









While using Bybit, a problem that occurs more frequently than the trading method itself is account and referral relationship management.
Common questions include the following:
- Can I add a referral code later if I missed it during registration?
- Can I change my referrer if one is already registered?
- Are Referral Codes and Affiliate Codes the same?
- Where can I check the referral code of an existing account?
- Can I transfer KYC to another account?
- How can I recover my account if I lose access to my email or phone?
- What should I do if I cannot use Google Authenticator?
- Do I need to set up both Passkey and 2FA?
- Is the withdrawal address whitelist actually safe?
- What should I be careful about when creating an API Key?
As of 2026, Bybit has significantly expanded its account management and security features.
In particular, features such as the ability to retroactively register an Affiliate Code within 14 days of registration, Passkey, Secure Transaction Approval, Anti-Phishing Code, Withdrawal Address Whitelist, and Fund Password are officially provided.
This article does not re-explain Bybit’s general trading methods or futures fees.
For comprehensive information on Bybit registration, trading, and deposits/withdrawals:
Fee structures can be found in a separate Bybit fee-specific guide.
This document focuses on solving Referral / Account / Security issues.
1. First and foremost: Referral and Affiliate are not the same concept
Bybit has both a general Referral Program and an Affiliate Program.
While both are similar in that they invite users, their operational structures differ.
Referral Program
This is a program where general Bybit users invite friends or acquaintances.
In Bybit’s 2026 Referral Program, rewards and trading commission structures are provided to eligible Referees and Referrers. Actual rewards and events change depending on the timing.
Affiliate Program
This is a separate partnership program used by content operators, communities, KOLs, and partners.
Bybit operates a commission and partial rebate structure based on trading volume in the Affiliate Program, and benefits may vary depending on the account and partner conditions.
The reason this distinction is important is that the policy for retroactive addition of referral codes after registration does not apply equally to both programs.
2. What if I missed the Bybit referral code during registration?
In the past:
If you did not enter a referral code during registration, you cannot add it later.
This was the standard explanation.
However, this is no longer accurate as of 2026.
As of June 2026, Bybit officially supports a feature that allows users who meet certain conditions to directly add an Affiliate or KOL Invitation Code within 14 days of registration.
Therefore, you do not necessarily need to create a new account just because you missed the referral code.
3. Conditions for adding an Affiliate Code within 14 days of registration
According to Bybit’s official policy, the following conditions are required to add an Affiliate Code retroactively:
- It must be a Main Account.
- It must be within 14 days of registration.
- No existing Affiliate or Referral Code must be registered.
- The code you intend to enter must be a Bybit Affiliate Code, not a general user Referral Code.
- Market Maker or Institutional Accounts are not supported.
- Joining the corresponding Affiliate Community may be restricted due to regulations.
- Once an Affiliate Code is added, it cannot be canceled or changed to another code later.
These conditions are key.
4. Can I also add a general Referral Code within 14 days of registration?
You should not interpret it the same way.
Bybit’s current retroactive registration feature is intended for Invitation Codes provided by Affiliates, according to official documentation.
Bybit explicitly states:
Referral Codes provided by general Bybit users through the Referral Program are not supported by this retroactive registration feature.
Therefore, if someone on the internet explains:
“Any Bybit referral code can be added within 14 days of registration”
that is not accurate.
You must first verify whether it is an Affiliate Code or a general Referral Code.
5. How to add an Affiliate Code after registration
If you meet the conditions, you can proceed on the Bybit website.
The basic path is:
Profile → Account → Account Info → Join an Affiliate’s Community
If you do not see this menu:
- You may already have a referral relationship,
- 14 days may have passed,
- It may be an unsupported account, or
- You may not meet other eligibility requirements.
You can apply by entering the Affiliate Invitation Code and the reason for the addition in that menu.
6. Where can I check an already registered Affiliate Code?
Bybit allows you to check the registered Affiliate Code in Account Info.
Therefore, if you think:
“I don’t know if a referrer is connected to my account.”
it is correct to check your Account Info before creating a new account.
7. Can I change it if another referrer is already registered?
It is difficult with the general retroactive registration feature.
Bybit’s current Affiliate Code addition policy requires:
The case where no Affiliate or Referrer is connected to the current account at all.
Also, it is explicitly stated that once a new Affiliate Code is successfully added, the registered Invitation Code cannot be canceled or changed.
Therefore, you should not simply advise:
“You can just delete the existing code and change it to COINPOP.”
8. Can I add a referral code if 14 days have passed?
Bybit’s current official retroactive registration policy explicitly states that requests made after 14 days from registration are not accepted.
Therefore, if 14 days have passed, it is appropriate to check the options available in the official Account Info or inquire about your account status through Bybit Support.
Creating a new account is not an automatic solution.
9. Should I create a new account to get a referral code?
You must be careful.
Bybit has separate conditions for KYC and account operation.
Currently, individual users can only process Individual KYC Verification for one account, and if necessary, can transfer verification information to another account through the official Identity Transfer feature.
However, you should not understand this as:
“An account switching feature to get new referral benefits.”
10. What is Bybit Identity Transfer?
Bybit currently provides an official feature that allows you to transfer only Verified Identity information from one account to another.
For example, it can be used in situations where you no longer want to use your existing email or need to change your account structure.
However, Identity Transfer has various conditions and limitations.
11. If I move KYC to another account, does the referral code follow?
No.
This part is very important.
Bybit specifies that what is transferred during the Identity Transfer process is only the Verified Identity information.
The following are not transferred:
- Referral Code
- Affiliate Code
- Assets
- Phone Number
In other words, the Affiliate relationship registered to the existing account is not automatically transferred to the new account.
12. Can I receive new user sign-up events again by transferring KYC?
Bybit also clearly places restrictions on this.
After Identity Transfer, the new account cannot repeatedly receive activity rewards such as Welcome Gifts that were already participated in with the existing account.
Therefore, advising:
“You can receive new member benefits again if you move KYC to a new account.”
is not consistent with current official policy.
13. Major limitations of Identity Transfer
According to the official Bybit guide, the main conditions are as follows:
- At least 24 hours must have passed since KYC completion
- The target account must still be in a non-KYC verified state
- Withdrawal and Fiat functions of both accounts may be restricted for 24 hours after transfer
- Transfer may be restricted depending on the ongoing P2P status
- Open Positions need to be managed in advance
- Some Fiat/Bank Card conditions may need to be cleared
- Referral/Affiliate relationships are not transferred
- Business KYC is not eligible
Therefore, Identity Transfer should be understood as an official identity information transfer procedure, not a feature to easily reset an account.
14. CoinPop Bybit Referral Code
The Bybit partner referral code used by CoinPop is:
COINPOP
New users can check the actual referral code application status on CoinPop’s Bybit guide page or partner registration path.
Actual Fee Rebates, Bonuses, or Promotions provided upon registration may vary depending on:
- Country
- Account
- Campaign
- Partner settings
- Timing
Therefore, rather than expressing that a specific discount rate is permanently guaranteed to all users, it is accurate to check the conditions displayed on the registration screen and your actual account.
15. The first thing to do after creating an account is security setup
Account security is more important than a referral code.
As of 2026, Bybit recommends the following features for account security:
- Google Two-Factor Authentication
- Fund Password
- Passkey
- Secure Transaction Approval
- Anti-Phishing Code
- Withdrawal Security
As the amount increases, relying solely on a password is not appropriate.
16. What is Passkey?
Passkey is a method of authenticating users using:
- Device biometrics
- Screen Lock
- Hardware Security Key
instead of a password.
Bybit supports adding Passkeys on the Account and Security page and advises that you can create up to 10 Passkeys per account.
The advantage of Passkey is that it is more resistant to phishing attacks than the traditional method of manually entering a password.
17. If I set up Passkey, is Google 2FA unnecessary?
It is better to configure security in multiple layers rather than relying on a single feature.
Bybit itself also guides you to use multiple security layers together in its Account Security guide, such as:
- Google 2FA
- Fund Password
- Passkey
- Secure Transaction Approval
- Anti-Phishing Code
Therefore, there is no reason to turn off other security features just because you have set up Passkey.
18. Google Authenticator
Google Authenticator-based 2FA is a representative security measure that protects account logins and sensitive operations.
What is important is not only using Authenticator but also securing a way to recover it if you lose your phone.
The Bybit Help Center provides separate procedures for Google Authenticator recovery, transfer, and deactivation.
19. What if I lose my phone and cannot use Google Authenticator?
You do not need to create a new account.
During the login process, Bybit supports:
Having problems with verification?
You can use this feature to proceed with a self-service change request for Google Authenticator, email, or phone verification information.
Some self-service features may be restricted for Suspended or Restricted Accounts.
20. When you can no longer use your email
Bybit provides a feature to change your registered Email Address.
You can change it in Account and Security, and if you cannot permanently access your existing email, you can use the self-service procedure on the login verification screen.
Therefore, you do not need to think:
“If I lose my email, my Bybit account is finished.”
However, you may be required to undergo additional Identity/Security Verification.
21. Changing phone number
Bybit allows you to change your registered Mobile Number or link a new number in Account Security.
Depending on the situation, the change process may require authentication such as:
- Existing Mobile Verification
- New Mobile Verification
- Google 2FA
There is also a condition that you cannot use a new number if it is already registered to another existing Bybit account.
22. Anti-Phishing Code is definitely worth setting up
Phishing attacks are a very common method of cryptocurrency account theft.
Bybit’s Anti-Phishing Code is a feature that displays a string specified by the user in official Bybit emails and text messages.
For example, suppose you set a string known only to you, such as:
BLUE-8251
as your Anti-Phishing Code.
If that code is missing from an email impersonating Bybit, you have a reason to be suspicious.
23. Is an email definitely genuine just because it has an Anti-Phishing Code?
You should not judge based on just one security measure.
If you receive a suspicious message, you should check:
- Sender address
- Domain
- Link address
- Anti-Phishing Code
- Whether login is requested
- Whether urgent withdrawal is requested
Bybit also guides users to distinguish impersonation messages using Anti-Phishing Codes in its 2026 phishing response guide.
24. What is Secure Transaction Approval?
This is a feature to pay particular attention to in Bybit account security in 2026.
Secure Transaction Approval is a feature that designates a specific mobile phone of the user as the Primary Device, and requires approval from that Primary Device when important transactions such as withdrawals are executed from another device or website.
For example, even if a PC account is compromised, you can create an additional defense layer where an approval request is sent to the registered primary mobile phone if an attacker attempts a withdrawal.
25. Secure Transaction Approval usage conditions
According to official Bybit guidance, the following conditions are required before activation:
- Completion of at least Standard Identity Verification
- Activation of Passkey or SMS Authentication
- Activation of Email Authentication or Google 2FA
Secure Transaction Approval itself is activated in the Bybit App.
It is a very useful feature if your asset size is large.
26. What is Fund Password?
Bybit also provides a separate Fund Password feature.
You can place an additional authentication layer for fund-related operations, separate from your login password.
If you forget your Fund Password, you can use the official reset procedure.
A point to note is that if you reset your Fund Password, withdrawals may be restricted for 24 hours.
This can be seen as a security constraint to reduce the risk of an attacker changing the Fund Password immediately after accessing the account and withdrawing assets.
27. Withdrawal Address Whitelist
If you keep a large amount on Bybit, this is a feature worth reviewing.
By setting up a Withdrawal Address Whitelist, you can manage verified withdrawal addresses.
Bybit provides the following features:
- Withdrawal Address Whitelist
- Daily Whitelist Withdrawal Limit
- Withdraw via Address Book
28. Daily Whitelist Withdrawal Limit
In addition to simply registering withdrawal addresses, you can set a daily whitelist withdrawal limit.
According to official Bybit guidance, additional security verification is required for withdrawals exceeding the set limit.
For example, if you are a user whose daily withdrawal amount is usually 10,000 USDT or less, you can create an additional barrier against abnormally large withdrawal requests.
29. Withdraw via Address Book
If you turn on this feature, you can restrict withdrawals to only addresses pre-registered in your Address Book instead of freely entering new addresses on the withdrawal screen.
This can help reduce the risk of an attacker entering their own wallet address to withdraw assets when an account is compromised.
30. Points to note regarding withdrawal whitelists
In Bybit’s whitelist structure, you can set it so that email and 2FA verification are not required for subsequent withdrawals to specific pre-verified addresses.
Therefore:
“Add any address to the whitelist for convenience”
can actually be dangerous.
It is appropriate to register only addresses you own or verified addresses that you trust and will use for a long time in the whitelist.
31. Bybit Protect
In 2026, Bybit also guides users on a multi-layered security framework called Bybit Protect.
This system is a structure that combines various security measures to protect accounts and assets, and also includes features like Secure Transaction Approval.
In other words, Bybit’s recent security direction is closer to creating separate defense layers at each stage:
Login → Device → Transaction → Withdrawal
rather than relying on a single OTP.
32. Security is more important when using API Keys
If you use automated trading, trading bots, or external programs, you can create API Keys.
Bybit supports API Key creation only on the website and advises that for new accounts, API Key creation may be restricted for the first 48 hours after registration for risk management purposes.
Important principles when using APIs are:
- Grant only necessary permissions
- Delete unused keys
- Do not expose Secret Keys externally
- Use a trusted fixed IP environment if possible
- Do not give unnecessary asset transfer permissions to programs that do not require withdrawal permissions
is the principle.
33. Can I show my API Secret to others?
No.
API Key and Secret are sensitive information, similar to account passwords.
Especially if there is a service on the internet that demands:
“Send us your API Secret for automated trading connection.”
you should be very cautious.
Before using a bot or external platform, it is important to check:
- Required Permissions
- API management method
- Business reliability
- IP restriction feature
is important.
34. If your KYC information is incorrect, there is no need to create a new account
As of 2026, Bybit provides a feature for Individual KYC users to directly modify their existing Identity Information if they meet certain conditions.
For example:
- Name recognition errors
- Name order issues
- ID renewal
- Address information changes
These can be handled via the official Update Info feature.
Therefore, creating a new account due to minor KYC errors is not a priority.
35. Can one person complete KYC on multiple accounts simultaneously?
Bybit states in its Individual KYC FAQ that only one account per user can process KYC Verification.
If you need to transfer your identity to another account, you must use the previously mentioned Identity Transfer feature.
36. What should I do first if I suspect my account has been compromised?
The most important step is to block further asset leakage rather than trading.
The following sequence is appropriate:
- Verify if it is the official Bybit site/App
- If login is possible, check your Password and Security status
- Check for unknown Devices and Activity
- Check API Keys
- Check Withdrawal-related settings
- Deactivate the account if necessary
- Submit a case to official Bybit Support
The Bybit Help Center provides separate self-service menus for Account Deactivation, Reactivation, Password Reset, and Security Settings.
Official Support also operates a separate Case Submission system.
37. What if I logged in on a phishing site?
It is recommended to immediately check the following items:
- Change Password
- Passkey status
- Google 2FA
- API Key
- Withdrawal Address
- Login Device
- Security of the email account itself
Bybit’s official phishing response documentation also guides users to identify impersonation emails and suspicious links, and to utilize account security features.
In particular, if the attacker has also gained control of your email account, changing your Bybit password alone may not be sufficient.
38. Recommended Bybit account security settings
Generally, the following configuration is recommended:
| Security Feature | Priority |
|---|---|
| Unique Login Password | Required |
| Passkey | Very High |
| Google 2FA | Very High |
| Anti-Phishing Code | Very High |
| Fund Password | High |
| Secure Transaction Approval | High |
| Withdrawal Address Management | High |
| Daily Withdrawal Limit | High if assets are large |
| Minimize API Permissions | Required for API users |
Bybit itself also recommends Google 2FA, Fund Password, Passkey, Secure Transaction Approval, and Anti-Phishing Code as official means to strengthen Account Security.
39. Most recommended security combination
If you are actively using the exchange, at a minimum:
Passkey + Google 2FA + Anti-Phishing Code
This combination should be considered first.
If your asset size is large, you can add:
Secure Transaction Approval + Withdrawal Security + Fund Password
Adding these can create additional layers of defense.
While having many security features does not mean the possibility of asset loss becomes zero, it means that if one credential is exposed, additional layers of defense exist.
40. Common mistakes related to Bybit accounts
Mistake 1. Creating a new account immediately after missing the referral code
If it has been within 14 days of registration and there is no existing referral relationship, you should first check the Affiliate Code post-registration feature.
Mistake 2. Thinking general Referral Codes and Affiliate Codes are the same
Currently, the 14-day post-registration feature applies to Affiliate Codes.
Mistake 3. Thinking KYC Transfer is a referral code transfer
Referral/Affiliate relationships are not transferred along with KYC.
Mistake 4. Thinking you can receive Welcome Bonuses again by transferring KYC
Bybit specifies that you cannot repeatedly receive rewards for new user activities that you participated in on your previous account.
Mistake 5. Thinking that turning on only OTP is sufficient
In 2026, Bybit provides several additional layers of defense such as Passkey, Secure Transaction Approval, Anti-Phishing, and Withdrawal Security.
41. Bybit Referral FAQ
Q1. I missed the referral code when signing up for Bybit. Can I add it?
It is possible if you meet the conditions.
As of 2026, Bybit supports manually adding an Affiliate Invitation Code for Main Accounts that are within 14 days of registration and do not have an existing Affiliate/Referral relationship.
Q2. It has been more than 14 days since registration. Can I add it?
It is stated that the current official post-registration feature does not accept requests after 14 days.
Q3. Can I add a general friend Referral Code within 14 days?
The current official post-registration feature targets Affiliate Codes, and general Referral Program Codes are not supported.
Q4. I already have a referrer, can I change to a different code?
The current post-registration feature is only for accounts without a referrer.
Bybit also advises that an added Affiliate Code cannot be canceled or changed later.
Q5. Can I check which Affiliate is registered to my account?
Yes, you can.
You can check the Registered Affiliate Code in Account Info.
Q6. What is the CoinPop Bybit referral code?
COINPOP
is the code.
For new sign-ups:
You can check the actual applicable conditions at the link above.
Q7. What is the fee discount rate for the COINPOP code?
Actual Referral/Affiliate benefits may vary depending on campaigns, accounts, regions, and partner conditions.
Therefore, rather than concluding that a specific discount rate is permanently guaranteed for all users, you should check the sign-up screen and your actual Fee Rate.
42. Bybit Account·KYC FAQ
Q1. Can Bybit KYC be done on multiple accounts?
Bybit advises that Individual KYC should be processed on one account per user.
Q2. Can I transfer KYC to another Bybit account?
If you meet the conditions, you can use the Identity Transfer feature.
Q3. If I transfer KYC, are my assets transferred as well?
No.
Bybit explains that only Identity Information is transferred, and assets, email, mobile number, and Referral/Affiliate codes do not move with it.
Q4. My name was verified incorrectly, can I fix it?
Individual KYC accounts that meet the conditions can update their name and identity information through the Update Info feature in Identity Verification.
Q5. I lost my registered email.
Bybit provides recovery/change procedures related to Email, Mobile Number, or Google Authenticator through the self-service feature on the Verification screen.
43. Bybit Security FAQ
Q1. What security feature should I set up first on Bybit?
You can prioritize reviewing Passkey, Google 2FA, and Anti-Phishing Code.
The official Bybit security guide also advises using Google 2FA, Fund Password, Passkey, Secure Transaction Approval, and Anti-Phishing Code.
Q2. Can I register multiple Passkeys?
Bybit currently advises that you can register up to 10 Passkeys per account.
Q3. Can I restrict withdrawal addresses?
Yes, you can.
You can use the Withdrawal Address Whitelist and Withdraw via Address Book features.
Q4. Can I set the daily withdrawal limit myself for security?
Bybit provides a Daily Whitelist Withdrawal Limit feature and requires additional Security Verification for withdrawals exceeding the set limit.
Q5. Can I require mobile approval when withdrawing from a PC?
By enabling Secure Transaction Approval, you can set it to require approval for important transactions on your designated Primary Device.
Q6. Can I withdraw immediately after changing my Fund Password?
Withdrawals may be restricted for 24 hours after a Fund Password reset.
Q7. If I lose my Google Authenticator, do I lose my account?
No.
Bybit operates a self-service procedure for Google Authenticator Reset and changing Security Options.
44. Conclusion – Bybit account management in 2026 is different from past guides
The outdated information that should be corrected first when using Bybit in 2026 is:
“If you don’t enter a referral code when signing up, it’s gone forever.”
This explanation is no longer accurate.
Currently, Bybit provides an official feature to directly add an Affiliate Code within 14 days of registration for accounts that meet the conditions.
However, the conditions are clear.
- Main Account
- Within 14 days of registration
- No existing referral relationship
- Must be an Affiliate Code
- Cannot be changed after registration
And while KYC Identity Transfer exists, it is not a feature for transferring referral relationships or repeatedly receiving new member rewards.
Bybit specifies that Referral/Affiliate Codes do not move with Identity Transfer, and Welcome Activity Rewards participated in on the previous account cannot be received again on the new account.
In terms of account security, rather than ending with the past:
Password + Google OTP
It is a much stronger structure to combine the currently provided:
- Passkey
- Google 2FA
- Anti-Phishing Code
- Fund Password
- Secure Transaction Approval
- Withdrawal Whitelist
etc.
Especially for users who keep large assets on the exchange, preventing account compromise comes before trading strategy.
CoinPop × Bybit
Comprehensive exchange information for Bybit can be found at:
at the link above.
If you are creating a new Bybit account, the CoinPop partner path is:
Referral Code: COINPOP
is the link.
If you missed the referral code immediately after signing up, it is better to check if Account Info → Join an Affiliate’s Community is displayed before creating a new account.
As of 2026, if you meet the eligibility criteria, you can add an Affiliate Code within 14 days of registration.
Actual fee rebates, sign-up rewards, and promotions may vary depending on region, account, and timing, so you should check the conditions displayed on the screen as the final standard.
Based on official materials
This document has been reviewed based on official Help Center documents from Bybit as of August 2026 regarding Affiliate Code registration, Referral Program, Identity Transfer, Individual KYC, Passkey, Google 2FA, Anti-Phishing Code, Fund Password, Secure Transaction Approval, Withdrawal Security, and Account Self-Service.
Since Bybit’s account policies and Security Features may change, you should check the conditions displayed on the current Account screen and the official Help Center as the final standard when performing actual tasks.
Affiliate Notice: CoinPop may participate in the Bybit Affiliate program, and CoinPop may receive affiliate revenue if you use CoinPop’s sign-up path. Actual user benefits related to referral codes take precedence based on the conditions displayed on the Bybit screen.
Security Notice: There is no reason for CoinPop or any legitimate Affiliate to ask for a user’s Bybit password, Google Authenticator Code, Passkey, API Secret, or withdrawal Verification Code. Do not provide such authentication information to others.