. Access MEXC through the official website or official app.
  2. Avoid entering credentials after clicking an unexpected email or social-media link.
  3. Be suspicious of messages received through Telegram, WhatsApp, Discord, X or email.
  4. Verify the domain carefully before logging in.
  5. Use MEXC's official verification resources if you are unsure whether a communication is genuine.
  6. Never give your password, 2FA code, verification code or private key to someone claiming to be MEXC Support.

VERIFY: Confirm that you reached MEXC independently through an official channel before entering credentials.

Secure MEXC API keys

API keys can create another access path into an exchange account. Only create them when necessary and restrict their permissions.

Click to see protection steps

Step-by-step

  1. Open your MEXC API management settings.
  2. Review all existing API keys.
  3. Delete unused or unfamiliar API keys.
  4. Give an API only the permissions it actually needs.
  5. Where supported, restrict API access using IP address whitelisting.
  6. Never share an API secret with an unknown person or application.
  7. Rotate or replace API credentials when they may have been exposed.

VERIFY: Confirm that every API key is intentional, necessary and restricted to the minimum permissions required.

Protect the device you use for MEXC

Exchange security settings cannot fully protect an account if the phone or computer used to access it is compromised.

Click to see protection steps

Step-by-step

  1. Keep your phone or computer's operating system updated.
  2. Install MEXC only from an official source.
  3. Use a strong screen lock.
  4. Remove suspicious applications and browser extensions.
  5. Be cautious with software requesting unnecessary accessibility or device-control permissions.
  6. Avoid sensitive account recovery actions on a device you suspect may be compromised.

VERIFY: Confirm that the device used for MEXC is updated, locked and free from suspicious software.

Secure the account after suspicious activity

An unfamiliar login, passkey, withdrawal address, API key or transaction should be treated as a potential account compromise.

Click to see protection steps

Step-by-step

  1. Stop unnecessary trading and withdrawals.
  2. Move to a trusted device if possible.
  3. Change your MEXC password.
  4. Review recent login history.
  5. Remove unfamiliar passkeys or devices.
  6. Review your withdrawal whitelist.
  7. Review and remove suspicious API keys.
  8. Review your email and phone security.
  9. Preserve suspicious transaction hashes, addresses and login details.
  10. Use only official MEXC support for assistance.

VERIFY: Do not resume normal activity until you have identified and addressed the source of the suspicious access.

Something does not look right?

If you find an unfamiliar login, changed recovery information, unexpected security alerts or another sign that someone may have accessed your account, stop the normal security check and move to the recovery process.

I think my account is compromised →
Still need help?

If you have worked through the relevant settings and something still looks wrong, do not give your security secrets to someone promising to fix the account. Use the service's official support and recovery resources for service-specific account problems.

For broader cybersecurity problems, you can also use the professional assistance pathway on this platform.

Need Professional Help? →
Mexc security is not a one-time task.

Review important account settings periodically, especially after a password change, device change, suspicious message or unexpected login alert.

VERIFY BEFORE YOU TRUST.

← Back to Secure Your Accounts