Sign in securely
Notes: Never enter your password or MFA code in response to unsolicited messages. CoinSmart (or any legitimate exchange) will not ask you to provide your password or recovery codes in email or chat.
Recommended pre-login checks
- Confirm you are on the correct, secure site (look for the correct domain and HTTPS certificate).
- Use a personal device or a managed, trusted machine — avoid public kiosks for account access.
- Have your authenticator app or hardware MFA device ready if you enabled MFA.
- Use a password manager to store and autofill strong, unique passwords for each service.
Enabling Multi-Factor Authentication (MFA)
MFA dramatically improves account security. Prefer time-based one-time password (TOTP) apps (Google Authenticator, Authy, or similar) or a hardware security key (FIDO2 / WebAuthn) when available.
- After login, go to Security > Two-Factor Authentication in your account settings.
- Choose an authenticator app or hardware key and follow the on-screen pairing steps.
- Record any backup/recovery codes in a secure, offline location (physical safe or encrypted vault).
Account recovery & password reset
If you lose access to your password or MFA device, follow the official account recovery steps provided through the exchange’s verified support portal. Typical steps include:
- Use the “Forgot password” flow to receive an email with a secure reset link.
- Complete identity verification if requested — this can include ID documents or liveness checks.
- Never share your password, recovery codes, or full ID documents with unverified third parties.
Troubleshooting common login issues
- 1. Didn’t receive the MFA code or email?
- Check spam folders, verify that your email address is correct, and ensure your authenticator app is synced to the correct time. If a hardware key is used, confirm browser and OS compatibility.
- 2. My device shows a certificate or security warning
- Do not proceed if the browser warns about invalid certificates. Confirm the URL, clear your browser cache, and try again. If the warning persists, contact official support and avoid entering credentials.
- 3. I suspect unauthorized access
- Immediately reset your password from a trusted device, revoke active sessions in security settings, and contact official support to freeze account activity if needed.
Best practices for long-term account safety
- Use a strong, unique password and rotate it periodically.
- Keep MFA enabled at all times and back up recovery codes offline.
- Audit connected apps and API keys — revoke those you no longer use.
- Use watch-only wallets or separate accounts for active trading versus long-term holdings.