Account Security

banner banner

Account Security

See all articles

HashKey Global Team

[Q&A] HashKey Exchange Platform Service Upgrade
Q: Will this upgrade affect the safety of my assets?
A: No. All user assets are securely held and will not be affected after the upgrade. After logging in to the HashKey Exchange App, you can view your account balance and positions on the “Assets” page.
 
Q: Do I need to complete KYC / identity verification again?
A: No. If you have already completed identity verification, your KYC status will be fully retained and integrated into the HashKey Exchange App. No resubmission is required.
 
Q: Will my login method change after the upgrade?
A: Email/mobile login remains unchanged. You can continue to log in with your existing email or mobile number and password. No re-registration is required. Google/Apple third-party login for MENA and Global site users is not supported for direct login to the HashKey Exchange App at this time. Please wait for further notice if you wish to use it.
 
Q: Do I need to register a new HashKey Exchange account?
A: No. Users with email/mobile login can log in to the HashKey Exchange App directly with their existing email or mobile number and password. Your account information, assets, KYC status, and trading history will be retained.
 
Q: Will my historical orders, trade records, deposits, and withdrawals remain available?
A: Yes. Historical orders, trade records, deposit records, and withdrawal records will be fully retained and remain available in the HashKey Exchange App.
 
Q: What should I do if I encounter issues during the upgrade?
A: You can contact us via in-app live chat, email at support@global-cs.hashkey.com, or the Help Center. Our support team will assist you with login and asset status verification.
See more
icon

HashKey Global Team

What is Passkey?
HashKey now supports passkeys for two‑step verification, delivering a code‑free experience and stronger account protection.
 
Learn more about passkeys on the FIDO Alliance website: https://fidoalliance.org/fido2/
 

1. Before You Start

You can create a passkey on:
  • A mobile device running iOS 16.0.0 or Android 7.0 or later.
  • A FIDO2‑compatible USB security key (also called a U2F key). It plugs into any USB port like a flash drive and can be used alongside iOS/Android as an extra layer of protection.
Note: If your iOS version is below 16.0.0 or you removed the built‑in Passwords app, you won’t be able to create a passkey. Please upgrade to iOS 16.0.0 or later and reinstall Passwords from the App Store (iOS 18 or later is required to install the app).
 

2. How do I set up a passkey for my account?

Step 1: Complete identity verification

  1. Go to HashKey User Center → Security Settings → Passkey → Manage → **Add Passkey**.
EN 1.png
EN 2.png
 
  1. To proceed, you must first verify your identity using your existing 2‑step verification.

Step 2: Create your passkey

After verification, follow the on‑screen instructions:
  • Method A: Use this device as your passkey
Tap **Continue**, then complete Face/Touch ID or enter your device passcode.
  • Method B: Create a passkey on another phone/tablet
Tap Other options → choose **iPhone, iPad or Android device**; scan the QR code with another device and approve on that device.
iOS: Devices signed in with the same Apple ID can use passkeys created previously.
Android: Passkeys rely on Google services; you must be able to access Google to use passkeys.
  • Method C: Use a USB security key
Choose Other options → **Security key**; insert the hardware key and follow the prompts.

Step 3: View details and sign in

After creation, review your passkeys on the Passkey page.
Next time you sign in, choose Sign in with a passkey for a code‑free login. You can also use your passkey to quickly verify actions that require additional confirmation (e.g., withdrawals).
 
EN 3.png

3. How do I delete a passkey?

Go to HashKey User Center → Security SettingsPasskeyManage → **Delete**.
Deleting a passkey requires identity verification using your existing 2‑step verification.
 

4. What if my passkey doesn’t work?

During sign‑in, withdrawals, etc., if your passkey can’t be used, click “Passkey not working?” on the verification dialog, then switch to one of your other bound 2‑step verification methods.
EN 4.png
 

See more
icon

HashKey Global Team

How should I set up my password to make it more secure?
When setting your account password, please follow the rules below to enhance your account security.
The password must be at least 8 characters in length and must contain at least an upper case letter, a lower case letter, and a number.
Please use different passwords for different accounts to avoid the loss of multiple associated accounts.
Please do not use important personal information or common words as passwords, and make sure the password is not related to your personal information.
Please update your passwords regularly and back them up securely to avoid using one password for too long. It is recommended that you change your password once every 90 days.
Password change process: Log in to your account - [Security Settings] - [Advanced Settings] - [Login Password].
See more
icon

HashKey Global Team

What is 2FA and why do I need to enable 2FA?
2FA stands for Two-Factor Authentication

It is an extra layer of security for your online accounts. When you enable 2FA, you not only need your password
to access your account but also a second factor, usually something you own, like a smartphone app that generates
a unique code or a physical device.
 
Why You Need to Enable 2FA:
  1. Enhanced Security: Even if someone has your password, they cannot access your account without the second factor.
  2. Protection Against Hacks: Passwords can be compromised through phishing or data breaches, but 2FA adds an extra hurdle for attackers.
  3. Compliance: Some platforms require 2FA to meet regulatory or security standards.
In short, enabling 2FA significantly reduces the risk of unauthorized access to your account.
See more
icon

HashKey Global Team

How to set up 2FA( 2factor authentication)
  1. Firstly, you need to log into your HashKey Global account and on the right top corner click on your personal profile and select "Security Settings"

    1280X1280.PNG

    2.Choose either "Mobile Phone Verification" or "Google Verification" and click on "Settings" to proceed to the respective settings page.
    2.1 For Mobile Phone Verification: Enter your phone number, SMS verification code, and email verification code. Click "Confirm" to successfully bind the phone number.
     
    1280X1280.PNG
    2.2 For Google Verification:
    Download the Google Authenticator app.
    Add the provided key to the Google Authenticator app and make sure to back up the key.
    Enter the email verification code and Google verification code.Click "Bind" to successfully bind Google Verification.
    1280X1280.PNG


See more
icon

HashKey Global Team

How to login to account if access 2FA verifications is lost?
If you have a Google Authenticator key, you can reinstall the Google Authenticator app and enter the key to set it up. The key will only be visible to you if you have activated Google Authenticator in your account. We strongly recommend that you backup this Google Authenticator key for future use in case you need to recover your Google Authenticator settings.
 
If you do not back up the Google authentication Key, don't worry, you can get assistance by contacting our customer support via live chat or email at support@global-cs.hashkey.com.
See more
icon