2FA • Anti-phishing • Safer login habits

Bybit security: 2FA and anti-phishing setup checklist

This page helps you lock down your account before you fund or trade: 2FA, anti-phishing code, device hygiene, and a simple “do this first” checklist.

Educational guide only. Not investment advice. Trading involves risk.

1) Set up 2FA (recommended first step)

  • 2FA adds a second layer to your login, so a password alone is not enough.
  • Use an authenticator app where possible and keep your device time accurate.
  • Save backup codes or recovery methods safely (do not share them).

2) Turn on an anti-phishing code

  • An anti-phishing code helps you spot fake emails/messages pretending to be Bybit.
  • If a message claims to be “Bybit” but does not show your code, treat it as suspicious.
  • Never enter password/OTP from links in random messages—open the site manually instead.

3) Safer login habits that prevent most account issues

  • Always verify the domain before logging in. Avoid look-alike domains.
  • Do not reuse your email or social media password for your exchange account.
  • Use a device lock (PIN/biometric) and keep OS/browser updated.
  • Avoid public Wi-Fi for sign-in; if you must, use a trusted connection.

4) Before you fund: 5-minute checklist

  1. Confirm you are on the official domain (use the official-site page).
  2. 2FA enabled and working (test a login).
  3. Anti-phishing code set.
  4. Review restricted countries if you travel or use VPNs.
  5. Know where Support is (so you can react fast if something looks wrong).

5) If you suspect a risk (quick response)

  1. Stop and do not approve any unknown prompts or links.
  2. Change password and review security settings as soon as possible.
  3. Verify the official domain and check recent login/activity if available.
  4. Contact Support through the official help center if you suspect compromise.