What we protect against
Most losses on exchanges don't come from someone breaking cryptography. They come from four ordinary things, and the controls on this page are built around them:
| Threat | What happens | Control |
|---|---|---|
| Stolen password | Someone signs in as you from another device | Two-factor code, login slow-down, activity alerts |
| Hijacked session | An attacker drives your open account | Withdrawal review: money cannot leave unseen |
| Wrong address | A typo or clipboard malware changes the destination | Address and network checked before sending |
| Phishing | A fake site or "support agent" asks for your code | We never ask for your password or 2FA code |
How a withdrawal is reviewed
The same path applies to every request, from $10 to the whole balance. There is no amount below which review is skipped, and VIP rank does not skip it either.
- Request submitted
The amount is moved out of your available balance immediately, so it cannot be spent twice while it waits.
- Destination checked
A team member confirms the address format matches the selected network and that the address is not flagged.
- Account checked
Recent sign-ins, password or 2FA changes, and unusual activity just before the request are looked at together.
- Sent or declined
Approved requests are broadcast to the network. Declined ones return the full amount to your balance with a written reason and no fee.
Most requests are handled within working hours of the desk. A request can take longer when the account changed its password or 2FA shortly before, when the address is new, or when the network itself is congested. Status is always visible in History.
Signing in
Password
A reset sends a one-time code to your email and replaces the password. Use a password you don't use anywhere else: most account takeovers start with a password leaked from an unrelated site. A signed-in session lasts 30 days on that browser; signing out ends it immediately.
Two-factor authentication
Turn it on in Settings → Security. Scan the QR code with any TOTP app (Google Authenticator, Authy, 1Password, Bitwarden), then enter the 6-digit code to confirm. From then on, signing in needs both the password and a fresh code from your phone.
Repeated wrong passwords
After 5 wrong attempts within 15 minutes, each further attempt is answered more slowly, up to 30 seconds. After 20, further attempts are refused for the rest of the 15-minute window. This makes guessing passwords impractical without locking you out for good.
Alerts that catch problems early
Deposit confirmations and withdrawal status changes can be sent by email, and by Telegram once you link it in Settings → Notifications. Keep at least one channel on: an alert about a withdrawal you didn't request is the fastest way to stop it while it is still in review.
Change your password, turn on or reset 2FA, and message support straight away with the time and what you saw. A withdrawal still in review can be held.
Identity verification
Verification is a short guided flow in Settings → Verification: personal details, address, an identity document and a live face check. Files go to a restricted review area and are used only to decide your application and meet compliance duties. Details on storage and retention are in the Privacy policy.
Your part
Do
- Type the site address yourself or use a bookmark
- Use a unique password and 2FA
- Compare the first and last 6 characters of a pasted address
- Send a small test amount to a new address first
Never
- Share a 2FA code, even with "support"
- Install remote-access apps on request
- Trust a DM promising to "unlock" or "double" funds
- Sign in from a link in an unexpected email
Our staff will never ask for your password, your 2FA code or for you to send funds "for verification". Anyone who does is not us.
Reporting a vulnerability
If you find a security weakness in Bitnetex, write to [email protected] with the steps to reproduce it. Please don't access other people's accounts or data, don't move funds, and give us reasonable time to fix it before disclosing publicly. We don't take legal action against good-faith research that follows these rules.