> For the complete documentation index, see [llms.txt](https://mc-markets.gitbook.io/mcmarkets-infohub/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mc-markets.gitbook.io/mcmarkets-infohub/faq/security-settings.md).

# Security Settings

<details>

<summary><strong>When is 2FA required? How many wrong attempts before it locks, and for how long?</strong></summary>

Sensitive operations: transactions over 1,000 USDT, unusual logins, new-device logins, withdrawals, binding a wallet or withdrawal address, setting or resetting the fund password, binding or resetting Google Authenticator, and creating or managing an API Key — all require security verification.&#x20;

Verification codes are valid for 30 seconds; 5 consecutive failed attempts trigger a 15-minute lockout; resetting Google Authenticator triggers a 24-hour withdrawal lock period.

</details>

<details>

<summary><strong>How do I set up a Fund Password?</strong></summary>

The Fund Password is used for sensitive asset operations such as withdrawals, Vault redemptions, and crypto-address management. Change it under User Center → Security Center → Fund Password. \
\
The current Change Password dialog states that Withdrawal and Crypto Address functions are disabled for 24 hours after a change. If forgotten, select "Forgot your Fund Password?" and complete security verification — any restriction that applies after a reset will be shown on the reset page at the time, and may differ from the 24-hour lock that follows a password change.<br>

</details>

<details>

<summary><strong>What should I do if I forget my Fund Password?</strong> </summary>

Click **\[Reset]**, complete verification via email or Google Authenticator, and set a new password. After a successful reset, the account will enter a 24-hour withdrawal lock period (subject to real-time display on the page and final system settlement).

</details>

<details>

<summary><strong>What should I do if my 2FA code isn't working?</strong> </summary>

You can log in using the recovery codes you saved when binding 2FA. If you have run out of recovery codes, please contact <cs@mcmarkets.com>.

</details>

<details>

<summary><strong>How do I reset Google Authenticator?</strong> </summary>

Go to **\[Security Center]** → **\[Google Authenticator]** and click **\[Reset]**. After verification, scan the QR code to rebind. After a successful reset, the account will enter a 24-hour withdrawal lock period (subject to real-time display on the page and final system settlement).

</details>

<details>

<summary><strong>What is Degraded Verification?</strong> </summary>

When your current verification method is unavailable, the system will automatically switch to another available method. If none are available, please contact customer support.

</details>

<details>

<summary><strong>Why can't I withdraw after modifying my security settings?</strong> </summary>

The current Fund Password Change Password dialog states that Withdrawal and Crypto Address functions are disabled for 24 hours after a fund-password change. If your Fund Password is forgotten, select ‘’Forgot your Fund Password?’’ and complete security verification.&#x20;

Resetting Google Authenticator also follows the 24-hour protection shown on the current page. Any protection period after a reset is shown on the reset page. Other security changes may use different protection rules, so review the notice shown for that action.

</details>

<details>

<summary><strong>Why do wallet users need to bind an email?</strong> </summary>

An email address is what enables 2FA and other security features, ensuring the security of your account.

</details>

<details>

<summary><strong>How do I view and manage platform notifications?</strong></summary>

Click the bell icon in the top-right corner to open the Message Center and view your notifications. To manage notification preferences, go to User Center → Notification Preferences → Manage, where you can control Inbox and Email delivery separately for Activity and Marketing notifications.&#x20;

Important note: necessary service notifications (such as order status or account security alerts) are not affected by the marketing notification toggles and will still be sent as normal.

</details>
