๐ก๏ธ What Is an Anti-Phishing Code?
An anti-phishing code is a custom word, phrase, or combination of characters that you create and set in your exchange account's security settings. Once set, this code will appear in every legitimate email the exchange sends you. If you receive an email claiming to be from the exchange that does not contain your custom code, you know it is a phishing attempt and you should not click any links or provide any information.
Phishing is one of the most common ways hackers steal crypto exchange credentials. Attackers send emails that look identical to official communications, tricking users into entering their login details on fake websites. An anti-phishing code is a simple but highly effective defense against this type of attack.
Phishing emails are getting more sophisticated every day. Many are nearly indistinguishable from real emails. Your anti-phishing code is a reliable visual cue that instantly confirms whether an email is genuine โ no technical expertise required.
โ๏ธ How an Anti-Phishing Code Works
The mechanism is simple but powerful:
-
1
You Set a Custom Code
In your exchange's security settings, you create a unique word or phrase (e.g., "BlueMoon2024", "SafeTrading", "MyCryptoGuard").
-
2
Exchange Stores Your Code
The exchange saves your code and associates it with your account. It will be included in all future official emails.
-
3
You Receive an Email
When you receive an email from the exchange, look for your custom code. If it's there, the email is legitimate.
-
4
No Code = Phishing Attempt
If the email does not contain your code, it is a fake. Do not click any links, open attachments, or enter any information. Report it to the exchange's support team.
Make it a habit to always check for your anti-phishing code before taking any action on an email from your exchange. This simple habit can save you from losing your funds.
๐ Step-by-Step Guide to Set Up an Anti-Phishing Code
Step 1: Log In to Your Exchange Account
Log in to your exchange account using your email, password, and 2FA code.
Step 2: Navigate to Security Settings
Find the Security or Settings section of your account. Look for options like:
- "Security Settings"
- "Account Security"
- "Privacy & Security"
Step 3: Find the Anti-Phishing Code Section
Look for an option labeled "Anti-Phishing Code," "Phishing Protection," "Email Security," or "Security Phrase." It may be listed alongside other security features like 2FA and withdrawal whitelist.
Step 4: Create Your Custom Code
- Choose a unique word or phrase that is easy for you to remember but difficult for others to guess.
- Avoid common words, your name, or your birthdate.
- Use a combination of letters, numbers, and special characters if allowed.
- Examples: "BlueMoon2024", "SafeTrading", "CryptoGuardian", "SecureWallet7".
Choose a code that is meaningful to you but not obvious to others. For example, a combination of your favorite color, a number, and a word you associate with safety. Avoid using "password," "admin," or your exchange username.
Step 5: Enter and Confirm Your Code
Type your chosen code into the input field. Some exchanges require you to enter the code twice to confirm. Click "Save" or "Update" to apply the changes.
Step 6: Verify the Code Is Active
To confirm your code is working, you can request a test email from the exchange (if available) or wait for the next official email from them. Look for your custom code in the email body.
โ Anti-Phishing Code Best Practices
- Use a unique code โ Do not reuse this code on other platforms or services. It should be specific to your exchange account.
- Make it memorable โ Choose a code you can easily recall without writing it down. If you do write it down, store it securely.
- Check every email โ Make it a habit to check for your anti-phishing code every time you receive an email from your exchange. Do not skip this step.
- Never share your code โ Your anti-phishing code is for your eyes only. Never share it with anyone, including people claiming to be from exchange support.
- Change it periodically โ Consider changing your code every few months or if you suspect it may have been compromised.
- Use with other security features โ An anti-phishing code works best as part of a comprehensive security setup that includes 2FA, strong passwords, and withdrawal whitelists.
If you receive an email that looks suspicious, even if it contains your anti-phishing code, verify independently. Open a new browser window, type the exchange URL directly (do not click the link in the email), and check your account dashboard for any messages or alerts.
๐จ What to Do If You Receive an Email Without Your Code
- Do not click any links โ Do not click on any links, buttons, or images in the email.
- Do not open attachments โ Attachments may contain malware or viruses.
- Do not reply โ Do not respond to the email or provide any information.
- Report the email โ Forward the suspicious email to the exchange's official support email address for phishing reports. Most exchanges have a dedicated email for this purpose (e.g., "phishing@exchange.com").
- Delete the email โ After reporting, delete the email from your inbox and trash folder.
- Stay vigilant โ If you've received one phishing attempt, you may receive more. Stay alert and continue to check for your anti-phishing code.
Phishing emails often create a sense of urgency โ "Your account will be locked," "Suspicious activity detected," "Withdrawal request pending." Don't fall for it. Take your time, check your anti-phishing code, and verify through official channels.