Use a unique password stored in a reputable password manager. Reused credentials turn an unrelated website breach into an exchange account risk.
Prefer authenticator-app or hardware-key two-factor authentication over SMS when supported. Secure the email account connected to the exchange with equal care.
Enable withdrawal allowlists, anti-phishing codes, login alerts, and device review. Remove old sessions and do not approve unexpected prompts.