Веерх ↑

Whitelisting

Learn how whitelisting works, where it is used, and how it improves security.

Whitelisting is a security control that defines a list of approved entities—such as wallet addresses, bank accounts, devices, IP ranges, email domains, or users—that are explicitly allowed to interact with an account or system. Anything not on the whitelist is blocked or subject to additional checks.

For financial and crypto services, whitelisting is commonly used to control where funds can be withdrawn, which devices or networks can access an account, and which external communications are trusted. It reduces the risk of unauthorised transfers, account takeover, and phishing.

Why whitelisting is used

Whitelisting addresses several key security and operational risks.

Controlling where funds can go

  • In crypto, users can whitelist specific external wallet addresses for withdrawals.
  • In fiat services, users can pre-approve certain bank accounts or beneficiaries for transfers.
  • Once enabled, withdrawals or transfers are only allowed to these pre-approved destinations.
  • This prevents attackers from draining an account to new, unauthorised addresses even if they gain access.

Restricting access to trusted devices or networks

  • Devices or IP ranges can be whitelisted so that only they can access certain features or log in without extra friction.
  • Useful for corporate or institutional accounts where access should be limited to specific offices, VPNs, or managed devices.
  • Reduces the attack surface by blocking access from unknown or untrusted environments.

Filtering communications and integrations

  • Email domains or specific sender addresses can be whitelisted to ensure important messages are not treated as spam or blocked.
  • API integrations can be restricted to specific IP addresses or keys that are explicitly allowed.
  • Helps prevent phishing, spoofing, and unauthorised third-party access.

Supporting a zero-trust mindset

  • Instead of allowing everything by default and trying to block bad actors (blacklisting), whitelisting starts from “deny all” and only allows known-good entities.
  • This is especially valuable for high-value accounts, institutional users, and sensitive operations.

Common types of whitelisting

Whitelisting is applied in several contexts.

Crypto address whitelisting

  • Users define a list of external wallet addresses that are allowed as withdrawal destinations.
  • When enabled:
    • Withdrawals to non-whitelisted addresses are blocked or require additional approval.
    • Adding a new address to the whitelist often requires:
      • Full authentication (password + 2FA).
      • A waiting period (for example, 24–48 hours) before the address can be used for withdrawals.
  • Benefits:
    • Even if an attacker compromises the account, they cannot immediately withdraw to a new address.
    • Gives users time to notice and react to unauthorised changes.

Bank account and beneficiary whitelisting

  • For fiat transfers, users can pre-approve specific bank accounts or beneficiaries.
  • Once enabled:
    • Transfers are only allowed to these pre-approved accounts.
    • Adding a new beneficiary may require additional verification and/or a cooling-off period.
  • Common in corporate banking, treasury management, and high-net-worth accounts.

Device and IP whitelisting

  • Specific devices or IP address ranges are marked as trusted.
  • Access from non-whitelisted devices or IPs may be:
    • Blocked entirely.
    • Allowed only with additional authentication (for example, stronger 2FA, manual approval).
  • Often used by:
    • Businesses restricting access to office networks or VPNs.
    • Institutional users limiting API or admin access to specific servers.

Email and domain whitelisting

  • Certain email addresses or domains are marked as trusted senders.
  • Messages from these senders:
    • Are less likely to be filtered as spam.
    • May bypass certain security filters (depending on configuration).
  • Used for:
    • Ensuring important notifications (for example, compliance, security, or operational emails) are received.
    • Reducing false positives in email security systems.

API and integration whitelisting

  • API access can be restricted to:
    • Specific IP addresses or CIDR ranges.
    • Specific API keys or certificates that are explicitly allowed.
  • Helps prevent unauthorised third parties from accessing account data or executing trades/transfers even if they obtain some credentials.

How whitelisting works in practice

Implementations vary, but most whitelisting features follow a similar pattern.

1. Enabling whitelisting

  • The user or administrator opts in to whitelisting for a particular feature (for example, “Enable withdrawal address whitelist”).
  • They may be shown a clear explanation of:
    • What whitelisting will restrict.
    • How to add or remove entries.
    • Any waiting periods or cooling-off rules.

2. Adding entries to the whitelist

  • The user specifies allowed entities, such as:
    • Crypto wallet addresses (with network specified).
    • Bank account details or beneficiary names.
    • Device identifiers or IP ranges.
    • Email addresses or domains.
  • Each addition typically requires:
    • Full authentication (password + 2FA).
    • Confirmation via email, push, or other channel.
  • Some systems impose a waiting period before the new entry becomes active for sensitive actions (for example, withdrawals).

3. Enforcing the whitelist

  • When a relevant action is requested (for example, a withdrawal):
    • The system checks whether the destination is on the whitelist.
    • If it is, the action can proceed (subject to other checks like limits and risk scoring).
    • If it is not, the action is blocked or requires additional approval (for example, manual review, senior authorisation).
  • For access controls (devices, IPs):
    • Requests from non-whitelisted sources are denied or challenged.

4. Managing the whitelist

  • Users can typically:
    • View the current list of whitelisted addresses, devices, or domains.
    • Add new entries (with authentication and any required waiting periods).
    • Remove or disable entries that are no longer needed.
  • Changes to the whitelist (especially removals) may themselves be subject to security checks and delays to prevent attackers from quickly disabling protections.

Benefits of whitelisting

Whitelisting provides several important security advantages.

Strong protection against unauthorised transfers

  • Even with full account access, an attacker cannot withdraw funds to a new address that is not whitelisted.
  • The waiting period for new addresses gives users time to detect and respond to unauthorised changes.
  • Particularly effective for crypto, where transactions are irreversible.

Reduced attack surface

  • By limiting access to known-good devices, IPs, or beneficiaries, the number of potential entry points for attackers is reduced.
  • Makes large-scale attacks (for example, from botnets or random IPs) less effective.

Clear, predictable rules

  • Users and administrators have a clear list of what is allowed.
  • Easier to audit and review than complex blacklists or heuristic rules.
  • Supports compliance and internal control requirements for institutional users.

Complement to other controls

  • Works well alongside:
    • Two-factor authentication.
    • Device binding and fingerprinting.
    • Velocity limits and transaction monitoring.
  • Adds an additional layer that an attacker must bypass.

Limitations and trade-offs

Whitelisting is powerful but not a complete solution on its own.

Reduced flexibility

  • Users cannot instantly withdraw to new addresses or accounts; they must plan ahead and manage the whitelist.
  • May be inconvenient for users who frequently interact with new counterparties or addresses.
  • Requires discipline to keep the whitelist up to date.

Social engineering and insider risk

  • If an attacker convinces a user to add a malicious address to the whitelist (for example, via phishing or impersonation), the protection is bypassed.
  • Insider threats (for example, a compromised employee with whitelist management rights) can also undermine controls.
  • Whitelisting must be combined with user education and strong access controls.

Management overhead

  • For institutional users with many beneficiaries, devices, or addresses, maintaining the whitelist can become complex.
  • Requires clear processes for adding, reviewing, and removing entries.
  • May need role-based access (for example, one team proposes additions, another approves).

Not a substitute for other security

  • Whitelisting protects against certain threats but does not stop:
    • Phishing that tricks users into authorising malicious changes.
    • Malware on a trusted device that initiates allowed actions.
    • Compromised credentials used from a whitelisted IP or device.
  • Must be part of a broader security programme.

How whitelisting affects users

From a user’s perspective, whitelisting shows up in several ways.

During setup

  • An option to enable whitelisting for withdrawals, beneficiaries, devices, or IPs.
  • Clear explanation of how it works, including any waiting periods and restrictions.
  • Initial configuration of allowed addresses, accounts, or devices.

When making withdrawals or transfers

  • If whitelisting is enabled:
    • You can only send funds to pre-approved addresses or accounts.
    • Attempting to use a new address triggers a flow to add it to the whitelist, which may include:
      • Additional authentication.
      • A waiting period before the address can be used.
  • This adds a small delay for new destinations but significantly improves security.

When managing security settings

  • A “Whitelisted addresses” or “Trusted beneficiaries” section where you can:
    • View current entries.
    • Add new addresses or accounts.
    • Remove entries that are no longer needed.
  • Possible restrictions on removing or changing the whitelist (for example, delays or additional approvals) to prevent attackers from quickly disabling it.

For institutional or business users

  • Role-based workflows for proposing and approving whitelist changes.
  • Audit logs showing who added or removed entries and when.
  • Integration with internal policies and compliance processes.

Good practices for users

To use whitelisting effectively:

  • Enable address or beneficiary whitelisting if you hold significant balances or want stronger withdrawal protection.
  • Only add addresses and accounts that you truly trust and control; double-check each entry before confirming.
  • Keep your whitelist up to date by removing old or unused entries.
  • Be cautious of anyone asking you to add a new address or account, especially under pressure or urgency; verify through independent channels.
  • Combine whitelisting with other security measures (2FA, device binding, strong passwords) for layered protection.

Good practices for services

For platforms implementing whitelisting:

  • Make the whitelist feature easy to find, enable, and manage in security or withdrawal settings.
  • Provide clear explanations of how whitelisting affects withdrawals, transfers, and access.
  • Enforce strong authentication and, where appropriate, waiting periods for adding new entries.
  • Allow users to view a full history of whitelist changes for transparency and auditing.
  • Combine whitelisting with other controls (risk scoring, monitoring, velocity limits) rather than relying on it alone.
  • For institutional users, support role-based access, approval workflows, and detailed audit logs.
Spend your
crypto.
Don’t sell it
Join the members who figured it out.

Cookies preferences

✕

Others

Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.

Necessary

Necessary
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.

Advertisement

Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.

Functional

Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.