Getting Started
Withdrawal Whitelist on OKX: The Boring Setting That Stops Account Thieves Cold
Even a thief with your password and 2FA hits a wall if withdrawals only work to pre-approved addresses. How the whitelist works, what it costs you in convenience, and who should turn it on.
Security advice usually focuses on keeping attackers out: strong password, two-factor authentication, no phishing links. The withdrawal whitelist starts from a darker assumption — suppose they get in anyway. What can they actually take?
With the whitelist enabled, the answer is: nothing, unless they can send it to an address you approved in advance.
What the whitelist does
A withdrawal address whitelist (OKX calls it the withdrawal address book with whitelist mode) restricts crypto withdrawals to a fixed list of addresses you've saved and verified. While it's on:
- Withdrawals to saved, verified addresses work normally.
- Withdrawals to any new address fail — no matter who requests them or how correctly they authenticate.
- Adding a new address requires fresh verification and, typically, a security delay before it becomes usable.
That delay is the entire point. An attacker who phishes your password and intercepts a 2FA code has minutes. A whitelist forces them to add their own address and wait out a holding period — while you receive notification emails about a change you didn't make.
The threat it actually counters
Most account takeovers follow the same script: gain access, immediately withdraw everything to the attacker's address. The whitelist breaks the second step:
| Attack | Without whitelist | With whitelist |
|---|---|---|
| Phished password + 2FA | Funds gone in minutes | Withdrawal blocked |
| SIM-swapped phone | Attacker resets and drains | New address triggers delay + alerts |
| Malicious browser extension edits address | Funds sent to attacker | Unknown address rejected |
| Leaked API key with withdraw rights | Silent drain | Only whitelisted destinations possible |
It does not protect against scams where you authorise the transfer yourself — fake "investment platforms" that persuade you to whitelist their address defeat it by design. No setting protects against persuasion.
The cost in convenience
Honesty requires listing the friction:
- Sending to a friend, a new wallet or a new platform means adding an address and waiting.
- If you trade across many venues, the address book needs maintenance.
- In an emergency where you genuinely need funds out fast to a new location, the delay works against you.
For an account you actively day-trade with small balances, that friction might not pay for itself. For an account holding meaningful savings — especially one using Earn products where funds sit for long stretches — the trade is heavily in your favour: you rarely withdraw, so the whitelist costs almost nothing and blocks the worst-case scenario.
Set it up alongside these
The whitelist is one layer. It combines well with:
- Anti-phishing code — a phrase you choose that appears in every genuine platform email, making fake emails easier to spot.
- Withdrawal notifications on every channel you actually check.
- App-based 2FA rather than SMS, since SIM swaps are a real attack path.
- A tested recovery plan: know how account recovery works before you need it, as covered in creating and securing an OKX account.
FAQ
Can an attacker just disable the whitelist? Disabling it or adding addresses triggers verification and a security freeze on withdrawals for a period — which is exactly the alarm window that protects you.
Does the whitelist cover internal transfers and Convert? It governs on-chain withdrawals. Trades and conversions inside the account are separate — an attacker could still shuffle assets, but not extract them.
What if I lose access to a whitelisted wallet? Remove that address and add the new one, accepting the verification delay. Keep the address book pruned to wallets you actually control.
This content is educational only — not financial advice.
Facts checked against official OKX pages, July 2026.
