All
Filter by:
How do I deposit cash into my account?
I need help with account verification
Why can't I access my account?
Are there any crypto withdrawal fees?
I need help signing into my account
At Kraken, we prioritize and invest heavily in security. But no amount of security on our end can make up for weak personal security.
Use the account security tools and advice below, and never share access to your account with anyone.
Never allow anyone to create or manage an account on your behalf. Scammers offer to “set up” or “manage” an account for you so they can control it, and your funds.
Create a password that’s at least 15 characters long and not used on any other website. Our minimum is 12 characters, but longer is stronger. We recommend using a password manager such as KeePassXC to create and store it.
Turn on Sign-in 2FA using Passkeys. This is the most important security feature on your account. Set up more than one Passkey so you have a backup.
Set up a Master Key using a Passkey. It protects you against unwanted password resets and works as a backup for your Sign-in 2FA.
Turn on the Global Settings Lock (GSL) to block changes to your account settings and withdrawal addresses, even if someone gets into your account.
Turn on 2FA for withdrawals, trading and API keys.
Check your account activity regularly.
Only use Kraken’s official apps: the Kraken app, Kraken Pro app, Krak app and Kraken Wallet. Any other app that uses Kraken’s name or asks for your Kraken sign-in details is phishing.
If someone gets into the email address linked to your Kraken account, they can use it to request your username, reset your password and approve withdrawals.
We strongly recommend setting up a dedicated email address that you only use for Kraken.
Create a password using the same guidelines as for your Kraken password.
Turn on two-factor authentication (2FA) for your email account, using Passkeys if your email provider offers them. Don’t use text message (SMS) 2FA if you have another option.
Remove your phone number from your email account.
If you’re comfortable using encryption tools, set up PGP to receive signed and encrypted email from us, if your email provider supports it.
For more information, see Securing your email address.
A compromised device can record everything you type on it. Your phone is also the device most people use for two-factor authentication (2FA), so protect it carefully.
Lock your devices with a strong passcode.
Don’t share your devices.
Never install remote access software, such as AnyDesk, TeamViewer or Quick Assist, because someone contacted you and asked you to.
Only sign in from your own personal devices. Avoid public computers and shared devices.
Don’t use work devices for personal accounts. Your employer may be able to monitor and record your activity on them.
Phone numbers are widely used to sign in to and recover accounts, which makes them a target. Attackers can trick mobile carriers into moving your number to a SIM card they control. This is called a SIM swap. Once they control your number, they can receive your text message codes and take over your accounts.
Take these steps:
Avoid using your phone number to sign in or for two-factor authentication (2FA) wherever you can.
Set a strong PIN or passcode on your mobile carrier account so no one can make changes without it.
Ask your carrier for a port freeze (sometimes called a number lock or port-out protection), and set a SIM PIN, to block unauthorized transfers of your number.
Regularly check your online accounts and remove your phone number from any that don’t need it.
If you have a public profile or significant savings or crypto holdings, consider getting a separate phone number that you only use for account security.
A compromised internet connection can be used to steal your sign-in details or send you to phishing sites.
Change the default admin password on your home router.
Turn off remote management unless you need it.
Protect your Wi-Fi network with a password. This is separate from your router’s admin password. Use WPA3 or WPA2 encryption if your router offers it.
Set up a guest network if your router offers one, and keep your main network for your own devices.
Avoid public Wi-Fi and use your mobile data instead. If you have to use public Wi-Fi, use a reputable, paid VPN. Free VPNs may log or sell your data.
Malicious browser extensions and fake websites can steal your sign-in details and your crypto.
Only install the browser extensions you need, from your browser’s official store.
Watch out for wallet drainer sites.
Never copy and paste a command into your computer because a website tells you to, for example to “prove you’re human.” This is a common way to install malware. See Beware of computer malware and Risks of remote access software.
The more people know about your crypto, the more likely you are to be targeted by phishing, SIM swaps, extortion and, in rare cases, physical threats.
Don’t post about your crypto holdings, balances or trading profits on social media, including screenshots.
Don’t share wallet addresses in a way that links them to your name. Anyone can see a wallet’s balance and history on the blockchain.
Limit the personal details you share online, such as your home address, phone number, email address, employer and travel plans. Attackers use them to impersonate you to your mobile carrier or email provider, and to make phishing messages more convincing.
Be wary of anyone who contacts you about crypto out of the blue, including on social media, dating apps and messaging apps. See Protect yourself from scams.