Withdrawal Whitelist at the Crypto Exchange: How to Lock the Withdrawal Path Against Foreign Addresses

16 hours ago 2

Rommie Analytics

If someone has your password and your second factor, only one question still decides whether your balance leaves the exchange: is the attacker's destination address already in your account, or do they have to enter it first? This is exactly where the withdrawal whitelist comes in. It is a list of approved destination addresses, and while it is active, withdrawals go solely to addresses on that list. Everything else is refused, even with the correct password.

September 2026 has made this question very practical. On September 7, Bloomberg reported the outflow of around $320 million from a Liquid Network wallet, in which, according to the operator, roughly 4,000 of 4,200 bitcoin were moved. TRM Labs puts the damage from the wave of attacks on Coldcard devices at $116 million. Neither case was an account takeover at an exchange, but both have the same effect on reader behaviour: many are shifting balances between exchanges and their own wallets these days, and every one of those movements runs through precisely the withdrawal path at issue here.

Withdrawal whitelist: what the function blocks and what it leaves open

Definition in one sentence: a withdrawal whitelist is an address book in the exchange account that permits withdrawals only to recipient addresses approved beforehand.

The protection works against two very different attacks. The first is account takeover: anyone who can log in can, without a whitelist, immediately enter an address of their own and withdraw. The second is the swapped address, for instance through malware that replaces the contents of the clipboard, or through a prepared address taken from the transaction history. How this second trick works and how to spot a slipped-in address is set out at length in our article on checking recipient addresses.

The whitelist leaves open everything that happens within the approved addresses. Anyone who gets you to enter and approve their address yourself bypasses the protection entirely. That is the usual course of support fraud over the phone, and it is the reason a whitelist is a barrier against strangers and not against deception.

Why two-factor sign-in does not secure the withdrawal

Two-factor sign-in and a withdrawal whitelist solve different problems. The second factor decides who gets in. The whitelist decides where something goes out. If the second factor falls, for example because it runs by SMS and the phone number has been taken over, the withdrawal path is open immediately without a whitelist. Why SMS is the weakest variant here, we took apart in our overview of two-factor methods at crypto exchanges.

The German Federal Office for Information Security recommends two-factor authentication as basic protection for accounts involving money. That recommendation remains correct. But it describes only the front door. For an exchange account you additionally need a rule for the exit, and that is precisely what is missing from most default settings: among providers that offer a whitelist at all, it is in practice always voluntary and switched off by default.

A second point is often overlooked. The whitelist also protects you from yourself. An address checked and saved once does not have to be copied afresh out of an app for every withdrawal, which removes the occasion on which a wrong address gets into the form in the first place. Anyone withdrawing regularly to the same hardware wallet reduces the number of risky moments to a single one, namely the first. Which devices come into question and how they differ is set out in the hardware wallet comparison.

Exposed mechanical time-lock movement from a bank vault door with brass gearwheels and an empty dial plate, a coin with a Bitcoin stamp in front of itThe second part of the protection is not a list but a clock: security settings can only be changed again after a waiting period.

The time lock in the exchange account: why the waiting period is the real protection

A whitelist on its own has a weak spot every attacker knows: it can be changed. Whoever is sitting in the account enters a new address and waits for confirmation. That is why providers who are serious about it tie the address list to a delay. New or altered entries take effect only after a fixed period, and that period runs regardless of whether the attacker is still in the account.

The effect is simple to describe. An attacker who wants to withdraw at once fails against the clock. An attacker who waits risks the notification about the change reaching you before the period expires. That does presuppose, though, that you actually receive that notification, meaning that the address on file is current and the mail account itself is well protected.

Kraken's global settings lock: what the help page actually promises

The most thoroughly documented of the providers examined is Kraken. The function is called Global Settings Lock there, GSL for short. According to the description on the help page on preventing unwanted withdrawals, last updated on March 23, 2026, the lock prevents changes to the account and hides sensitive account information.

You set the waiting period yourself

When switching it on you determine how long unlocking takes without a master key. Kraken describes this waiting period in the instructions as a mandatory entry during setup. The decisive sentence in the documentation is that support cannot help remove the lock when the unlock period lies between one and thirty days. That is unusually plainly put and the actual core of the function: the lock works against the provider as well, and thus against the route attackers take in support fraud.

With the lock active, no new address can be entered

The instructions for adding a new withdrawal address carry the note that no withdrawal address can be added while the global settings lock is active. That closes the chain: withdrawals go to entered addresses, and nothing can be entered while the lock stands. Every newly added address has to be confirmed via a link in an email in any case.

Even without the lock, a short holding period applies

Independently of the global settings lock, Kraken describes a delay after a password change: for anyone who changes their password and has set up neither two-factor sign-in nor a master key, withdrawals to new addresses are held back for 24 hours. Addresses already entered are not affected. That is exactly the pattern that makes a whitelist so valuable: the trouble hits the new destinations, while the familiar route to your own wallet keeps working.

Master key: the spare key that lifts the waiting period again

The lock comes with a counterpart that the documentation names openly. The master key can switch off the global settings lock at any time. Kraken writes expressly that this convenient option comes with an increased security risk should the master key be compromised. And there is an order of operations you only get wrong once: once the lock is active, no master key can be created any more.

From this follows a decision nobody takes off your hands. With a master key you stay able to act if you change your mind, and your protection is only as good as the safekeeping of that key. Without one the lock is harder, and you have to sit out the period you set yourself if it comes to it, even as the rightful account holder. A long period is therefore no pure gain, it is a trade: more protection against strangers, less freedom of movement for you.

In practice this means: choose the period by the amount you leave on the exchange, and not by feel. Anyone who keeps only trading balance there and withdraws regularly to the same wallet gets by with a short period. Anyone leaving larger holdings on the account should first check whether those holdings need to be there at all.

Brass key board behind cracked glass with a single remaining spare key, a coin with a Bitcoin stamp beneath itThe master key lifts the waiting period at once and thereby becomes the most rewarding target in the account itself.

The survey: 13 providers, 23 pages, three explicit statements

This evaluation was carried out by cryptoticker.io itself on September 8, 2026. The method in one sentence: for thirteen providers with a German-language presence, the publicly reachable security and help pages were retrieved with an ordinary browser identifier, the HTTP status code was noted and the visible text without HTML scaffolding was searched for any mention of a whitelist, an allowlist or an address book for withdrawals.

Examined were 23 pages from 13 providers: Kraken, Binance, Coinbase, Bitpanda, Bitvavo, BISON, OKX, Bybit, Bitget, Crypto.com, KuCoin, Bitstamp and Nexo. Evaluable in terms of the method were four provider pages. Three of them name the function explicitly, one does not. Nine providers could not be examined by this procedure.

Crypto.com and Nexo: what the readable security pages say

The security page of Crypto.com carries the sentence that approving external addresses via an email confirmation is mandatory. It is the only finding in the survey that describes a whitelist not as an option but as a requirement. The same page also names passkeys, hardware security modules and FIDO2 as sign-in methods.

Nexo lists an address whitelist as a point of its own on its security page and describes it as managing your own crypto addresses for error-free transfers. The emphasis there is recognisably on the typo and not on the attacker. The page additionally names an anti-phishing code for the authenticity of messages and an automatic check of every withdrawal.

The security page of Bitpanda was likewise reachable, but its visible text contains no statement on a withdrawal whitelist. That is a finding about the page and not a statement about the function: from a missing sentence on a marketing page it does not follow that the setting is absent from the account.

For Binance, the relevant help page on the whitelist for withdrawal addresses is publicly available, but it could not be retrieved by machine in the test: the response came back without content. Via web search the content is confirmed, namely that with the function activated no withdrawals are possible to addresses that are not on the list. We therefore list this as a confirmed indication and not as a measurement of our own.

Nine provider pages could not be examined: what this evaluation does not show

Honesty about the gaps is part of the survey. At Coinbase and Bitvavo the help pages answered with a defence against automated retrieval, visible as status code 403. At OKX the addresses checked led nowhere. Bybit, KuCoin, Bitget and Bitstamp did return a successful status code, but their content is loaded only later in the browser, so the retrieved document holds no evaluable text. The security address checked at BISON did not exist.

From this follows a clear limit to the statement. What was measured is what a provider documents publicly and machine-readably, not which settings actually exist inside a logged-in account. Several of the providers that could not be examined very probably do offer address approval. Anyone wanting to know for certain finds the answer in one place no survey from outside can reach: in the security settings of their own account.

The distribution is striking all the same. Of thirteen large providers, at four it is possible to read up at all on how the withdrawal path is secured, and at only one is the lock described in enough detail that you know what you are letting yourself in for before switching it on. For a function that in an emergency decides over the entire account balance, that is thin.

Switching on the whitelist: the order that does not lock you out

Depending on the provider the settings are called address book, address whitelist, allowlist or withdrawal addresses, and they nearly always sit in the security area of the account, not in the withdrawal form. The order matters more than the label, because two of the steps are hard to make up later.

First enter the receiving address of your own wallet and test it with a minimal amount, while nothing is locked yet. Then check whether the provider offers a master key or a comparable emergency function, and set it up before the lock becomes active. Only after that arm the whitelist and, where available, set the waiting period for changes. Finally check the email address on file, because confirmation and warning both run through it. If your provider runs several networks for the same coin, enter and label each address separately.

What you see in the withdrawal form afterwards

After switching it on, the free input field for the address disappears at most providers and is replaced by a selection list. That visible difference is precisely your check: if you can still type in a foreign address and use it straight away, the whitelist is not active, whatever the settings say.

Withdrawing this week: the sequence from request to confirmation

September brings many readers a concrete occasion to move balances. When an exchange discontinues trading in a coin, a longer withdrawal window often remains, and experience from recent weeks shows that many holders react only shortly before it closes. Which deadlines are currently running we keep in our continuously checked deadline overview.

For the sequence this means: set up the whitelist before you are under time pressure. A newly entered address needs a confirmation by email, and where a waiting period applies, it comes on top. Anyone entering an address for the first time on the last day of a deadline is working against the very delay that is supposed to protect them.

And if something does flow out, speed counts. Lock the account, secure the records from the activity log and document the destination address before you change anything. How to proceed afterwards and what a police report achieves in practice, we described in a separate article on what to do after a crypto theft.

Setting up a withdrawal whitelist: what to take away

Open your account's security settings today and see whether address approval exists. It is publicly documented at only four of thirteen providers examined; in the account itself you see it in two minutes. If your provider offers none, that is an argument for your next switch, and the selection is in the crypto exchange comparison. Enter your own wallet address, test it and only then lock. A minimal amount up front costs fees in the cent range and rules out the most expensive mistake. Which device is suitable is set out in the hardware wallet comparison. Choose the waiting period deliberately and create the master key beforehand. Anyone holding larger balances on an exchange should additionally check whether the provider is supervised at all; the starting point for that is our list of regulated crypto exchanges.

A closing note, because it often gets lost in the discussion about security functions: every one of these locks works only on balances held at a provider. What sits in your own wallet is protected by no whitelist; different rules apply there. Protecting the withdrawal path is therefore no substitute for the decision about how much stays on an exchange at all.

(As of September 8, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Read Entire Article