01

What you are doing

You are hardening both the exchange account and the email account used to recover it.

02

Why it matters

API restrictions do not protect an attacker who controls your full exchange login. Account security is a separate control layer.

03

Before you start

Use a trusted device, updated browser and a password manager. Keep recovery codes offline.

04

Step by step

  1. 01Enable Google 2FA or a supported hardware/passkey method.
  2. 02Protect the linked email account with independent 2FA.
  3. 03Set Bybit anti-phishing protections and verify them on future messages.
  4. 04Review active sessions and remove devices you do not recognize.
  5. 05Use a unique account password and never reuse it for HEDGERON.
05

What you should see

Bybit should show the selected authentication methods as enabled. Save recovery material securely before continuing.

06

Security check

Never share one-time codes, QR setup codes, recovery codes or authenticator seeds with support.

07

Common problems

A security message looks suspicious

Open Bybit from your own bookmark and verify the event inside the account.

You changed your password

Some API keys may become invalid or have shortened validity. Revalidate the HEDGERON connection.

08

Next step

Create a dedicated Standard Subaccount for HEDGERON.

Official sources

Exchange interfaces and rules can change. Verify the current official source before acting.

www.bybit.com