To keep your mining account secure, use a unique password, enable sign-in two-factor authentication (2FA), verify payout settings, and protect the devices and integrations connected to your account. Monitor security notifications so you can respond quickly to unauthorized activity.
Mining-account security and wallet security protect different parts of your operation. A pool account controls access to settings and withdrawal requests; a wallet’s private keys authorize on-chain spending. Protecting one does not replace protecting the other.
1. Use a unique password and enable sign-in 2FA
Use a strong password for your mining account that you do not reuse for email, exchange accounts, or miner-management software. A reused password can expose multiple accounts if one service suffers a credential leak.
Protect the email account linked to your mining account with a unique password and 2FA as well. That inbox may receive verification codes and password-recovery messages, making it an important part of account security.
For ViaBTC, bind Google Authenticator and then enable “2FA while signing in.” Binding an authenticator and enabling sign-in verification are separate steps. Securely back up the TOTP setup secret shown during binding, preferably offline, and keep it out of screenshots, chat history, and unencrypted cloud notes. This secret restores authenticator access; it is not a Bitcoin wallet private key. See ViaBTC’s 2FA setup guide.
Authenticator-app codes add protection beyond a password, but they are not phishing-resistant. An attacker may use a valid code entered into a fraudulent site. Always verify the website before entering credentials or codes. NIST’s authentication guidelines explain this limitation of manually entered one-time codes.
2. Check login pages and support contacts
Fraudulent login pages and impersonated support contacts can expose account credentials. Bookmark the pool’s official website and check the full domain before signing in, especially when a message asks you to act urgently.
Never give a support contact your login password, 2FA code, email verification code, payment password, wallet seed phrase, or API secret. Enter verification codes only into the verified service when completing an action you initiated.
ViaBTC’s security guidance states that it has no official telephone or live-chat channels and that its group staff will not initiate private chats. It also provides a way to check websites, email addresses, and social-media accounts. Use the ViaBTC Official Verification Channel guide before acting on a suspicious request. Reach support through the official website rather than contact details supplied in an unsolicited message.
3. Verify payout settings before saving changes
Payout addresses, auto-withdrawal settings, and revenue-sharing instructions affect where your mining earnings go. Review changes to these settings carefully.
Before saving an on-chain withdrawal destination, compare the complete address with a trusted record from your receiving wallet or exchange. Do not rely only on a clipboard value or browser autofill. Confirm that the receiving service supports the asset and network you intend to use.
ViaBTC requires security authentication when setting or changing an auto-withdrawal destination. It supports withdrawal to an address, CoinEx, or your own ViaBTC main or sub-account. It also distinguishes payout by account balance from payout by daily earnings. Check the selected destination and payout mode before enabling the feature. See ViaBTC’s auto-withdrawal guide.
Auto-withdrawal can reduce the balance retained on the platform between payouts, but a wrong saved destination can affect subsequent payouts. More frequent on-chain payouts can create more individual receipts than less frequent payouts; enabling automation alone does not determine transaction frequency. Choose settings based on your destination and how you manage your earnings, and review them after any change.
Protect the receiving wallet or exchange account separately. For self-custody, keep wallet recovery information secure; for a custodial account, enable strong authentication. Bitcoin.org’s wallet-security guide provides further guidance.
4. Protect your payment password and recovery details
If the platform offers a separate payment password, use one that differs from your sign-in password. It adds protection for actions that require it, but should not be treated as a guarantee that every payout or account-change workflow is protected by that password.
ViaBTC documents the following withdrawal restrictions after security-detail changes:
- Payment-password reset: withdrawals are suspended for 48 hours after a successful reset. See the payment-password guide.
- Phone-number reset: withdrawals are suspended for 48 hours after a successful reset. See the phone-number guide.
- Account-email change: withdrawals are prohibited for 24 hours after the change. See the account-email guide.
These are ViaBTC product rules, not universal mining-pool standards. They do not guarantee that unauthorized changes will be detected. Investigate unexpected security-change notifications immediately.
5. Secure your ASIC miners
An ASIC miner’s administration interface is separate from your pool account. Someone who gains access to it can change the mining configuration and redirect hashrate without accessing your pool login.
Change the miner’s default administration password, avoid exposing its web interface directly to the public internet, and separate miners from other devices on your network where practical. Obtain firmware from the hardware manufacturer or a source you have independently verified.
Unexpected pool-address or worker-name changes, loss of management access, repeated restarts, failed firmware updates, and reduced or zero hashrate can warrant a device-security check. These symptoms do not prove malware is present, but they should not automatically be treated as hardware faults. Check the configured pool URL and the account portion of the worker name. ViaBTC’s miner-malware guidance describes these symptoms and recommends network isolation and manufacturer assistance when dealing with an infected miner.
The worker-password field is separate from your account credentials. ViaBTC’s BTC mining instructions allow any worker-password value. Follow the instructions for your coin and miner firmware, and never enter your pool-account password in that field.
6. Protect API keys and monitoring access
Create API keys only for integrations you use. Keep keys and secrets out of support tickets, screenshots, and chat messages. Review the access an integration receives and remove keys you no longer need.
If an integration connects from stable IP addresses, use an IP whitelist to restrict access. ViaBTC supports up to 20 addresses in its API whitelist. This restriction supplements secure key storage; it does not replace it. See ViaBTC’s API setup guide.
ViaBTC sub-accounts help separate mining operations, hashrate statistics, earnings, and payout destinations. Do not assume that creating a sub-account also creates an independent staff login or granular team permissions. See the sub-account guide.
For observation, ViaBTC’s Watcher URL lets someone view the information exposed by the link without permission to modify it. Review the viewing permissions when creating a link and share it only with intended recipients. Anyone holding the link can access the information it exposes. See the Watcher URL guide.
7. Monitor activity and respond to unauthorized access
ViaBTC sends an email notification when a login occurs from a new device, location, or IP address. Check whether the activity is yours. If it is not, ViaBTC recommends resetting your password and submitting a support ticket immediately. See its unrecognized-login guidance.
If you see clear unauthorized activity, such as payout settings changing without your approval, promptly freeze the account if you can access it safely. Do not delay containment to rotate individual API keys first. ViaBTC’s freeze feature:
- Disables login to the main account and sub-accounts.
- Suspends revenue sharing and auto-payment.
- Deletes all API keys.
- Cancels pending withdrawals.
- Terminates active login sessions.
Freezing cannot reverse a completed transaction. Reactivation requires a support ticket. Follow ViaBTC’s account-freeze instructions and contact support through a verified channel. If you cannot access the account, contact support immediately.
As part of recovery, use a trusted device to secure your linked email and account credentials. Review payout settings and connected integrations before resuming normal use.
FAQ
Is 2FA enough to secure a mining account?
No. Authenticator-app codes reduce the risk of password-only compromise, but an attacker may use a valid code entered into a phishing site. Combine sign-in 2FA with a unique password, website verification, secure recovery information, and careful payout management.
Does a worker password protect my mining account?
No. The worker-password field belongs to the miner’s pool-connection configuration. ViaBTC’s BTC instructions allow any value in that field. It does not replace your account password, payment password, or 2FA.
Should I enable auto-withdrawal to reduce risk?
Auto-withdrawal can reduce the balance retained on the platform between payouts, but its benefit depends on your settings and receiving account’s security. Verify the saved destination and payout mode. A wrong destination can affect subsequent automatic payouts.
What should I do first if my mining account is compromised?
For clear unauthorized activity, promptly freeze the account if accessible and contact verified support. If you only received an unfamiliar-login alert, first check whether the login was yours; if not, reset your password from a trusted device and contact support immediately. Secure your linked email and review payout settings during recovery.


