Securing your Kraken account and digital life

Last updated: September 30, 2026

At Kraken, we prioritize and invest heavily in security. But no amount of security on our end can make up for weak personal security.

Use the account security tools and advice below, and never share access to your account with anyone.

  1. 1

    Never allow anyone to create or manage an account on your behalf. Scammers offer to “set up” or “manage” an account for you so they can control it, and your funds.

  2. 2

    Create a password that’s at least 15 characters long and not used on any other website. Our minimum is 12 characters, but longer is stronger. We recommend using a password manager such as KeePassXC to create and store it.

  3. 3

    Turn on Sign-in 2FA using Passkeys. This is the most important security feature on your account. Set up more than one Passkey so you have a backup.

    1. Select your profile icon and open your Security settings. Under Sign-in 2FA, select Add a Passkey.
    2. Once Sign-in 2FA is on, you’ll also use it, or your Master Key if you have one, to confirm sensitive changes like adding, editing or removing 2FA methods. This is called Step-up 2FA.
    3. Choose Passkeys over an authenticator app wherever you can. Passkeys resist phishing; authenticator app codes can be stolen. See Risks of using an authenticator app.
    4. If you use an authenticator app, store its backup code somewhere safe and offline. Anyone who finds it can set up your 2FA on their own device. Turn off cloud sync too: if someone gets into the Google, Apple or Microsoft account your codes sync to, they get your 2FA codes as well. See Risks of using an authenticator app.
    5. If you lose access to your Sign-in 2FA, see I can’t sign in to my account!
  4. 4

    Set up a Master Key using a Passkey. It protects you against unwanted password resets and works as a backup for your Sign-in 2FA.

    1. If your email is ever compromised, a Master Key stops anyone from resetting your Kraken password without it.
    2. Keep your Master Key on a different device from your Sign-in 2FA, so losing or compromising one device doesn’t expose both. For example, if your Sign-in 2FA Passkey is on your phone, create your Master Key Passkey on a Hardware Security Key. Never keep both in the same authenticator app. See Risks of using an authenticator app.
    3. Select your profile icon and open your Security settings. Find Master Key and follow the prompts to set it up.
    4. Set up your Master Key before you turn on the Global Settings Lock (GSL). You can’t add or change a Master Key while the GSL is on.
  5. 5

    Turn on the Global Settings Lock (GSL) to block changes to your account settings and withdrawal addresses, even if someone gets into your account.

    1. When you turn on the GSL, you choose how long it takes to remove it, from 1 to 30 days. The default is 3 days.
    2. Without a Master Key, you’ll need to wait the full period to remove the GSL. Kraken Support can’t shorten it. If you set up a Master Key before the GSL, you can use it to remove the GSL immediately.
    3. Select your profile icon and open your Security settings. Find Global Settings Lock, turn it on and choose your waiting period.
  6. 6

    Turn on 2FA for withdrawals, trading and API keys.

    1. You’ll find withdrawal and trading 2FA in your Security settings, in the same place as Sign-in 2FA and your Master Key. For API keys, see How does two-factor authentication (2FA) for API keys work?
    2. These only protect you if someone who gets into your account can’t turn them off. Sign-in 2FA or the GSL stops that.
  7. 7

    Check your account activity regularly.

    1. Review your active sessions and connected devices. On Kraken and the Kraken app, select your profile icon, then Device Management. On Kraken Pro, select your profile icon, then Security > Device Management.
    2. If you see a session or device you don’t recognize, see My account is compromised, what should I do?
    3. Keep your email notifications turned on, and act quickly on any security email you don’t expect, such as a new device approval or a new withdrawal address.
  8. 8

    Beware of scams.

    1. Bookmark id.kraken.com/sign-in and use the bookmark to sign in, instead of searching for Kraken.
    2. Never share your sign-in details with anyone. Kraken Support will never ask for your password or ask you to install third-party software.
    3. Check any email that claims to be from Kraken against Is this email from Kraken?
  9. 9

    Only use Kraken’s official apps: the Kraken app, Kraken Pro app, Krak app and Kraken Wallet. Any other app that uses Kraken’s name or asks for your Kraken sign-in details is phishing.

If someone gets into the email address linked to your Kraken account, they can use it to request your username, reset your password and approve withdrawals.

  1. 1

    Create a password using the same guidelines as for your Kraken password.

    1. Make sure it’s unique and not used for any other account.
  2. 2

    Turn on two-factor authentication (2FA) for your email account, using Passkeys if your email provider offers them. Don’t use text message (SMS) 2FA if you have another option.

  3. 3

    Remove your phone number from your email account.

    1. Many email providers let you reset your password by text message. If someone takes over your phone number, they can reset your email password and then use your email to reset your Kraken password. Use Passkeys and securely stored backup codes to recover your email account instead.
  4. 4

    If you’re comfortable using encryption tools, set up PGP to receive signed and encrypted email from us, if your email provider supports it.

For more information, see Securing your email address.

A compromised device can record everything you type on it. Your phone is also the device most people use for two-factor authentication (2FA), so protect it carefully.

  1. 1

    Lock your devices with a strong passcode.

    1. Use a long passcode and turn on biometric sign-in (fingerprint or facial recognition) if your device supports it. Avoid easy-to-guess PINs and unlock patterns.
  2. 2

    Don’t share your devices.

    1. Don’t share access or passwords to your devices, even with friends and family, especially devices you use for 2FA.
  3. 3

    Never install remote access software, such as AnyDesk, TeamViewer or Quick Assist, because someone contacted you and asked you to.

    1. Scammers often pose as tech support, your bank or an exchange and ask for remote access to “fix” an urgent problem. Once connected, they can see and control your device and take over your accounts.
    2. If you use these tools for a legitimate reason, such as work or helping family, only accept sessions you arranged yourself, and never sign in to Kraken or approve a withdrawal while someone is connected. See Risks of remote access software.
    3. Kraken Support will never ask you to install remote access or screen sharing software.
  4. 4

    Only sign in from your own personal devices. Avoid public computers and shared devices.

  5. 5

    Don’t use work devices for personal accounts. Your employer may be able to monitor and record your activity on them.

Phone numbers are widely used to sign in to and recover accounts, which makes them a target. Attackers can trick mobile carriers into moving your number to a SIM card they control. This is called a SIM swap. Once they control your number, they can receive your text message codes and take over your accounts.

Take these steps:

  1. 1

    Avoid using your phone number to sign in or for two-factor authentication (2FA) wherever you can.

    1. Replace text message (SMS) 2FA with Passkeys. Only use an authenticator app if Passkeys aren’t available.
  2. 2

    Set a strong PIN or passcode on your mobile carrier account so no one can make changes without it.

  3. 3

    Ask your carrier for a port freeze (sometimes called a number lock or port-out protection), and set a SIM PIN, to block unauthorized transfers of your number.

  4. 4

    Regularly check your online accounts and remove your phone number from any that don’t need it.

  5. 5

    If you have a public profile or significant savings or crypto holdings, consider getting a separate phone number that you only use for account security.

    1. Don’t share this number with anyone or use it for anything else.

A compromised internet connection can be used to steal your sign-in details or send you to phishing sites.

  1. 1

    Change the default admin password on your home router.

    1. Default passwords are often printed on the router or published online. Anyone connected to your network, or anyone online if remote management is turned on, could use it to change your router’s settings.
    2. Use a unique password that follows the same guidelines as for your Kraken password. Long, unique passwords are much harder to guess.
  2. 2

    Turn off remote management unless you need it.

  3. 3

    Protect your Wi-Fi network with a password. This is separate from your router’s admin password. Use WPA3 or WPA2 encryption if your router offers it.

  4. 4

    Set up a guest network if your router offers one, and keep your main network for your own devices.

  5. 5

    Avoid public Wi-Fi and use your mobile data instead. If you have to use public Wi-Fi, use a reputable, paid VPN. Free VPNs may log or sell your data.

Malicious browser extensions and fake websites can steal your sign-in details and your crypto.

  1. 1

    Only install the browser extensions you need, from your browser’s official store.

    1. Before installing, check who made the extension and what permissions it asks for. An extension that can “read and change all your data on all websites” can see everything you do in your browser.
    2. Remove extensions you no longer use.
    3. Fake versions of popular crypto wallet extensions are common. Only download a wallet from its provider’s official website.
  2. 2

    Watch out for wallet drainer sites.

    1. These are fake websites, often promoted through ads, social media, direct messages or “free airdrop” offers, that ask you to connect your crypto wallet and approve a transaction. Approving it can give the scammer permission to move your funds.
    2. Never connect your wallet or approve a transaction on a site you reached through a link someone sent you. Check the web address carefully first.
    3. Read what you’re approving before you confirm. If your wallet asks for permission to spend your tokens, or shows a request you don’t understand, reject it.
  3. 3

    Never copy and paste a command into your computer because a website tells you to, for example to “prove you’re human.” This is a common way to install malware. See Beware of computer malware and Risks of remote access software.

The more people know about your crypto, the more likely you are to be targeted by phishing, SIM swaps, extortion and, in rare cases, physical threats.

  1. 1

    Don’t post about your crypto holdings, balances or trading profits on social media, including screenshots.

  2. 2

    Don’t share wallet addresses in a way that links them to your name. Anyone can see a wallet’s balance and history on the blockchain.

  3. 3

    Limit the personal details you share online, such as your home address, phone number, email address, employer and travel plans. Attackers use them to impersonate you to your mobile carrier or email provider, and to make phishing messages more convincing.

  4. 4

    Be wary of anyone who contacts you about crypto out of the blue, including on social media, dating apps and messaging apps. See Protect yourself from scams.