Setup guide

Download the BitMEX app without installing somebody else's

Cloned trading apps are a mature industry. They rank in store search, they buy the same keywords, and they look identical right up to the moment they ask for something the real client never asks for. This guide covers the checks that take four minutes and the setup that makes a stolen password worthless.

Before you install anything

Decide first whether a derivatives client is the app you actually want. This matters more than any installation detail. If your plan is to buy Bitcoin monthly and hold it, a leveraged perpetuals venue adds risk, complexity and account restrictions with no upside for you. If your plan is to trade contracts actively, then yes — read on.

Second, understand what installing an exchange app means. You are not creating a wallet. You are creating an account at a company that will hold your coins for you. The app is a window into their ledger. That is the custodial model, and it is why the security work below focuses on your login rather than on a seed phrase. Our platform overview explains the distinction and when each model is appropriate.

Rule of thumb

Exchange app = account credentials to protect. Wallet app = seed phrase to protect. The defences are completely different, and confusing the two is how people lose money to "verify your wallet" phishing.

How a cloned client actually reaches you

The distribution routes are boringly consistent, which is good news — a short checklist covers nearly all of them.

  • Paid search results. A sponsored result above the real one, on a domain one character off. Type the address manually and this route disappears.
  • In-store keyword squatting. Searching an exchange name inside an app store surfaces dozens of unrelated "trading assistant" apps. Reach listings via links from the operator's own site instead.
  • Support impersonation. A helpful account in a Telegram or X thread sends you a "mirror download" because the official one is "under maintenance". It never is.
  • Sideloaded APKs. Blog posts promising an unrestricted regional build. These are malware more often than not, and the ones that are not malware still break the terms you agreed to.

The five-step install

  1. Start from the operator’s own domain, never from a search ad

    Type the official address into the address bar yourself and follow the store link published there. Fake trading apps buy search ads and app-store keywords; the URL bar is the one field an attacker cannot rewrite.

  2. Check the developer name, not the app icon

    Icons and screenshots are trivially copied. Open the listing’s developer profile and confirm the publisher entity matches the company named in the platform’s own legal documentation, then look at the release history — a genuine exchange client has years of updates, not three.

  3. Install, then refuse every optional permission

    A trading client needs network access and notifications. It does not need SMS, contacts, call logs, accessibility services or the ability to draw over other apps. Accessibility permission in particular is the standard tool for screen-reading malware.

  4. Set up two-factor authentication before your first deposit

    Use an authenticator app or a hardware key. Save the recovery codes offline. Do not use SMS: a SIM swap turns your phone number into somebody else’s second factor.

  5. Add a withdrawal address whitelist and test with a small amount

    Whitelist the wallet address you will actually withdraw to, then move a token amount out and back before committing real size. The test costs a network fee and buys certainty about the whole round trip.

Never

No exchange app, on any platform, will ever ask for a wallet seed phrase or private key during installation, login or verification. A prompt for twelve or twenty-four words inside an "exchange" app means the app is stealing, full stop. Close it and start the compromise checklist in the FAQ below.

Android and iOS are not the same risk

People treat the two stores as interchangeable. From a security standpoint they are not, and the difference changes what you should watch for.

Practical differences between installing a crypto exchange app on Android and iOS
Consideration Android iOS
Sideloading risk High — APKs install with two taps Low — requires enterprise profiles or a jailbreak
Clone listings in store search Common Common
Screen-reading malware Possible via accessibility permissions Effectively blocked by the sandbox
Hardware security key support NFC and USB-C keys widely supported NFC and Lightning/USB-C keys supported
Update discipline Depends on the vendor's OS support window Long support windows across older devices
Biometric app lock Available Available

Platform behaviour summarised from Apple and Google developer documentation. App availability and feature parity for a specific exchange client are published by the operator at bitmex.com.

Permissions worth refusing

Grant the minimum. A trading client works perfectly with network access and push notifications alone. Everything below is a request you should decline unless you can name the feature that needs it.

  • Accessibility services — lets an app read and control your screen. Almost never legitimate for a trading client.
  • SMS and call logs — historically requested to auto-fill codes; also everything a SIM-swap attacker wants.
  • Contacts — used for referral harvesting, not for trading.
  • Draw over other apps — the mechanism behind overlay phishing screens.
  • Unrestricted background location — a compliance app may check region once; it does not need continuous tracking.

Finishing the setup properly

Installation is the easy half. The half that determines whether you keep your money is what you do in the next fifteen minutes.

Lock the login

A unique password from a password manager, app-based or hardware two-factor authentication, and recovery codes stored offline. Then enable the biometric lock inside the app so a stolen, unlocked phone still cannot place orders.

Lock the exit

Turn on the withdrawal address whitelist and add the wallet you control. With a whitelist active, an attacker who fully owns your session still cannot send funds anywhere new without tripping a delay and an email you will see.

Prove the round trip

Deposit a small amount, trade nothing, and withdraw it to your own wallet. You will learn the real confirmation times, the real fee, and whether anything in your account triggers a manual review — while the stakes are trivial. Nobody regrets doing this. Plenty of people regret skipping it.

Keeping it trustworthy after install day

A verified install is a snapshot, not a permanent state. Three habits keep it that way.

Update deliberately, not automatically-and-blindly

Automatic updates are correct for security patches, and you should leave them on. But when a release changes something material — a new permission request, a redesigned withdrawal flow, a fresh login prompt after updating — read the release notes before carrying on. A legitimate app does not gain a need for accessibility access in a point release. If one appears to, that is the moment to check the developer profile again rather than tapping through.

Keep the device boring

The app can only be as trustworthy as the phone it runs on. That means a current OS version, a screen lock that is not a four-digit PIN you also use elsewhere, no sideloaded APKs from anywhere, and no "battery optimiser" or "screen recorder" utilities with sweeping permissions. Trading from a rooted or jailbroken device removes the sandbox that does most of the work of keeping your session private.

Re-check the exit path every few months

Whitelists drift. People add an address for a one-off transfer and forget it. Wallets get replaced and the old address stays approved. Open the withdrawal settings occasionally and prune anything you would not want a stranger sending your balance to — because in the scenario that matters, a stranger is exactly who is choosing from that list.

Next

Signing in for the first time, or stuck in a verification loop? The login and sign-up troubleshooting guide covers 2FA lockouts, region blocks and the errors people mistake for outages.

Fewer regional blocks

Buy, hold and withdraw without the derivatives paperwork

A licensed spot platform gets you from bank transfer to a wallet you control in a couple of steps, with app availability in far more regions and no funding rates to track.

Check availability in your region

External link, opens in a new tab.

Two smartphones displaying a crypto portfolio and a buy order screen

Frequently asked questions

Is the BitMEX app on the App Store and Google Play?

The operator publishes mobile clients for both platforms and links to them from its own website. Because store listings for financial apps are a favourite target for impersonation, always reach the listing through a link on the official site rather than through search results inside the store.

Why can’t I find the app in my country’s store?

Store availability follows the platform’s licensing map. If the listing is hidden in your region, that is a deliberate restriction, and installing a sideloaded APK to get around it puts you outside the terms of service — which is exactly the situation in which a withdrawal review gets escalated.

Is it safe to install an APK from a third-party site?

No. Sideloaded builds are the single most common delivery route for wallet-draining malware. If the official store listing is unavailable to you, the correct conclusion is that the service is not offered to you, not that you need a different download source.

Does the mobile app have all the features of the web platform?

The account and the matching engine are the same, so balances, positions and order types line up. Dense workflows — multi-chart layouts, ladder entry, API key management and bulk order editing — remain far more comfortable on desktop. Most experienced users treat the app as a risk-management tool rather than an execution tool.

What should I do if I already installed a fake app?

Uninstall it, then treat every credential typed into it as compromised. From a different, clean device: change the password, revoke all active sessions and API keys, regenerate two-factor authentication, and move funds to an address you control. If a seed phrase was ever entered, move those funds immediately — that wallet is no longer yours alone.