Why advanced protection matters
Basic username/password authentication is no longer enough. Advanced features such as hardware security keys (FIDO2), passkeys, and strict withdrawal whitelists protect against phishing, remote compromise, and SIM swaps. This page guides you through enabling these protections after signing in.
Signing in: a stepwise checklist
- Open the official KuCoin site or app.
- Enter email/phone and password. Use a password manager to auto-fill safely.
- Complete 2FA. If configured for hardware key, touch the device when prompted.
- Verify anti-phishing code shows in any official KuCoin email before clicking links.
- After login, immediately review security settings if this is a new device.
Security hardening checklist (do these now)
- Enable Authenticator app 2FA: Google Authenticator, Authy, or similar.
- Register a hardware security key: YubiKey or similar for phishing-resistant logins.
- Set an anti-phishing code: Displayed in official emails.
- Enable withdrawal whitelist: Restrict withdrawals to pre-approved addresses.
- Keep backup codes offline: Store in paper or an encrypted drive.
Account recovery & lost 2FA
Lost 2FA requires a careful recovery flow. KuCoin typically asks for identity verification and ownership proofs — expect to provide transaction history or verification documents. If you have backup recovery codes, use them immediately to restore access.
FAQ — Advanced Login & Security
Can I use a hardware key and Google Authenticator together?
Yes. Combining hardware keys for sign-in and authenticator codes for withdrawals provides layered defense.
Are passkeys safer than passwords?
Passkeys use device-based cryptography and are phishing-resistant — a modern, secure alternative to text passwords.
What if my email is compromised?
Update email password immediately, enable 2FA on email, and contact KuCoin support. Email security is critical because password resets use email verification.
How can I spot a phishing page?
Check the URL, SSL certificate, anti-phishing code, and do not click links from unsolicited messages. Bookmark the official KuCoin site for direct access.