A Few Things We’d Like to Share About Account Security

Beginner
A Few Things We’d Like to Share About Account Security

As crypto trading becomes more widely adopted, phishing attacks and scams targeting users are also becoming increasingly sophisticated. As a platform you rely on over the long term, we want you not only to feel secure when using our services, but also to be better prepared to protect yourself from potential risks.

 

In this article, we’d like to cover a few important topics: how to identify phishing attempts, how to protect your information, and how to manage employee access securely. Spending just a few minutes on these basics can go a long way toward keeping your account safer.

 

Let’s start with one simple truth: phishing works by tricking you into voluntarily giving away sensitive information such as your account credentials, password, or verification codes.

 

We will continue strengthening security protections at the platform level, but keeping your account secure ultimately requires both sides to do their part. If you remember one rule — never give away sensitive account information lightly — most attacks can be stopped before they succeed.


Learn How to Spot Phishing

Scammers may use many different tactics, but most phishing attempts share a few common warning signs. Whenever you receive an email, SMS, or direct message, check the following before taking action.

1. Check the Sender’s Actual Address, Not Just the Display Name

Display names can easily be changed. What matters is the actual sender address and domain.

 

Official emails from KuCoin will only come from official domains. Even a small difference — such as changing .com to .co, adding an extra letter, or replacing the letter o with the number 0 — should be treated with caution.

2. Be Cautious of Messages That Pressure You to Act Immediately

“Your account is at risk. Verify within 24 hours or it will be frozen.”

“A withdrawal is awaiting confirmation. Click here immediately.”

Creating panic and urgency is one of the most common phishing tactics. The more urgent a message feels, the more important it is to stop and verify first.

3. Avoid Logging In Through Links in Emails or SMS Messages

If you need to log in or perform an account action, manually enter the official KuCoin website address, use a trusted bookmark, or open the official KuCoin app.

 

Whenever possible, avoid accessing a login page through a link sent by email or SMS.

4. Remember: No One From KuCoin Will Ask for Your Sensitive Credentials

KuCoin Support, operations staff, and other KuCoin employees will never ask you to provide your verification codes, password, private keys, or seed phrase.

 

If someone asks for this information, treat the request as suspicious — without exception.

5. There Is No Such Thing as a “Safe Account”

Scammers may claim that your account is at risk or about to be frozen and instruct you to transfer your assets to a so-called “safe account” designated by the platform.

 

Please remember: always keep control of your funds. KuCoin will never ask you to transfer your assets to a designated account in order to “protect” them.


Protect Your Information — Don’t Make Yourself an Easy Target

Once your information is exposed outside the platform, scammers can use it to create highly targeted attacks that appear much more convincing.

 

A few everyday security habits can significantly reduce that risk:

  • Use a unique password for your KuCoin account: Use a strong password that is not shared with any other website or service. If another service suffers a data breach, password reuse can put your KuCoin account at risk through credential stuffing attacks.

  • Enable Two-Factor Authentication (2FA): Whenever possible, use an authenticator app such as Google Authenticator rather than relying on SMS verification alone, which may be vulnerable to SIM swap attacks.

  • Limit the account and personal information you share publicly: Avoid posting your registered email address, phone number, UID, or trading screenshots in group chats or on social media. Scammers can use these details to make impersonation attempts more convincing.

  • Keep your devices and network secure: Avoid logging in from public computers or unsecured public Wi-Fi. Keep your operating system and security software up to date, and do not install unknown applications, suspicious browser extensions, or software from untrusted sources.

  • Protect the email account linked to your KuCoin account: Your email can serve as a key part of account recovery and security verification. Use a unique password for your email account and enable 2FA there as well.


Manage Employee Access Carefully

For merchants, account security risks do not always come from external attackers. Poor internal access management can also create serious vulnerabilities — for example, sharing a Master Account password with employees, allowing multiple people to use the same account, or failing to remove access after an employee leaves.

 

Setting clear access controls in advance can prevent many of these problems.

1. Use Sub-Accounts or Role-Based Permissions Instead of Sharing the Master Account

Give employees separate Sub-Accounts or individual access based on their responsibilities, while keeping control of the Master Account limited to authorized personnel.

 

This reduces unnecessary exposure of the Master Account and makes account activity easier to trace.

2. Follow the Principle of Least Privilege

Only give employees the permissions they actually need to perform their responsibilities.

 

For example, customer support staff may only require viewing permissions, while finance staff may need access to withdrawal-related functions.

 

High-risk permissions — such as withdrawals, changes to security settings, and managing the Address Book — should be restricted as much as possible.

3. Require Approval or Dual Authorization for Critical Actions

Large withdrawals, changes to withdrawal addresses, and changes to linked account information should require secondary approval or dual authorization whenever possible.

 

Avoid allowing a single person to complete high-risk actions without additional oversight.

4. Review and Revoke Permissions Regularly

When an employee changes roles or leaves the company, remove or disable their access immediately.

 

Periodically review your access permissions and remove anything that is no longer required.

5. Give Employees the Same Security Reminders

Account security can depend on the security awareness of everyone who has access.

 

Consider sharing this article with every team member who has permission to operate the account.


What to Do If You Suspect a Phishing Attack

If you think you may have encountered phishing, act quickly and follow these steps:

  1. Change your password immediately and reset your 2FA.

  2. Check your withdrawal addresses, linked email address and phone number, and API keys for any unauthorized changes. Remove or revoke anything you do not recognize.

  3. Contact KuCoin only through official channels. Open the official KuCoin app or manually enter the official website address to reach KuCoin Support. Do not use any contact information provided by the suspected scammer.

  4. If you have already clicked a suspicious link or entered sensitive information, complete all of the steps above as soon as possible.


Final Thoughts

Account security is not something either side can achieve alone.

 

We will continue investing in stronger platform-level protections, and we hope you will work with us to keep your account secure.

 

When both sides do their part, scammers have far fewer opportunities to succeed.

 

If you ever have questions about account security, please contact KuCoin through official channels.

 

We’re here to help keep you and your account secure.

Disclaimer: The information on this page may come from third parties and does not necessarily reflect KuCoin’s views. It is provided for general reference only and should not be interpreted as financial or investment advice.

Virtual asset investments may involve risk. Please carefully assess the product risks and your own risk tolerance. For more information, please refer to our Terms of Use and Risk Disclosure.