The site's referral record is not registered; the code, benefits and commercial arrangement in the account-opening guide remain unverified. This tool recommends no product, and nothing you tick is sent anywhere. Full disclosure.
Account security self-check
Security is not a number you can add up. What this tells you is which routes you have closed and which ones are still standing open.
Tick anything and the result appears here. Nothing you select is sent anywhere — this page has no analytics and no server side.
No score here. "Security 7/10" cannot be acted on. "You have not closed off SIM swap" can.
Why the output is not a score
Folding security settings into a single number creates two misreadings.
The first is that it makes the controls look interchangeable, as though having three on is half again as safe as having two. They are not. Each one answers a specific attack route, and the routes do not substitute for one another. An anti-phishing code does not make a SIM swap any harder.
The second is that it makes people stop at the number. "7/10" does not tell you which three points are missing. "You have not closed off withdrawals after a compromise" is something you can go and do in the next five minutes.
So what this returns is a coverage list: which categories you have closed, which are still open, and what each open one actually means.
One category that no setting closes
However many boxes you tick, one line stays in the result: a transfer you were talked into making yourself.
Every mechanism above is designed on the assumption that the person operating the account is not you. Once the person really is you and has merely been misled, they stand aside one at a time — you log in, you pass the check, you add the other party's address to the whitelist, you wait out the cooling-off period. At no point is any control defeated. All of them worked exactly as designed.
Only two habits reduce this category, and they are in the result for the same reason they are here: re-check anything that involves moving money from an entry point you saved yourself, and never transfer while being hurried.
If you only do one thing
If the result shows several gaps, this is the order worth closing them in:
- Withdrawal address whitelist. The only control on the list that still works after an intrusion has already happened.
- Move off SMS to an authenticator app or a passkey. This takes your mobile carrier out of the chain entirely.
- A unique password. Not shared with any other site.
- Anti-phishing code. The cheapest item here by effort.
- Store the backup codes. This one protects you from locking yourself out.
How each mechanism works, what it stops and what it structurally cannot stop is set out control by control in a three-column table.
Where these settings live
Menu locations and names differ between platforms, but all of these sit in account security, usually under a heading like "Security", "Account security" or "Security centre". The rough name mapping:
- Two-factor authentication may appear as 2FA, two-step verification, or authenticator.
- Withdrawal address whitelist may appear as address management, address book, trusted addresses or address whitelist.
- Anti-phishing code may appear as security phrase or anti-phishing verification.
If you cannot find one of them, first check whether the platform offers it at all. Not every platform provides all of these, and whether it does is itself a data point worth adding to your pre-funding checklist.