KipInCrypto LogoKipInCryptoTR
Guide

What Is an Anti-Phishing Code? A Guide to Protecting Yourself Against Fake Emails, SMS Messages, and Support Scams on Crypto Exchanges

What Is an Anti-Phishing Code? A Guide to Protecting Yourself Against Fake Emails, SMS Messages, and Support Scams on Crypto Exchanges cover image

Featured short answer

Related Guides

An anti-phishing code is a personal security phrase you set on a crypto exchange. When enabled, this code appears in the exchange’s official emails, SMS messages, or notifications. If the message doesn’t include the code, if the code is incorrect, or if the message directs you to a suspicious link, the message may be a scam.

However, the anti-phishing code alone is not enough. Even if the code appears to be correct:

  • open the app yourself without clicking the link,
  • type the domain name manually,
  • do not share your 2FA code with anyone,
  • do not give in to pressure such as “your account has been locked—call immediately,”
  • do not send cryptocurrency to anyone claiming to be a support representative,
  • If in doubt, lock your account and contact the official support channel.

Who is this guide for?

This guide is for:

  • Users of Binance, OKX, Bybit, MEXC, KuCoin, or other exchanges,
  • those who have received an email or SMS message stating “your account is at risk,”
  • Those who say, “I received a withdrawal code but didn’t make a transaction,”
  • those who suspect a fake support call,
  • those who want to set up an anti-phishing code on their exchange account,
  • those who are unsure about a message even though the anti-phishing code appears correct,
  • those who clicked on a phishing link,
  • those setting up stock exchange security settings for new users,
  • those creating security procedures for corporate or family crypto accounts

.

Critical Risk Warning

An anti-phishing code never replaces a password, 2FA code, passkey, hardware security key, whitelisted withdrawal address, device security, or email account security.

The following requests are signs of fraud:

  • “Send your 2FA code to verify your anti-phishing code.”
  • “Your account has been locked; call this number.”
  • “You need to transfer your funds to a secure wallet.”
  • “As exchange support staff, we are providing you with a new address.”
  • “Make a small verification transfer to unlock your account.”
  • “Enable screen sharing so we can make the settings.”
  • “Enter your seed phrase or private key.”
  • “If you don’t share the withdrawal code, your account will be closed.”

A legitimate exchange support team should never ask you for your seed phrase, private key, password, or 2FA code.

What is an anti-phishing code?

An anti-phishing code is a special word, code, or security phrase that you set for your exchange account.

KIP2026 Blue_7 Trust8

The exchange includes this code in official emails, SMS messages, or certain notifications.

Is the code I set included in the message? Is the code correct? Does the message’s language, link, and purpose seem normal?

If the code is missing or incorrect, the message may be a scam.

What is the purpose of an anti-phishing code?

1. It helps you identify fake emails

Scammers may copy the exchange’s logo and email design, but they may not know the code you set.

2. It serves as a checkpoint against panic-inducing messages

Phishing messages often create a sense of urgency:

  • “Your account will be closed in 30 minutes.”
  • “An unauthorized withdrawal has been detected.”
  • “Click the link to cancel this transaction.”
  • “The support team will call you.”

3. Establish a procedure for family and team accounts

When a message arrives, you can perform a standard check: “Does the message contain our security code, and did it come from an official channel?”

4. Helps reduce fake support messages

It adds an extra layer of security, particularly for email and SMS redirects.

What doesn’t the anti-phishing code do?

It does not stop an attacker who has already logged into your account on its own

It does not provide sufficient protection if your password and 2FA have been compromised.

It does not automatically block fake websites

If the user enters their password and 2FA on the fake site, the attack can still occur.

If the code is compromised, its effectiveness is reduced

The code may be compromised due to screenshots, email forwarding, data leaks, or malware.

It does not verify phone calls

The fact that the caller knows the code does not prove that the call is genuine.

It does not work the same way on every exchange

On some exchanges, it is used only in emails; on others, it may also be used in SMS messages or withdrawal screens.

The difference between an anti-phishing code and 2FA

Anti-phishing code

Purpose: Helps determine whether an incoming message is official.

2FA

Purpose: Provides a second layer of verification when logging in, making a withdrawal, or changing security settings.

The difference between an anti-phishing code and a passkey

How should you choose an anti-phishing code?

A good code:

  • is easy to recognize,
  • is hard to guess,
  • is not the same as your exchange password,
  • is not your 2FA backup code,
  • does not include your name, birth year, or phone number,
  • it shouldn’t be a phrase you use on social media,
  • it shouldn’t be a very common word.

Bad examples:

123456 password binance ahmet crypto 2026

Better examples:

Kip_47A Mavi7K Tuna_8

The character length and types allowed by the exchange vary by platform.

Should the same anti-phishing code be used on every exchange?

If possible, no.

Binance: KIP_7A OKX: Mavi8 MEXC: Tuna4

A code leak on one platform makes it harder to use the same code on other platforms.

Where should the anti-phishing code be stored?

Secure storage:

  • a note section in a password manager,
  • an offline security note,
  • restricted access in a company procedures document.

Things to avoid:

  • social media posts,
  • screenshot,
  • publicly accessible document,
  • email signature,
  • support message,
  • note with the same password.

How do I set up the Binance anti-phishing code?

  1. Open the Binance app or official website.
  2. Go to the Profile or Account section.
  3. Open the Security menu.
  4. Find the Anti-Phishing Code section.
  5. Select the "Create" or "Enable" option.
  6. Create a personal code that meets the requirements.
  7. Complete 2FA or passkey verification.
  8. Check the code in official emails and supported messages.

Finding the code does not mean you need to click the link in the message.

How do I set up the OKX anti-phishing code?

  1. Log in to your OKX account via the official app or website.
  2. Open the User Center or Security Center section.
  3. Find the "Anti-phishing code" option.
  4. Create your personal code.
  5. Complete the security verification.
  6. Check the code in emails from OKX.

How do I set up the Bybit anti-phishing code?

  1. Log in to your Bybit account.
  2. Go to the "Account" or "Account Info" section.
  3. Select the "Anti-phishing Code" option.
  4. Enter your personal code.
  5. Click "Confirm" to finish.
  6. Check the code in your inbox and supported messages.

How do I set up the MEXC anti-phishing code?

  1. Open the official MEXC app or website.
  2. Log in to your account.
  3. Tap the profile icon and go to the "Security" section.
  4. Select the Anti-Phishing Code option.
  5. Create a code that meets the platform’s character limit.
  6. Tap "Confirm" to finish.

KuCoin Safety Phrase and Anti-Phishing Mechanism

On KuCoin, you can use safety phrases for email, login, and withdrawals. Users should check not only their email safety phrase but also their login and withdrawal safety phrase options.

Does Coinbase have an anti-phishing code?

Coinbase’s security approach may vary by region and product. Basic security:

  • Open coinbase.com directly,
  • avoid clicking on fake links,
  • reporting suspicious emails to the security channel,
  • using the account lockout feature,
  • using strong 2FA or a security key,
  • and not sending crypto to anyone claiming to be a support representative.

Is the message real or fake? Step-by-step verification

1. Notice the panic in the message

  • “Your account will be suspended.”
  • “An unauthorized withdrawal has begun.”
  • “Click here immediately to cancel this transaction.”
  • “The support team is calling you.”
  • “Transfer your funds to a secure address.”

2. Check the anti-phishing code

  • Is there a code?
  • Is the code correct?
  • Is the code outdated?
  • Is the code’s format normal?

3. Do not click on the link

Type the domain name into your browser yourself or open the mobile app directly.

4. Check for in-app notifications

Genuine security warnings often appear within your account as well.

5. Don’t rely solely on the sender’s address

Email addresses, SMS subject lines, and phone numbers can be spoofed.

6. Don’t enter a code unless you initiated the process

If you didn’t initiate a login, withdrawal, or security change, do not enter the 2FA code anywhere.

7. Lock your account if you’re suspicious

If the platform supports it, use the account lock or withdrawal suspension feature.

Could the message still be fake even if the anti-phishing code is correct?

Yes. The code could have been leaked in the following ways:

  • a screenshot,
  • compromised email account,
  • a support chat,
  • a data breach,
  • malware,
  • sharing the same code elsewhere,
  • message forwarding rules.

Even if the code looks correct, stop the process if the message prompts you to make a call, send cryptocurrency, share your 2FA code, or redirects you to a different domain.

What should you do if you receive a suspicious email?

If you haven’t clicked on anything

  1. Take a screenshot.
  2. Report it to the exchange’s official phishing reporting channel.
  3. Block the sender.
  4. Check your account security settings.

If you clicked the link but didn’t log in

  1. Close the tab.
  2. Run a malware scan on your device.
  3. Open the exchange using the official app.
  4. Check your session and device list.

You entered your password but did not enter your 2FA code

  1. Change your password immediately.
  2. Log out of all sessions.
  3. Check your 2FA and passkey settings.
  4. Enable the withdrawal address whitelist.
  5. Create a support ticket.

If you also entered a 2FA code

  1. Lock the account immediately.
  2. Log out of all sessions.
  3. Change your password.
  4. Reset or renew 2FA.
  5. Check your withdrawal history.
  6. Delete API keys.
  7. Open a support ticket.

If you sent crypto

  1. Record the TXID and recipient address.
  2. Notify the exchange immediately.
  3. Obtain the transaction history from the sending platform.
  4. Consider using official channels to file a report.
  5. Do not make payments to anyone who claims, “I’ll get your money back.”

Fake SMS and withdrawal code scams

Scammers may use messages such as:

  • “Your Coinbase/Binance withdrawal code: 123456”
  • “If this transaction isn’t yours, call us immediately.”
  • “Your account has been frozen.”
  • “Speak with a security representative.”
  • “Your funds are at risk.”

Correct action:

  • Do not call the number in the text message.
  • Do not click on the link in the message.
  • Open the stock exchange app yourself.
  • Check to see if there really is a withdrawal.
  • If you have any doubts, lock your account.
  • Proceed through the official support channel.

How can you spot a fake support call?

Red flags:

  • “Your account has been hacked; we’ll transfer your funds to a secure wallet.”
  • “Enter your 2FA code to cancel this transaction.”
  • “Enable screen sharing.”
  • “We’re the exchange’s security team.”
  • “Send your crypto to a temporary cold wallet.”
  • “Make a test transfer to this address.”
  • “If you end this call, your account will be closed.”

When should the anti-phishing code be changed?

  • If a screenshot was shared,
  • if your email account has been compromised,
  • if you entered the code during a support chat,
  • if you’ve used the same code on more than one exchange,
  • if the correct code appears in a suspicious message,
  • if a team member has left,
  • if your old security notes have fallen into the wrong hands,
  • if there has been a leak of identity or account information.

Anti-phishing procedure for corporate and personal accounts

  1. Incoming stock exchange messages are checked against the anti-phishing code.
  2. Do not click on the link.
  3. The stock exchange app is opened directly.
  4. Check to see if there are any in-app notifications.
  5. If there is a transaction request, a second-party approval is required.
  6. Withdrawals are made only to addresses on the whitelist.
  7. Suspicious messages are forwarded to the security officer.

Security measures that must be enabled along with the anti-phishing code

  1. Authenticator app or hardware security key
  2. Passkey
  3. Whitelist of withdrawal addresses
  4. Anti-phishing code
  5. API IP restriction
  6. Device and session control
  7. Email security

Practical Scenarios

Scenario 1: No anti-phishing code in the Binance email

  1. Do not click the link.
  2. Open the Binance app yourself.
  3. Check your withdrawal history.
  4. Report the email as phishing.
  5. Check your password and login activity.

Scenario 2: The code is correct, but the message asks you to make a phone call

The code may have been compromised. Do not call the number; open the app yourself and lock your account if you have any doubts.

Scenario 3: You received an SMS with a withdrawal code purporting to be from Coinbase

Do not share the code. Open the Coinbase app and check your sessions and security settings.

Scenario 4: The code in the OKX email is incorrect

Treat the email as a scam, do not click the link, and check the OKX app for any notifications.

Scenario 5: A team member shared the code in a screenshot

Change the code and update the team’s security procedures.

Troubleshooting table

Security Checklist

  • ☐ I used a different anti-phishing code on each exchange.
  • ☐ My code is not a password or a 2FA backup code.
  • ☐ I did not share the code on social media or in a screenshot.
  • ☐ I verify the code in the email I received.
  • ☐ I do not click on the link, even if the code is correct.
  • ☐ I open the exchange app myself.
  • ☐ I do not call the number in a suspicious text message.
  • ☐ I do not give my 2FA code to any support representative.
  • ☐ I do not make “secure transfers” to addresses outside the exchange.
  • ☐ I use an authenticator or security key.
  • ☐ I have enabled the withdrawal address whitelist.
  • ☐ I regularly check my API keys.
  • ☐ I delete unknown devices and sessions.
  • ☐ I have 2FA enabled on my email account.
  • ☐ If my code is compromised, I change it immediately.

Frequently Asked Questions

What is an anti-phishing code?

It’s a personal security phrase you set on a crypto exchange that appears in official emails, SMS messages, or notifications.

If there’s no anti-phishing code, is the email definitely a scam?

If the platform supports the code and it’s enabled, its absence is a strong red flag. Check by opening the app directly.

If the anti-phishing code is correct, is the message definitely genuine?

No. The code may have been compromised. The link, domain name, requested action, and in-app notifications should also be verified.

Does the anti-phishing code replace 2FA?

No. The anti-phishing code is for message verification; 2FA is for login and transaction security.

Can I use the same code on every exchange?

While technically possible, it’s safer to use a different code for each exchange.

My code is correct, but the message is asking me to send crypto. What should I do?

Do not send any crypto. Open the exchange app yourself and verify with official support.

I received a withdrawal code via SMS, but I didn’t initiate the transaction. What should I do?

Do not share the code. Open the app, check your sessions and withdrawal history, and lock your account if necessary.

When should the anti-phishing code be changed?

It should be changed if the code was shared, if your email account was compromised, if a legitimate code appears in a suspicious message, or if you’ve used the same code on different platforms.

Conclusion

The anti-phishing code is a simple yet effective security measure for crypto exchange accounts. It serves as a personal verification marker to help distinguish between genuine and fraudulent emails, SMS messages, and support communications.

The safest approach:

  1. Set a different anti-phishing code for each exchange,
  2. check the code in incoming messages,
  3. not clicking on links in the message,
  4. opening the exchange app directly,
  5. never share your 2FA code with anyone,
  6. enabling additional security features such as a whitelist for withdrawal addresses and a passkey,
  7. and changing the code immediately if it is compromised.

Related Safety Guides

Sources

What Is an Anti-Phishing Code? Stock Market Security Guide | KipInCrypto