Security Center · Cta
CoinDock Security Standards
Security claims are only useful when the boundary is stated. This page covers both what CoinDock does and where its protection stops.
Account controls
| Control | What it stops |
|---|---|
| Two-factor authentication (TOTP) | A stolen or reused password |
| Passkeys | Phishing — the credential is bound to the domain and cannot be relayed |
| Email verification | Access before an address is confirmed |
| Password confirmation on security changes | Someone using an already-open session to alter your authentication |
| Trusted device management | Persistent access from a device you no longer control |
Scoped API keys (read / trade / withdraw) |
A leaked key doing more than its purpose required |
| HMAC request signing | Replay and tampering on API requests |
| Withdrawal allowlist with cooldown | Momentary account access being converted into an immediate withdrawal |
| KYC gating on trading and withdrawal | Anonymous movement of funds through the platform |
Configure these in your account settings. Start with how to set up 2FA and account protection.
Where the boundary is
Stated plainly, because a misunderstood boundary is itself a risk:
CoinDock account controls protect your CoinDock account. They do not protect a self-custody wallet. 2FA, passkeys, and trusted devices have no bearing on a wallet you control yourself — anyone with that seed phrase controls those funds regardless of your exchange settings.
API keys authenticate independently of your login. A valid signed request does not present a 2FA challenge; that is what makes automation possible. The controls there are minimal scoping and revoking what you do not use.
Listing review is verification, not endorsement. CoinDock verifies that a token is what it claims to be. That is not an assessment of whether a project will succeed, and it is not a recommendation to buy.
No control makes trading safe. Cryptocurrency trading carries risk of total loss regardless of how well an account is secured.
What CoinDock will never do
- Ask for your seed phrase or private keys — no legitimate service has any use for them
- Contact you first requesting a payment, an approval, or a credential
- Send an invoice as an address in a message — invoices appear in your authenticated account
- Guarantee a price, a return, or a performance outcome
If something claiming to be CoinDock does any of these, it is not CoinDock. Report it through coindock.online/about, reached by typing the domain rather than following a link.
Your side of it
The controls above bound what an attacker can do with your account. These bound what any single mistake can cost you overall:
- Separate wallets by purpose — vault, trading, burner. Your most likely mistake then costs you a burner.
- Initiate contact yourself. Type domains; never follow links or respond to approaches.
- Read what you sign — which contract, which token, what amount.
- Verify identifiers, not labels — contract addresses over token names, full destination addresses over the first four characters.
- Add withdrawal addresses in advance, so the cooldown protects rather than obstructs you.
Full setup: how to protect your wallet.
Risk disclosures
Cryptocurrency trading carries risk of total loss. Prices are volatile, markets can be illiquid, and a position that appears valuable on a thin order book may not be exitable at anything near its quoted price.
CoinDock publishes educational material. Nothing on this site is financial, investment, legal, or tax advice, and CoinDock does not forecast prices or guarantee outcomes.
Full disclosures: coindock.online/risk.
If something has gone wrong
Secure funds before investigating — the order matters:
- Move funds from a clean device to a wallet whose seed never touched the suspect machine
- Revoke approvals on the affected wallet
- Assume the seed is burned if it may have been exposed
- Secure email first, then your exchange account: password, sessions, trusted devices, API keys, withdrawal allowlist
- Then capture evidence and report
- Ignore any recovery offer that reaches you afterwards — that is a second fraud
Detail: how to report phishing.
Educational content. Not financial, investment, or legal advice. No security practice eliminates the risk of loss.
Related on Security Center
-
Security Center
Everything CoinDock publishes on crypto security — wallets, scams, contract checks, and account protection.
-
Wallet Safety Guide
A wallet stores keys, not coins. Once that is clear, most wallet security advice stops being arbitrary rules and starts...
-
Crypto Security Basics
Most crypto security advice is a list of rules. This is where the rules come from — which is what lets you handle situat...
-
Common Crypto Scams
Each scam here has a mechanism and a specific check that defeats it. Knowing the mechanism matters more than memorising...
-
How to Protect Your Wallet
A setup that limits the damage of mistakes rather than trying to prevent all of them.
Review CoinDock Security Standards
Continue your CoinDock journey.
Go