At BitGo, security is at the core of everything we do, and safeguarding the digital assets of all of our customers is paramount. As part of the regular wallet security health check-up, Bitgo recommends all customers review and implement the latest security best practices to enhance the protection of their digital assets. The following recommendations can help enhance the security of BitGo wallets.
Here are BitGo’s security best practice recommendations:
- If a wallet has only one admin, add at least one more administrator to the wallet.
- If a wallet has no security policies in place (velocity limits, whitelisting, webhook policies, etc.), please implement security policies immediately, starting with velocity limits and whitelist rules.
- If policies exist, review and adjust policies to ensure they genuinely limit unauthorized withdrawals and suspicious activity.
- If a withdrawal limit allows more than 50% of the wallet balance to be emptied in 24 hours, reduce velocity limits to an appropriate level based on transaction patterns.
- If a velocity limit is not set or set higher than the actual spending patterns, adjust limits to align with the operational needs, internal policies, and risk appetite.
- If a wallet is processing 20+ transactions per day and holds significant funds, move excess funds to cold storage or higher-security wallets.
- If a wallet has reject and accept policy configurations, reject will take precedence, these should be reviewed for conflicts and aligned to operational needs, internal policies, and risk appetite.
- For custodial wallets: Review the ‘BitGo Video ID’ policy to ensure the 24 hour Trust Velocity Limit is set to an appropriate amount given normal withdrawal patterns
For references and guides on implementing security best practices, please review the below links or contact our support team at support@bitgo.com.
[Guide] Policy User Guide
[Blog] Securing the Future: Crypto Breach Analysis
Security is an ongoing process. Regularly schedule an internal review of BitGo policies. Leveraging BitGo's security features will ensure assets remain protected.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article