Security at GXT Exchange
Security is foundational to GXT Exchange. We combine institutional-grade custody, deep technical defences and transparent reserves to keep your assets safe.
01.Verify you're on the official site
Before entering your password or 2FA code, always confirm the address bar shows exactly one of these domains, with a valid HTTPS lock icon:
https://gxtexchange.comhttps://www.gxtexchange.com
Any other spelling (extra letters, hyphens, different endings such as .net, .io, .app) is not us. Do not sign in, do not connect a wallet, and do not enter any code on such a page.
02.What GXT Exchange will never do
- Ask for your password, 2FA code, or recovery seed phrase — over email, chat, phone, or any support form.
- DM you first on Telegram, WhatsApp, X, Discord, or Instagram offering "account recovery", "airdrops", or "VIP support".
- Ask you to move funds to a "safe wallet", "verification address", or any external address to unlock or protect your account.
- Send you a link to install remote-access software (AnyDesk, TeamViewer, etc.) to fix an account issue.
- Charge a fee to withdraw, unlock, or verify your own funds.
03.Protect your account
- Enable 2FA (TOTP) from Settings → Security immediately after signup.
- Use a unique password that is not reused anywhere else.
- Bookmark
https://gxtexchange.comand open the site from your bookmark — never from an email link, search-engine ad, or social-media DM. - Set a withdrawal address whitelist so funds can only leave to addresses you pre-approved.
- Review Active Sessions in Settings regularly and sign out any device you don't recognise.
04.Report phishing or a suspicious message
If you receive an email, DM, or see a website that impersonates GXT Exchange, forward it to security@gxtexchange.com. Include the full URL, sender address, and a screenshot if possible. Do not click any links inside the message first.
05.Asset Custody
98%+ of customer assets are held in air-gapped, geographically distributed multi-signature cold wallets. Hot wallets are limited to operational liquidity and protected by HSM-backed key shards and withdrawal velocity controls.
06.Proof of Reserves
GXT Exchange publishes a monthly Proof of Reserves report using Merkle-tree attestations, allowing every user to cryptographically verify that their balance is fully backed 1:1 by on-chain reserves.
07.User Protection Fund
A $300M reserve fund is set aside in stablecoins and BTC to compensate users in the rare event of an extreme security or operational incident outside their control.
08.Account Security
Mandatory password complexity, optional anti-phishing code, device whitelisting, withdrawal address whitelists, 24-hour withdrawal lockout on new devices, and TOTP/passkey 2FA across login, withdrawal, API and password change.
09.Platform Defences
WAF, DDoS protection, secure SDLC, code review, third-party penetration tests every quarter, continuous red-teaming, SOC 2 Type II controls and 24/7 SOC monitoring.
10.Bug Bounty
We run a public bug-bounty programme with rewards up to $1,000,000 for critical findings. Submit reports to security@gxtexchange.com.
11.Responsible Disclosure
Please do not publicly disclose vulnerabilities before we have remediated them. We commit to acknowledge reports within 24 hours and triage within 72 hours.
