> For the complete documentation index, see [llms.txt](https://docs.chainbitx.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.chainbitx.com/help-center/eng/readme/account-and-asset-management/account-settings/account-security-settings.md).

# Account Security Settings

In the world of digital assets, security is the starting point for all operations. Whether it's depositing, trading, or withdrawing, account security forms the foundation of trust and user experience. To help users effectively prevent asset risks, we provide a comprehensive set of multi-layered protection measures, including mobile phone and email binding, Google Authenticator, login and fund passwords, anti-phishing codes, and more. This document will systematically explain the significance and usage of each security setting, helping you build your own personalized account security system.

***

#### Mobile Phone and Email Binding: The First Step of Account Verification <a href="#h_01k2bs9ehq2283hcxyjszgxwyf" id="h_01k2bs9ehq2283hcxyjszgxwyf"></a>

**Mobile Binding**

* Your mobile number is the primary identifier of your account. Once bound, it can be used for verification codes, password recovery, risk notifications, and other key steps.
* The system automatically detects the country code based on your IP to reduce input errors.
* Format verification: only numbers are accepted; Chinese, English, or special characters are not allowed.
* After passing the graphical captcha (like slide puzzle), a verification code is sent via SMS.
* If the code expires, is incorrect, or validation fails, binding will fail.

**Email Binding**

* Email is an important two-factor authentication method, commonly used for receiving important notifications and security alerts.
* Format must include “@” and not contain irregular characters.
* The verification process is similar to mobile binding, including code sending, graphical captcha, and security checks.
* Verification codes cannot be requested repeatedly within their validity period to avoid abuse.

**Recommendation:** Bind both your mobile and email to ensure multiple ways to recover your account.

***

#### Changing Mobile Number or Email <a href="#h_01k2bs9ej16t9ebgxgwxyr8j2t" id="h_01k2bs9ej16t9ebgxgwxyr8j2t"></a>

* When you change your mobile number or email, the system strictly requires validation of the old information to prevent unauthorized account changes.
* The new contact information must meet format requirements and pass verification.
* Errors such as expired or incorrect verification codes will be blocked.

***

#### Google Authenticator: Your Account’s Second Key <a href="#h_01k2bs9ej4n22axvzndxqddncr" id="h_01k2bs9ej4n22axvzndxqddncr"></a>

* Google Authenticator is a time-based one-time password tool widely used to prevent unauthorized access.
* Initial binding process: Download the app → Scan QR code or enter key manually → Enter verification code sent to mobile/email to confirm identity.
* To change the authenticator device, you must verify the old device first, then bind the new one using the same initial process.
* **Important:** Securely back up your Google Authenticator key to avoid being locked out if your phone is lost.

***

#### Login Password Setup and Modification <a href="#h_01k2bs9ej8vdtvv1y0g4dzpww3" id="h_01k2bs9ej8vdtvv1y0g4dzpww3"></a>

* Users can change their login password anytime.
* Requires old password input, new password setting, and confirmation.
* The system checks password strength and consistency.
* After changing the password, withdrawal is restricted for 24 hours to prevent account theft.

***

#### Fund Password: The Last Line of Defense for Asset Operations <a href="#h_01k2bs9ejc8mtrwbbk5n24m5b0" id="h_01k2bs9ejc8mtrwbbk5n24m5b0"></a>

* Used for withdrawals, transfers, margin, and futures trading operations, protecting your funds.
* Must be set before performing related operations for the first time.
* Requires double input and verification code validation when setting or changing.
* Withdrawal is restricted for 24 hours after modification.
* Recommended that fund password and login password be different for added security.

***

#### Anti-Phishing Code: Identifying Official Emails <a href="#h_01k2bs9ejgh8r9hb839g7548yb" id="h_01k2bs9ejgh8r9hb839g7548yb"></a>

* Your anti-phishing code will be automatically embedded in all emails sent by the platform, helping you recognize genuine official messages and prevent phishing attacks.
* Length: 3 to 10 characters, allowing only letters and numbers, no special symbols.
* You can freely set or change it as you wish.

***

#### Login Management: Every Login is Traceable <a href="#h_01k2bs9ejk1j7fxnxx09heb01k" id="h_01k2bs9ejk1j7fxnxx09heb01k"></a>

* Users can view login history in their account dashboard, including login time, IP address, device, and status (success/failure).
* This helps detect abnormal logins from unfamiliar IPs or devices so you can proactively change your password or freeze your account.

***

#### Summary of Security Settings <a href="#h_01k2bs9ejnfqac52enkkf1dmc8" id="h_01k2bs9ejnfqac52enkkf1dmc8"></a>

Account security is not optional in digital asset trading, but a basic standard. We encourage users to:

* Bind both mobile and email
* Enable Google Authenticator for two-factor authentication
* Set strong login and fund passwords, keeping them different
* Configure anti-phishing code to identify official emails
* Regularly check login records and respond quickly to abnormalities

***

#### Friendly Reminder <a href="#h_01k2bs9ejq0a9q9tpjchqsdq74" id="h_01k2bs9ejq0a9q9tpjchqsdq74"></a>

Security is every user’s essential responsibility. Completing the above security settings will greatly reduce asset risks and ensure a smooth, secure trading experience. If you encounter any problems, please contact customer support anytime. We are dedicated to protecting your assets.
