What you are doing
You are hardening both the exchange account and the email account used to recover it.
Why it matters
API restrictions do not protect an attacker who controls your full exchange login. Account security is a separate control layer.
Before you start
Use a trusted device, updated browser and a password manager. Keep recovery codes offline.
Step by step
- 01Enable Google 2FA or a supported hardware/passkey method.
- 02Protect the linked email account with independent 2FA.
- 03Set Bybit anti-phishing protections and verify them on future messages.
- 04Review active sessions and remove devices you do not recognize.
- 05Use a unique account password and never reuse it for HEDGERON.
What you should see
Bybit should show the selected authentication methods as enabled. Save recovery material securely before continuing.
Security check
Never share one-time codes, QR setup codes, recovery codes or authenticator seeds with support.
Common problems
A security message looks suspicious
Open Bybit from your own bookmark and verify the event inside the account.
You changed your password
Some API keys may become invalid or have shortened validity. Revalidate the HEDGERON connection.
Next step
Create a dedicated Standard Subaccount for HEDGERON.
Privacy note
HEDGERON Help analytics must never collect API credentials, passwords, private account values or secret-bearing URLs.
Official sources
Exchange interfaces and rules can change. Verify the current official source before acting.
www.bybit.com