We want our customers to have a trading experience that is safe and secure. Here are some helpful tips to keep yourself and your Bittrex account secure:
- Use strong passwords: do not reuse the same password for multiple accounts!
use unique and complex passwords for every type of account you create
use a password manager to store and generate secure passwords - Enable Two-Factor Authentication (2FA) whenever possible: it's a good idea to do this not just on your Bittrex account, but on any of your online accounts - especially email accounts.
use an authenticator app on your mobile device, like Google Authenticator or other
device-based one-time password (OTP) authentication
avoid SMS 2FA, as it is a less secure method - Avoid scams and phishing: we know, it sounds obvious, but sometimes all it takes is one click.
never use a search engine to locate Bittrex, and always type Bittrex.com into your web
browser
never click on links from unknown sources
never share your account information with anyone (username, password, 2FA codes)
never allow someone remote access to control your device
get familiar with common scams going around - Limit sharing your personal information online: scammers can use the data you share online to try to impersonate you and gain access to your accounts.
avoid sharing things like email addresses, trading platforms you use, birthdays, phone
numbers, etc. - Secure your mobile device: ask your mobile provider about their security options!
set a password/PIN on your account that must be provided before making changes
online, in person, or over the phone
don't lock your phone number to your SIM card
avoid installing unknown software on your device - Secure your email: use different email addresses when creating multiple online accounts. This limits the ability for hackers to use automated “Forgot password” links.
disable password recovery via SMS
keep one-time use recovery passwords stored offline
make sure your emails do not contain any sensitive or personal information
Now that you know how to protect yourself online, here are some tips to protect your Bittrex account:
- Enable Two-Factor Authentication (2FA) on your account: click here for instructions.
- Add IP and crypto wallet addresses to your Allowlists: see below section in this article for instructions.
- Limit sharing of your API key: some third-party apps or websites may request your API key in order to do trading for you.
Consider this before sharing:
check reviews to determine if the app or site should be trusted - zero reviews is a red
flag!
check how long the app or site has been active - don't use it if it just launched
understand that by sharing your API key with anyone, you are putting your account at
risk - Monitor activity on your account: see below section in this article for instructions.
Adding IP and crypto wallet addresses to your Allowlists is a great way to protect your account in the event that you lose your credentials or API keys.
Note:
You can only perform these actions from the web version of bittrex.com, but you will also need your mobile device on hand. It is also required to have 2FA enabled on your account before you can add an IP or crypto wallet address to your Allowlist.
Adding one or more IP addresses to your IP Address Allowlist tells Bittrex to only authorize trades or withdrawals from those IPs. This includes both the bittrex.com web interface and API based trades or withdrawals.
Note:
The Auto-Sell feature is not compatible with IP allowlisting.
-
- Log in to your Bittrex account.
- Go to My Account > IP Address Allowlist.
- Click Add New IP Address.
- Enter the IP address.
↪ What is my IP address? - Enter the authentication code from your mobile device and click Add IP Address.
- Log in to your Bittrex account.
If you are experiencing any issues adding an IP address to your Allowlist, please visit this article.
Adding a crypto wallet address to your Withdrawal Allowlist tells Bittrex to only authorize withdrawals to that address for that specific coin/token. This includes both the bittrex.com web interface and API based withdrawals.
Note:
When using this feature, you will need to add an address for each coin/token you would like to withdraw.
- Log in to your Bittrex account.
- Go to My Account > Withdrawal Allowlist.
- Click Add New Address.
- Select your Currency from the drop-down menu.
- Enter your wallet address and authentication code from your mobile device.
- Click Save.
If you are experiencing any issues adding a crypto wallet address to your Allowlist, please visit this article.
Note:
Currently, we only support allowlisting of crypto wallet addresses, not memos. Memos are expected to come at a later date.
check for suspicious log ins or changes made to your account
view your deposit and withdrawal history
view trading history to make sure no unauthorized trades have occurred
You can only view this from the Web version:
- Log in to your Bittrex account.
- Go to My Account > Account Activity. Here you can review all recent activity and the IP address it came from.
- You can also enable the Account login activity email notification.
↪ How do I enable/disable email notifications?
You can view this from Mobile or Web.
Mobile:
- Log in to your Bittrex account.
- Tap Holdings.
- In the top right corner, tap the History icon.
- You can tap either Deposits or Withdrawals. Deposits are shown by default.
Web:
- Log in to your Bittrex account.
- Go to Holdings > Deposits.
- Then click the Withdrawals tab.
You can view this from Mobile or Web.
Mobile:
- Log in to your Bittrex account.
- Tap Orders.
- You can tap either Open Orders or Closed Orders. Open Orders are shown by default.
Web:
- Log in to your Bittrex account.
- Go to Orders > Order History.
- Click Download History.
- Select a year and check the reCAPTCHA.
- Click Download*.
*option available on Web only
If you believe your Bittrex account has been compromised, please click here for guidance.
We hope this helps give you some peace of mind so you can enjoy using our platform. Stay safe out there!