Security

The slow step is on purpose.

Deposits credit automatically because the blockchain has already verified them. Withdrawals don't, because nothing outside Bitnetex has verified that request yet. Every withdrawal is checked by a person before it leaves.

What we protect against

Most losses on exchanges don't come from someone breaking cryptography. They come from four ordinary things, and the controls on this page are built around them:

ThreatWhat happensControl
Stolen passwordSomeone signs in as you from another deviceTwo-factor code, login slow-down, activity alerts
Hijacked sessionAn attacker drives your open accountWithdrawal review: money cannot leave unseen
Wrong addressA typo or clipboard malware changes the destinationAddress and network checked before sending
PhishingA fake site or "support agent" asks for your codeWe never ask for your password or 2FA code

How a withdrawal is reviewed

The same path applies to every request, from $10 to the whole balance. There is no amount below which review is skipped, and VIP rank does not skip it either.

  1. Request submitted

    The amount is moved out of your available balance immediately, so it cannot be spent twice while it waits.

  2. Destination checked

    A team member confirms the address format matches the selected network and that the address is not flagged.

  3. Account checked

    Recent sign-ins, password or 2FA changes, and unusual activity just before the request are looked at together.

  4. Sent or declined

    Approved requests are broadcast to the network. Declined ones return the full amount to your balance with a written reason and no fee.

How long it takes

Most requests are handled within working hours of the desk. A request can take longer when the account changed its password or 2FA shortly before, when the address is new, or when the network itself is congested. Status is always visible in History.

Signing in

Password

A reset sends a one-time code to your email and replaces the password. Use a password you don't use anywhere else: most account takeovers start with a password leaked from an unrelated site. A signed-in session lasts 30 days on that browser; signing out ends it immediately.

Two-factor authentication

Turn it on in Settings → Security. Scan the QR code with any TOTP app (Google Authenticator, Authy, 1Password, Bitwarden), then enter the 6-digit code to confirm. From then on, signing in needs both the password and a fresh code from your phone.

Repeated wrong passwords

After 5 wrong attempts within 15 minutes, each further attempt is answered more slowly, up to 30 seconds. After 20, further attempts are refused for the rest of the 15-minute window. This makes guessing passwords impractical without locking you out for good.

Alerts that catch problems early

Deposit confirmations and withdrawal status changes can be sent by email, and by Telegram once you link it in Settings → Notifications. Keep at least one channel on: an alert about a withdrawal you didn't request is the fastest way to stop it while it is still in review.

Saw activity you don't recognise?

Change your password, turn on or reset 2FA, and message support straight away with the time and what you saw. A withdrawal still in review can be held.

Identity verification

Verification is a short guided flow in Settings → Verification: personal details, address, an identity document and a live face check. Files go to a restricted review area and are used only to decide your application and meet compliance duties. Details on storage and retention are in the Privacy policy.

Your part

Do

  • Type the site address yourself or use a bookmark
  • Use a unique password and 2FA
  • Compare the first and last 6 characters of a pasted address
  • Send a small test amount to a new address first

Never

  • Share a 2FA code, even with "support"
  • Install remote-access apps on request
  • Trust a DM promising to "unlock" or "double" funds
  • Sign in from a link in an unexpected email

Our staff will never ask for your password, your 2FA code or for you to send funds "for verification". Anyone who does is not us.

Reporting a vulnerability

If you find a security weakness in Bitnetex, write to [email protected] with the steps to reproduce it. Please don't access other people's accounts or data, don't move funds, and give us reasonable time to fix it before disclosing publicly. We don't take legal action against good-faith research that follows these rules.