Sign In — a reliable routine
Adopt a short, repeatable routine every time you log in. Consistency reduces mistakes and prevents shortcuts that attackers exploit.
Desktop (web) quick routine
- Open a fresh browser window. Type kucoin.com or use your trusted bookmark.
- Confirm the address bar shows HTTPS and the correct domain — do not proceed with certificate or domain warnings.
- Let your password manager fill credentials to avoid phishing forms.
- Complete the approved second factor (authenticator code or security key).
- Mark the device as trusted only on personal machines; do not on public/shared devices.
Mobile app sign-in
- Install KuCoin from official app stores only (App Store / Google Play).
- Use the app’s onboarding to enable app-level PIN and biometric unlock for convenience, but pair those with 2FA for sensitive operations.
- Regularly check app permissions and remove any suspicious connected apps or overlays on Android that might intercept input.
If you ever receive an unexpected "new device sign-in" email, do not click links. Open KuCoin manually and review active sessions.
Two-Factor Authentication (2FA) — choices & setup
2FA significantly raises the bar for attackers. Choose the strongest method you can realistically support.
Recommended methods
Authenticator appsGoogle Authenticator, Authy, etc. — good balance of security & practicality.
Hardware security keysFIDO2/U2F keys (YubiKey) — phishing-resistant. Best for high-value accounts.
SMS (fallback)Easy but vulnerable to SIM swap — use only as a fallback.
How to enable 2FA
- Sign in → Account → Security Settings.
- Select Enable 2FA, scan the QR with your authenticator app or register your security key.
- Store backup codes physically (safe, secure location) and consider registering a second device or key.
Do not store backup codes in cloud notes or email. If you lose your only 2FA device without backups you may face lengthy recovery steps.
Account recovery — practical steps
Prepare for recovery before you need it. Put a few simple items in place so that, if access is lost, you can get back in quickly.
Forgotten password
- Use the official password reset on KuCoin’s site and follow the email link.
- Secure your email account first if you suspect it’s been compromised.
Lost 2FA device
- Use printed backup codes that you stored during setup.
- If you registered an additional security key or device, use it to sign in and reset your 2FA configuration.
- If you have no backups, open an official support ticket; be prepared for identity verification and processing time.
Tip: when setting up 2FA, immediately make one secure, offline backup of the recovery codes — it prevents a lot of pain later.
API keys & programmatic access — keep bots safe
Programmatic trading requires extra discipline. Treat API keys like credentials and minimize their privileges.
API hygiene checklist
- Create a dedicated API key per bot/service and assign only the permissions it requires.
- Never grant withdrawal permissions to third-party bots you don't fully control.
- Use IP whitelisting (if offered) to restrict where keys can be used.
- Store keys in secret-management tools and rotate them regularly.
Monitoring
Alert on unusual trade volumes, unexpected withdrawal attempts, or API access from new IPs. Small, automated checks catch issues before they escalate.
Phishing & social engineering — avoid the traps
Most compromises begin with social engineering. Learn the signals and adopt protective habits.
Common phishing signs
- Urgent tone asking you to click a link immediately.
- Slightly misspelled domains or extra subdomains (e.g., kucoin-security.example.com).
- Requests for codes, passwords, or screenshots of your account page.
If you suspect phishing
- Do not click any links. Open KuCoin manually via your bookmark.
- Forward the suspicious message to KuCoin’s official security contact (check the official site for the address) and delete it.
- Change passwords and revoke active sessions if you entered credentials on a suspicious site.
Never provide full passwords or authentication codes to anyone — legitimate support never requests these details.
Daily checklist — quick security steps
- Verify the KuCoin URL and HTTPS before logging in.
- Use a password manager; avoid reusing passwords.
- Enable an authenticator app or hardware key for 2FA.
- Store backup codes offline and register a backup key/device.
- Regularly review and revoke unused API keys and connected apps.
- Use whitelists and limits for withdrawals when available.
Following these steps will mitigate most common threats and make your account far more resilient to real-world attacks.