Security Update: Your Koinex account is safer than ever!

Introducing rock-solid security upgrades for the safest digital assets trading experience

Team Koinex
Koinex Crunch
4 min readDec 29, 2018

--

At Koinex, we treat the safety of user accounts and funds as the top-most priority. In our continuous efforts to strengthen the exchange on the same principle, we are proud to introduce additional layers of security to your Koinex account — greater protection and better functionalities.

10-min Protection Mode

Koinex will now have a Protection Mode, automatically activated for 10 minutes immediately after signing in. To place a withdrawal request for cryptocurrencies in your Koin wallet, you will need to wait for 10 minutes from the time of signing in. In case your account is compromised and there is an unauthenticated withdrawal attempt during the span of the first 10 minutes of the session, the system will throw a pre-defined error (as shown below). This is only applicable to cryptocurrency/token/digital asset withdrawal requests, and P2P INR withdrawal requests can even be placed immediately after signing in. You can trade (place Buy/Sell orders) as soon as you sign in to your Koinex account.

Error pop-up if the withdrawal request is placed before 10mins

In the span of the first 10 minutes of a session, you can easily lock your account if you suspect that your account has been compromised.

Email confirmation for withdrawals

We have put in place an additional verification step for cryptocurrency withdrawals. Progressing from the current withdrawal scheme (initiating a request and verifying with a Google Authenticator code), users will now receive an email on their registered email IDs with a secure link to verify the cryptocurrency withdrawal requests placed from their accounts (sample email below). Unless a withdrawal request is confirmed over email, the status of that withdrawal will be shown as ‘Awaiting Confirmation’ under Koin Withdrawal history.

Withdrawal request mail on your verified email ID

This confirmation link will only be valid for 30 minutes after which users will have to go back to the withdrawal request and click on ‘re-send verification link’ option.

Lock My Account

Whenever a user signs in to Koinex, an email is sent to notify about the recent activity. We have improved this notification email and made it more actionable for our users. The sign in notification email will now carry a ‘Lock My Account’ link. In case any suspicious/fraudulent activity is observed, users will be able to lock their Koinex accounts (halting all trading and transaction activities on the account) with just one click.

Login activity mail on your verified email
  • Upon clicking on the ‘Lock my Account’ link, you will be redirected to an Account Security page which will allow users to choose between two ways of locking their accounts: to keep open orders and lock or to delete open orders and lock.
  • Selecting ‘Delete Open Orders’ will delete all open orders from the account and lock it. Selecting ‘Keep Open Orders’ will leave the open orders be and lock the account (open orders will be executed normally according to prices set by users).
Account Security page

The action to lock your account from the email link does not require you to sign in. Upon choosing to lock your account, you will not be able to track the status of your open orders or modify them before you unlock your account.

Once you lock your Koinex account, you will receive a snapshot (till date) of your trades, deleted orders, deposits and withdrawals on your registered email ID.

  • Once you select an option to lock the account, a confirmation dialogue will prompt for certain information. You will need to enter your date of birth, PAN card number and the reason for locking your account — this is for confirmation purpose only.
Lock my Account confirmation pop-up | Source: Koinex.in

All cryptocurrency withdrawal requests which have not been confirmed by email will be automatically cancelled if the account is locked. All withdrawal requests which have been confirmed via email will be processed as usual, even when users choose to lock their accounts. Once the locking procedure is completed, users will be signed out from all existing devices, including the Koinex mobile application.

More security updates and features are going to roll out on Koinex, stay tuned for further details!

--

--

Team Koinex
Koinex Crunch

Our team is a diverse coalition of engineers, designers, and entrepreneurs who have come together under a united passion: love for Blockchain Technology.