Account security · Verified June 2026

Lock down your Shuffle account: 2FA, anti-phishing codes, withdrawal whitelist.

Shuffle offers three independent security layers on top of a standard password: TOTP-based two-factor authentication, an anti-phishing code on every outbound email, and a withdrawal address whitelist that stops funds leaving to any address you haven't pre-approved. All three together take about five minutes to set up and meaningfully cut the risk of account takeover or phishing.

Claim MAXBET at Shuffle →

18+ · $20 min deposit · 35x on deposit + bonus · $10 max bet while clearing · Last verified June 2026

2FA type

TOTP (Google Authenticator etc.)

Anti-phishing

Custom code on all emails

Withdrawal whitelist

Yes, address pre-approval

KYC at signup

Not required

KYC triggered at

$5,000 / 30-day withdrawals

Support

24/7 live chat

Two-factor authentication (2FA)

Once enabled, you'll enter a 2FA code at login and again when confirming withdrawals. The code prompt appears after the standard username and password step.

  1. Go to Account Settings. Select Security.
  2. Under Two-Factor Authentication, click Enable.
  3. Open Google Authenticator, Authy, or your TOTP app of choice. Tap the + icon to add a new account.
  4. Scan the QR code shown on Shuffle's screen, or enter the manual key if your app doesn't support scanning.
  5. Enter the six-digit code generated by your app to confirm setup.
  6. Save your backup codes somewhere offline. These let you recover access if you lose your phone.

Anti-phishing code

Phishing attacks typically involve fake emails that look identical to official casino communications but link to malicious sites. Shuffle counters this with a custom anti-phishing code: you set a short word or phrase in your security settings, and every legitimate Shuffle email will display this code at the top.

If you receive an email claiming to be from Shuffle and it doesn't show your anti-phishing code, it's fake. Delete it and don't click any links.

To set it up: Account Settings, Security, Anti-Phishing Code. Choose something memorable but not guessable. The code starts appearing on all Shuffle emails within minutes of saving.

Sign-up takes about ninety seconds. Code MAXBET goes in the referral field.

Claim MAXBET at Shuffle →

Withdrawal address whitelist

The withdrawal whitelist means you pre-approve specific wallet addresses in your account settings. Once enabled, Shuffle will only process withdrawals to those addresses. A request to any other address will be blocked, even if the attacker has your login credentials and 2FA code.

For most players, this means adding the one or two wallets you regularly use. Addresses can be managed in Account Settings under Security. Adding a new address triggers a confirmation email to your registered address and a time-delay before it becomes active (Shuffle uses this delay to give you a window to cancel if the addition was unauthorised).

The whitelist is the strongest of the three security tools because it limits the damage of a full account compromise. Even with everything else, funds can only go to your pre-approved address.

Password and email security hygiene

The three Shuffle-native security tools work best alongside good general hygiene: a unique password used only at Shuffle (a password manager makes this easy), a dedicated email address for the account, and avoiding logging in on shared or public devices.

Shuffle's official domain is shuffle.com. The support email is accessible via live chat, and the deposit address shown in the cashier changes with each new deposit request as is standard for crypto wallets. If you ever receive an email asking you to send crypto directly or to log in via a link that doesn't resolve to shuffle.com, treat it as a phishing attempt.

After the October 2025 data breach: context

In October 2025, Shuffle's third-party CRM provider Fast Track was compromised, exposing personal data including names, emails, addresses, phone numbers, and transaction histories for the majority of Shuffle users at the time. Passwords, login credentials, and player funds were not compromised in the breach.

The practical takeaway for current players: if you registered before late 2025, your personal details may be in the wild. The risk vector is targeted phishing using that data. The anti-phishing email code and 2FA combination significantly reduces that risk. Shuffle recommended enabling 2FA immediately after the breach was disclosed. If you haven't done it yet, do it now.

Sign-up takes about ninety seconds. Code MAXBET goes in the referral field.

Claim MAXBET at Shuffle →

Questions readers actually ask

Does Shuffle require 2FA?
2FA is optional but strongly recommended. It's not mandatory at signup; you enable it in account security settings at any time.
What TOTP apps work with Shuffle?
Any standard TOTP app: Google Authenticator, Authy, Microsoft Authenticator, 1Password, Bitwarden. All use the same TOTP standard.
What is the anti-phishing code?
A word or phrase you set in Shuffle's security settings. Every legitimate Shuffle email will show this code. Emails without it are phishing attempts.
Can I whitelist more than one withdrawal address?
Yes. You can add multiple addresses across different coins and networks. Each new address has a confirmation step and time-delay before activation.
What happens if I lose my 2FA device?
Use your saved backup codes to recover access. If those are also lost, contact Shuffle support through live chat for account recovery assistance, which involves identity verification.
Was the October 2025 data breach serious?
Personal data was exposed but passwords, login credentials, and funds were not compromised. Players who registered before late 2025 should enable 2FA and set an anti-phishing code as a precaution.