OKX Shield Terms and Conditions

Published on 9 Sept 2026

1. Programme Description

OKX Shield (the "Programme") is a voluntary, discretionary goodwill initiative offered by OKX to eligible users. It is not insurance, an investor compensation scheme, a deposit guarantee scheme, nor an unconditional undertaking to reimburse any loss.

Where a user's OKX Exchange account has been accessed or controlled by an unauthorised third party resulting in the theft and transfer of assets held within that account (an "Account Takeover" or "ATO"), OKX may, at its sole discretion, provide reimbursement to eligible users in accordance with these Terms, subject to the security status of the relevant account, the outcome of OKX's case review, and the applicable reimbursement limit.

The Programme is provided separately from, and in addition to, any existing regulatory obligations of OKX (if any). OKX will determine at its sole discretion whether to provide reimbursement, based on, inter alia, these Terms, platform records, materials submitted by the user, and the overall review outcome.

2. Scope

The Programme is currently available only to users who have been onboarded on the following platforms and who have completed identity verification:

  • OKX Europe Limited

  • OKX Europe Markets Limited

The Programme applies only to specified account-security incidents occurring within an eligible user's OKX Exchange account.

OKX Pay, the OKX Wallet, decentralised finance services, and any other external platforms or services are outside the scope of the Programme.

The Programme may not be available to all users or for all OKX platforms. Subject to applicable law, OKX may offer the Programme with different or supplemental terms (including in relation to eligibility, reimbursement limits, claims, and complaints handling processes) to different users or users of different OKX platforms.An incident may be considered for reimbursement only if all of the following conditions are satisfied:

  • an unauthorised third party accessed or controlled the user's OKX Exchange account;

  • that third party initiated an asset transfer without the user's authorisation;

  • the loss occurred within the user's OKX Exchange account;

  • a direct causal connection exists between the account takeover and the asset transfer;

  • the user satisfied the Programme's eligibility requirements at the time of the incident;

  • the user has not received any prior reimbursement under this Programme;

  • the user promptly notified OKX through the permitted channels set out in Section 7 following the incident and cooperated fully with the investigation; and

  • the incident or the right to reimbursement is not excluded under these Terms and does not involve the user's negligence, duplicate reimbursement, or abuse of the Programme.

3. Eligibility

The Programme does not activate automatically. A user must opt in and complete the initial activation process, even if every eligibility condition is otherwise satisfied. Eligibility, active Programme status, and the applicable reimbursement limit depend on, inter alia, the user's account status, security settings, device-security condition, user tier, and the OKX entity with which the user contracts.

To activate the Programme and to maintain activation status, a user must satisfy all of the following requirements:

(a) Account eligibility: identity verification must be complete and remain valid, and the account must not be restricted, suspended, or terminated at the time of the incident.

(b) Account and device security: the all devices used by the user to access OKX and every trusted or associated device linked to the user's OKX account must be updated to the latest OKX app version, and be free from malware, root access, jailbreaking, and any other conditions identified as insecure in the security assessment.

(c) Passkey: enabled.

(d) Facial verification for large withdrawals: enabled.

(e) P2P verification code preference: set to "Always".

(f) Web withdrawal function: disabled.

(g) The account must have no disqualifying high-risk record, abnormal behaviour, or platform-rule violation under the terms of service for the OKX platform on which the user is onboarded with.

(h) The user must have agreed to, and must continue to comply with, these Terms and the account-security obligations set out in Section 6.

(i) Any other condition reasonably determined by OKX for account-security, fraud-prevention, compliance, or applicable-law purposes.

(j) Eligibility and continuing eligibility are assessed using the account, device and security checks described in Section 13.

The Programme does not reimburse any loss that is attributable to risk or abnormal activity that occurred, existed, or was known to the user when the Programme was not activated.

4. Eligible Incidents

Subject to all applicable conditions of the Programme, the following categories of incident may be considered for reimbursement.

4.1 Unauthorised Third-Party Account Access

Where an unauthorised third party accesses or controls a user's OKX Exchange account and steals and transfers user assets held within the OKX platform, the said amount of assets transferred without user authority may be considered for reimbursement.

4.2 Account Takeover Caused by Phishing

Where a user discloses account credentials through a phishing website, phishing link, fake page, or similar means, and a third party uses those credentials to log in to the user's OKX Exchange account and initiate an unauthorised asset transfer, the resulting loss may be considered only if both of the following conditions are satisfied:

(a) Environment condition: the third party logged in from an abnormal device, network address, or location, or other case evidence establishes an abnormal login environment.

(b) Behaviour condition: the relevant login, address change, or asset transfer exhibits an identifiable and material deviation from the user's historical operating pattern, or other case evidence demonstrates a comparable material deviation.

A transfer initiated, authorised, or confirmed by the user personally, whether following inducement or deception, does not constitute an account takeover caused by phishing for the purposes of this Section 4.2.

4.3 Account Takeover Caused by Trojan, Malware, or Malicious Remote Control

Where, without the user's participation or knowledge, a Trojan, malware, malicious remote-control software, or a materially similar attack causes a third party to gain control of the user's OKX Exchange account and make an unauthorised asset transfer, the resulting loss may be considered for reimbursement.

OKX may reject or reduce reimbursement where the loss is directly or materially connected with the user's active installation or use of high-risk software, cracked software, plug-ins, remote-control tools, unofficial clients, or other unsafe conduct as referred to in Section 5.6.

Where the user personally performs a key authorisation action in connection with a transfer — including entering a verification code, providing biometric verification, completing a secondary confirmation, or signing — even while under remote control, screen sharing, inducement, or deception, Section 5.1 applies and the loss is not eligible for reimbursement under this Section 4.3. This Section 4.3 applies only where the user did not participate in the relevant authorisation and a third party actually controlled the account and completed the transfer.

4.4 Account Takeover Caused by SIM Swap

Where a third party obtains the user's SMS verification code through a SIM swap or a materially similar attack, uses it to access or control the user's OKX Exchange account without authorisation, and steals and transfers assets from the platform, the resulting loss may be considered for reimbursement.

OKX may require carrier confirmation, SIM replacement records, a police report, or other reasonably relevant evidence. Carrier confirmation should, where possible, state when and through which channel the SIM replacement was processed and whether the user appeared in person or whether another person acted on their behalf, together with any other verifiable processing information reasonably requested by OKX.

5. Exclusions

The Programme applies only to losses that clearly fall within Section 4 and that also satisfy every applicable requirement concerning eligibility, active Programme status, direct causation, evidence, filing/reporting deadlines, and these Terms. The fact that an event or loss is not expressly listed in Sections 5.1 to 5.8 does not mean that it is automatically eligible for reimbursement, and does not create any presumption of or entitlement to reimbursement. OKX may reject all or part of a claim if any applicable requirement is not met.

Sections 5.1 to 5.8 set out common, non-exhaustive categories of excluded loss. OKX may reject all or part of a claim where the nature, cause, or risk of an event or loss is similar to an identified exclusion, or where its principal cause involves a user-initiated act, the user's negligence, an external platform or wallet, investment or market risk, authorized third-party tools, insufficient evidence, duplicate reimbursement, fraud, or abuse of the Programme. OKX will communicate the principal reason for any rejection, and the user may appeal or raise a complaint in accordance with Section 12.2.

5.1 User-Initiated, Authorised, or Confirmed Transactions

The Programme does not cover any transfer, withdrawal, trade, address change, or API operation (including any transaction triggered by an automated standing instruction) that was initiated, entered, instructed, confirmed, approved, authorised, or signed by the user, even where the user acted as a result of fraud, impersonation, misleading information, coercion, or social engineering. Other dispositions of assets carried out by the user are similarly excluded, including where effected through another form of social engineering. For these cases, you may wish to contact your local law enforcement agency(s) and request that they reach out to OKX via enforcement@okx.com directly and as soon as possible, so that we can consider implementing any urgent action(s) requested by them as appropriate. Our Law Enforcement Team handles requests received directly from law enforcement agencies on a voluntary basis and in accordance with OKX’s internal policies. Kindly refer them to OKX’s Law Enforcement Request Guide.

Operations completed using the user's Passkey, biometric verification, trusted-device verification, or another equally reliable advanced security method are subject to Section 5.7.

By way of illustration (and without limitation), the following are excluded:

  • errors in instruction such as "fat finger" input, mistiming, mistyping, or misubmission of instructions or wallet addresses;

  • transfers voluntarily made following inducement by an investment scam;

  • transfers voluntarily made following impersonation of customer support, a relative, friend, romantic contact, or business partner;

  • transfers voluntarily made to a scammer's address;

  • transactions, withdrawals, signatures, or on-chain operations voluntarily authorised by the user; and

  • voluntary participation in a Ponzi scheme, pyramid scheme, fake project, or third-party investment scheme;

even if such voluntary participation was obtained though deception or misapprehension.

5.2 Investment, Trading, or Market Losses

The Programme does not cover:

  • losses caused by market movements;

  • investment or trading losses;

  • opportunity costs or loss of expected returns;

  • indirect or incidental losses; or

  • losses arising from participation in third-party projects, Ponzi schemes, pyramid schemes, or investment scams.

5.3 Losses Involving External Wallets, Platforms, or Transfers

The Programme does not cover losses occurring outside the OKX Exchange platform, including:

  • loss of assets in an external wallet;

  • loss in an external-platform account, including defi wallets;

  • loss following an independent on-chain transfer made by the user;

  • loss caused by an incorrectly entered or copied withdrawal address, or an address tampered with or substituted in an external environment; and

  • loss following the user's confirmation of a transfer in an external environment affected by clipboard hijacking or address substitution.

A loss occurring in OKX Pay, an OKX Wallet, a self-custody wallet, an external platform, or any other account outside the Programme does not become eligible for reimbursement merely because it is subsequently reflected in the user's OKX Exchange account through an internal transfer, deposit, API display, or otherwise.

Where a loss involves an incorrect, tampered-with, or substituted withdrawal address, OKX will assess the incident by identifying who actually initiated the address change or withdrawal instruction and who completed the key authorisation actions.

Where the user added or confirmed the address during the user's own session or on the user's own device, and personally completed a verification code, biometric verification, secondary confirmation, signature, or equivalent key authorisation step, the loss is excluded. Withdrawals to a trusted, allowlisted, or verification-exempt address that is assessed by OKX to have been added with the user's authorisation will be regarded as an authorised asset transfer under the Programme.

Where an unauthorised third party used the user's OKX Exchange account to change the address or initiate the withdrawal in an abnormal session or environment, without the user's participation in any key authorisation step, OKX may review the incident under Sections 4.1 to 4.4 or another applicable provision of Section 4. OKX may have regard to session identifiers, device information, network addresses, operation timestamps, authentication records, and other sources of evidence when conducting this assessment.

5.4 Losses Caused by API Key or Third-Party Tool Authorisation

The Programme does not cover losses caused by the disclosure or misuse of an API key or the authorisation of a third-party tool, including:

  • API key disclosure;

  • third-party tool authorisation;

  • calls made by an external programme;

  • high-risk API permissions actively configured by the user; and

  • compromise of a quantitative-trading platform, cloud storage service, code repository, or other third-party service.

5.5 Fraudulent Use of Bank Cards, Credit Cards, or Third-Party Payment Instruments

Losses caused by the fraudulent use of a bank card, credit card, bank account, or third-party payment instrument are generally outside the scope of the Programme. Users should contact the relevant card issuer, bank, card scheme, or payment service provider directly.

Where the same incident also involves unauthorised access to or control of the user's OKX Exchange account, and the compromised payment instrument belongs to that user, OKX may conduct a case-specific review using account, payment, and transaction records.

Where the compromised payment instrument does not belong to the OKX Exchange account user, and there is reasonable evidence that the OKX Exchange account user used the instrument without the holder's authorisation, the resulting loss is excluded and may be referred to OKX's payment-risk management, anti-money laundering, or compliance processes. Such a referral does not constitute acceptance, review, or any undertaking of reimbursement under the Programme, and does not preclude OKX from separately reviewing any direct loss of assets within the user's OKX Exchange account that arises from an independently established unauthorised third-party takeover.

Any amount actually recovered (in any form, and regardless of whether paid into the user's OKX accounts or otherwise) for the same loss from a bank, card scheme, payment institution, insurer, or any other channel will be deducted from any amount otherwise eligible for reimbursement under the Programme. OKX does not provide duplicate reimbursement.

5.6 User Negligence or Breach of Account-Security Obligations

OKX may reject or reduce reimbursement where a loss is directly or materially connected with the user's negligence, breach of account-security obligations, usage of vulnerable systems or device, or failure to satisfy the Programme's continuing eligibility conditions. Where the platform security system reasonably identifies, at the time of the incident, that the current device or any trusted or associated device is rooted, jailbroken, system-tampered, contains security vulnerabilities or inherent defects (whether or not caused by the user) or otherwise high-risk, OKX Shield will be treated as inactive and the loss will not be reimbursed. The user may submit objective evidence through the appeals process to demonstrate that the detection was erroneous or that all eligibility conditions remained satisfied.

By way of illustration (and without limitation):

  • voluntarily sharing an account, password, verification code, two-factor authentication credentials, Passkey, private key, or device;

  • voluntarily authorising another person to operate the account;

  • renting, lending, transferring, buying, or selling an account;

  • renting, lending, buying, or selling identity-verification materials;

  • voluntarily installing high-risk remote-control, cracked, plug-in, or unofficial software;

  • rooting, jailbreaking, or using a tampered system environment on the current device or any trusted or associated device, or logging in, authenticating, or operating an OKX Exchange account from such an environment;

  • using of devices, software, or systems that contain known security vulnerabilities;

  • using an unofficial client, tampered application, or high-risk runtime environment;

  • continuing to operate the account with knowledge of an existing account-security risk;

  • failing to promptly notify OKX following a lost or stolen device, or following the discovery of an account anomaly, thereby causing the loss to increase; and

  • failing to provide reasonably requested evidence or to cooperate with OKX's investigation.

5.7 Operations Completed Through Advanced Security Verification

Where an operation has been completed through a Passkey, strong biometric verification, trusted-device verification, or another equally reliable advanced security method, OKX will generally treat that operation, and any direct or indirect loss resulting from it, as having been authorised or confirmed by the user. Such operations and resulting losses are accordingly excluded in principle.

A user may submit objective and verifiable evidence demonstrating that the relevant authentication was bypassed, forged, completed under coercion, or not in fact performed by the user. OKX will review its platform records together with the user's evidence. Where the evidence is sufficient to rebut the authorisation inference, the incident may nonetheless be reviewed as an account-takeover case.

A determination under this Section 5.7 is made solely for the purpose of assessing eligibility under the Programme and does not constitute any admission by OKX of fault, legal liability, or any obligation to reimburse. The exercise of any appeal right, complaint right, or external remedy does not itself create eligibility, and does not affect the applicable standard of evidence, the review process, or OKX's right, to the extent permitted by applicable law, to restrict an account, suspend a payout, set off amounts, recover amounts paid, or apply other risk-control measures. Any right of the user that applicable law does not permit to be contractually excluded or limited remains unaffected.

A user alleging that advanced security verification was bypassed, forged, or not completed by that user must provide objective and verifiable technical evidence independent of the user's own statement — for example, a device-forensics conclusion, an authentication-log anomaly, a reproducible bypass path, or other reliable technical evidence. The user's unsupported assertion, suspicion, or speculation is not sufficient. A claim that an OKX authentication mechanism was bypassed is also subject to the technical verification threshold and security-incident process set out in Section 4.5, and requires a written conclusion from the OKX Security Team.

A claim is excluded where the user makes a false statement or material omission; forges, alters, deletes, conceals, or destroys evidence; manipulates a device, account, or security status before or after submitting a claim in order to evade detection; colludes with a recipient, related party, or third party; transfers assets to an address or account actually controlled, jointly controlled, or beneficially connected with the user; carries out circular transfers or fabricates a loss; or submits a duplicate claim in respect of the same loss to OKX, another OKX entity, a bank, an insurer, or any third party. Any other abuse of the Programme is similarly excluded.

To identify organised fraud and links across cases, OKX may, to the extent permitted by applicable law, cross-reference a claim with other claims, records of OKX group entities, and reliable third-party information. This may include common or related identity details, devices, network addresses, contact information, payment instruments, addresses, recipients, fund flows, and behaviour patterns. OKX may verify relevant information with document issuers, financial institutions, trading platforms, service providers, or competent authorities. Personal data will be processed or shared only in accordance with the Privacy Notice, applicable data-protection law, and the principle of necessity.

Where false information or evidence tampering concerns a core fact of the claim, OKX may reject the claim in its entirety. OKX may also suspend review and payout during an investigation and may, as appropriate: reject all or part of a claim; cancel eligibility; freeze or restrict relevant accounts; set off or recover amounts already paid; recover reasonable investigation and recovery costs to the extent permitted by applicable law; report the matter to relevant authorities; or take legal action.

5.9 OKX System or Security-Control Issues

Where a defect in an OKX platform system, security verification mechanism, risk-prevention control, strong authentication process, or multi-factor authentication mechanism causes an unauthorised third party to gain access to a user's account and transfer assets, OKX will handle the incident in accordance with its platform rules and the outcome of the relevant investigation.

Such an incident requires written confirmation from the OKX Security Team of a reproducible technical defect, or objective and verifiable technical evidence — independent of the user's own statement — establishing that the relevant authentication was bypassed. Incidents falling within this Section 5.9 will be handled through OKX's security-incident response process and will not be subject to the Programme's standard case-review procedures or per-case reimbursement limits.

6. User Security Obligations

To become and remain eligible for the Programme, the user must comply with the following account-security obligations and continuously satisfy any other security-setting requirement expressly displayed by OKX on the product page or account page:

  • securely safeguarding the account, passwords, verification codes, two-factor authentication credentials, Passkey, private keys, and devices;

  • not sharing account credentials, security-authentication information, or devices with any third party;

  • using only official OKX applications, websites, and clients;

  • not renting, lending, transferring, buying, or selling an account;

  • not renting, lending, buying, or selling identity-verification materials;

  • not voluntarily installing high-risk remote-control, cracked, plug-in, or unofficial software;

  • not rooting or jailbreaking any device, or using a tampered system environment;

  • continuously keeping Passkey and Large Withdrawal Protection enabled, keeping the P2P verification code preference set to "Always", keeping the Web withdrawal function disabled, and maintaining the security of the account and every associated device;

  • promptly notifying OKX upon discovering an account anomaly, a lost or stolen device, a SIM swap, or any unauthorised operation; and

  • promptly preserving and providing an incident description, complete timeline, device and account information, communications, transaction or on-chain records, police-report materials, and any other reasonably relevant evidence.

Prior to the completion of OKX's investigation, the user must not intentionally reset a device, uninstall a relevant application, delete logs or communications, transfer relevant assets, or otherwise destroy evidence. The user must cooperate with any device-security inspection or forensic review to the extent necessary, relevant, and consistent with applicable privacy and data-protection law. OKX may reject a claim where the user, without reasonable cause, refuses to cooperate or destroys evidence and thereby materially obstructs the investigation.

7. Claim Process

Upon discovering a suspected account takeover or unauthorised asset transfer, the user must notify OKX and submit a formal claim through one of the following channels within 72 hours of the last unauthorised transaction:

  1. The OKX customer service support accessed through the OKX App/Web Help Centre; or

  2. Online customer service chat.

The user will be guided to follow the prompts to freeze the account, update security settings, and submit the formal claim. The user will further be required to provide supporting information within 7 days of the formal claim. Claims submitted outside either period will generally not be accepted.

Where hospitalisation, detention, or another objective and reasonably unavoidable circumstance prevented timely submission of the formal claim or the supporting information, and the user provides reasonable supporting evidence of that circumstance, OKX may, having regard to the facts, determine whether to continue processing the claim.

In the formal claim submission stage, OKX may require the user to complete a structured incident questionnaire addressing each suspicious transaction, the incident timeline, use of remote-control or screen-sharing software, disclosure of verification or authentication information, SIM replacement records, use of destination addresses, and any other reasonably relevant matter. The user may also be required to sign a declaration confirming the truthfulness and completeness of all submitted materials and acknowledging the consequences of a false statement.

In accordance with OKX's investigation policies and the terms of service of the OKX platform on which the user is onboarded with, upon claim submission, OKX will temporarily restrict asset withdrawals, transfers, and security changes on your account and may freeze the reimbursement limit associated with the claim to prevent further loss during investigation. The user must complete any required account and security remediation. Restrictions will be lifted or adjusted once the necessary investigation is complete and account-security risks have been resolved, and OKX will update or notify the user of any change in status.

Where the user fails, without reasonable cause, to provide required materials by the relevant deadline, refuses to cooperate, refuses a necessary and relevant device-security inspection or forensic review (consistent with applicable privacy and data-protection law), or otherwise materially obstructs the investigation, OKX may treat the claim as abandoned and terminate the review.

OKX may require the following evidence, among other things:

  • a description of the incident;

  • an account-anomaly timeline;

  • evidence relating to a lost or stolen device or account anomaly;

  • a police report or case reference number;

  • telecommunications-carrier evidence relating to a SIM swap;

  • records showing remote locking of the device or suspension of the SIM;

  • screenshots, emails, or text messages relating to the incident; and

  • any other evidence reasonably requested by OKX.

Where the claim amount meets or exceeds the official-evidence threshold displayed on the product page or within the claims process, the user must, in principle, provide a police report, case reference number, or equivalent official evidence issued by the local police, a regulator, or another competent authority within 7 days of the first formal claim submission. OKX may verify the authenticity and status of such documentation directly or through a third-party service provider, and may reject or suspend the claim where the user does not, without reasonable cause, provide the required official evidence or where the documentation cannot reasonably be verified.

OKX will conduct an overall assessment using platform system records; account and device logs; device-identification information; login and authentication records; network-address and geographic information; security and risk-monitoring records; transaction and fund-flow records; on-chain data; communications between the user and OKX; materials submitted by the user, including any police or official reports of the incident; and any other reliable information available.

Unless a manifest error is established or sufficient contrary evidence is provided, records generated and retained by OKX in the ordinary course of platform operations will constitute primary evidence of account status, authentication methods, operation timestamps, device environment, and transaction activity. The user is responsible for providing sufficient, reliable, and internally consistent material demonstrating that OKX Shield was active at the time of the incident; that the loss was directly caused by unauthorised third-party control; that the claimed amount is accurate; and that no exclusion applies. OKX will assess all evidence reasonably available at the time and may reject all or part of a claim where material evidence is missing, contradictory, not reasonably verifiable, or collectively insufficient. Nothing in this Section 7 varies any burden of proof or mandatory user right imposed by applicable law.

Where the evidence reasonably available at the time does not reasonably exclude the user's authorisation, participation, knowledge, actual control of a recipient address or account, collusion with a third party, or other direct or indirect involvement, the claim will not be eligible for reimbursement. The user may submit objective and verifiable contrary evidence and may appeal in accordance with Section 12.2.

When a user submits a claim, OKX processes the personal data described in this Section 7 and in Section 13 to assess the claim, verify the information provided, prevent fraud and duplicate reimbursement, and meet applicable legal and regulatory obligations. Further information is set out in Section 13 and in the applicable Privacy Notice.

8. Review, Evidence, and Decision

OKX will assess every claim against the eligibility, eligible-incident, causation, evidence, and exclusion requirements set out in these Terms. Classification of an incident as a suspected or confirmed unauthorised account access does not, by itself, establish eligibility; every applicable condition must still be satisfied.

In reviewing a claim, OKX will consider, among other things:

  • whether an unauthorised third party accessed or controlled the account;

  • whether the loss occurred within the OKX Exchange account;

  • whether the asset transfer was initiated, authorised, or confirmed by the user;

  • whether a direct causal link exists between the account takeover and the loss;

  • whether the account satisfied the applicable eligibility requirements;

  • whether the user complied with their account-security obligations;

  • whether the user promptly notified OKX and cooperated fully with the investigation;

  • whether the destination of funds involves the user, an address or account actually controlled by the user, a related party, shared devices, network addresses, identity data, or payment instruments, or involves circular transfers, rapid return flows, layering, aggregation, or another abnormal link;

  • whether the user has already received reimbursement or recovered amounts from a bank, card scheme, payment institution, insurer, law-enforcement authority, or any other channel;

  • whether there is evidence of gross negligence, a false or duplicate claim, a material omission, evidence tampering or destruction, a related-party transfer, collusive fraud, manipulation of device or account status, or any other form of Programme abuse; and

  • any other factor OKX considers relevant to the case.

Based on the outcome of its review, OKX may determine in its sole discretion whether to reimburse, the amount of any reimbursement, whether supplemental materials are required, whether reimbursement should be reduced, or whether the claim should be rejected. Review timing varies by case. OKX generally seeks (but does not guarantee) to provide a conclusion to its assessment (or if further time is required, an update on any estimated timelines required) within 15 business days of an incident being notified to OKX, subject the user providing all requested cooperation and information in a timely manner.

Where a user's claim for reimbursement is approved, OKX will pay any eligible reimbursement to the user's verified OKX Exchange account within a reasonably practicable period, and will state the expected payout time in the decision notice.

Rejection of a claim for failure to satisfy scope, eligibility, causation, or evidence requirements does not, by itself, constitute a false claim or Programme abuse. Unless reliable evidence establishes a false statement, material omission, forged or destroyed evidence, collusion, or another form of abuse, rejection alone will generally not affect the user's future eligibility for the Programme.

9. Reimbursement Limits, Payout, and Valuation

The maximum reimbursement limit is determined by user tier, account-security settings, and the applicable OKX entity. The specific limit applicable to a user is the valid limit displayed on the OKX Shield product page at the time the relevant incident occurs. Any change to the applicable limit takes effect prospectively only and does not alter the limit applicable to an incident that occurred before the change took effect.

A displayed reimbursement limit is not an unconditional undertaking to reimburse every loss up to that amount. The actual reimbursement amount depends on the outcome of OKX's review, the applicable limit, the degree of user responsibility, amounts already recovered from other sources, and any other factor reasonably relevant to the claim.

For an approved crypto asset loss, value is determined as at the time the last unauthorised asset transfer connected with the same security incident was completed. OKX will use the OKX index price for the relevant asset; where no index price is available, the average platform execution price at the relevant time; and, where liquidity is insufficient, a reasonably realisable value. Amounts already recovered from any other source are deducted before the applicable maximum limit is applied. Subsequent market movements, opportunity costs, and expected returns are excluded from any reimbursement calculation, as are amounts recovered from any other channel following payout by OKX. Where the loss involves fiat currency, the value of the loss is determined at face value in the relevant fiat currency as at the time of the unauthorised transfer.

Reimbursement is denominated and paid in a Euro-denominated stablecoin, such as EURC, as determined by OKX in its discretion based on availability and platform limitations at the time to the user's verified OKX Exchange account, and may not match the full quantum or the currency of the actual loss suffered. OKX will, where reasonably practicable, notify the user of delays caused by applicable law, sanctions or anti-money-laundering review, technical or network conditions, or any other reasonable operational cause.

Eligibility, active Programme status, and the applicable limit are determined by reference to platform records and account-security status at the time of the incident. Where any continuing eligibility condition is not satisfied, or where the account is reasonably tagged as high-risk by the platform security system, the Programme will be automatically suspended and incidents occurring during that suspension will be excluded. Once the relevant risk tag is removed and all conditions are restored, the Programme may become effective again in accordance with these Terms and the status displayed by the platform. OKX will notify the user of any change in Programme status or applicable limit through the account page, in-app notification, email, or another reasonable channel, and will enable the user to view the current status, applicable limit, and available appeal channels.

The maximum and aggregate reimbursement is calculated per natural person (per KYC identity), and not separately per account. Multiple accounts held or actually controlled by the same individual do not attract separate limits. Each natural person (KYC identity) may receive reimbursement in respect of no more than one approved claim during that person's lifetime across all OKX entities. Payments made in instalments under a single approved claim are collectively treated as one reimbursement event. Once a user receives reimbursement under the Programme, even if not to the full limit, that user is no longer eligible for reimbursement in respect of any subsequent incident.

10. Prevention of Duplicate Reimbursement

The user must truthfully disclose to OKX whether reimbursement has been or may be received from any of the following sources:

  • a bank;

  • a card scheme;

  • a payment institution;

  • an insurer;

  • law-enforcement recovery;

  • a third-party platform; or

  • any other source.

OKX will not reimburse any portion of a loss that has already been recovered through another channel. Where the user receives reimbursement from another source after receiving reimbursement from OKX, OKX may require the user to return the duplicate portion.

To the extent permitted by applicable law, and after giving any required notice or obtaining any required authorisation, the user must reasonably cooperate with OKX in verifying any reimbursement received or potentially receivable from a bank, card scheme, payment institution, insurer, law-enforcement authority, third-party platform, or other relevant institution. OKX may also conduct necessary verification where another lawful basis for processing exists.

To the extent permitted by applicable law, by accepting reimbursement under the Programme, the user assigns to OKX, or authorises OKX to exercise, any rights of recovery against the relevant scammer, recipient, or other responsible third party arising from the incident, up to the amount actually reimbursed by OKX. OKX may pursue such recovery in the user's name or its own name, and the user must provide reasonable assistance and must not take any action that would prejudice those recovery rights. OKX does not guarantee that any recovery action will be successful or that any amount will be recovered.

Following acceptance of reimbursement from OKX, the user may not seek damages, reimbursement, or any other monetary remedy from OKX in respect of the same loss, up to the amount actually reimbursed by OKX. This does not constitute a waiver in respect of any uncompensated portion of the loss and does not exclude or limit any right or remedy that cannot be waived or limited under applicable law.

11. Suspension, Cancellation, or Adjustment of Eligibility

Where any eligibility condition ceases to be satisfied, OKX Shield will immediately and automatically be suspended and displayed as "Inactive". The Programme may resume only after the user remedies the relevant failed condition and the platform verifies that all continuing eligibility conditions remain satisfied. Whether resumption is automatic or requires further user action will be determined by the platform status and instructions displayed at that time.

In addition to automatic suspension, OKX may, in its sole discretion, cancel or adjust a user's eligibility where the user:

  • breaches the OKX User Agreement, platform rules, or these Terms;

  • engages in high-risk account behaviour;

  • presents a risk of false claims, Programme abuse, or reimbursement fraud;

  • has not completed the required security settings;

  • refuses to cooperate with an investigation or to provide required materials; or

  • falls within any other circumstance in which OKX reasonably considers suspension, cancellation, or adjustment necessary for account security, compliance, fraud prevention, or applicable-law purposes.

A user who wishes to appeal any suspension, cancellation, or adjustment of eligibility may reach out to OKX via the appeal route set out in Section 12.2(a). Pending the conclusion of any appeal, OKX reserves the right to continue to apply such suspension, cancellation, or adjustment.

12. Programme Changes, Appeals, and General Terms

12.1 Programme Changes and General Terms

These Terms supplement and form part of the terms of service, user agreement, Privacy Notice and other platform rules applicable to the OKX entity serving the user (collectively, the "Platform Terms"). Except for provisions expressly specific to OKX Shield, the Platform Terms continue to apply in full. Where there is a conflict concerning the Programme, these Terms prevail to the extent permitted by applicable law; all other matters remain governed by the Platform Terms. Governing law, dispute resolution, notices, and applicable jurisdiction are as set out in the relevant Platform Terms.

Where OKX identifies a coordinated or organised attack, a surge in abnormal or fraudulent claims, a systemic account-security event, a significant fraud pattern, or any risk to the fairness, security, or normal operation of the Programme, or where required to do so by a regulatory or law-enforcement authority, OKX may, to the extent reasonably necessary and permitted by applicable law: temporarily suspend new activations, claims acceptance, case reviews, or payouts; apply enhanced verification procedures; and prospectively adjust eligibility criteria, limits, or processes in respect of events not yet occurring. OKX will, where reasonably practicable, notify affected users and explain the expected handling arrangements, including the effective date of any new changes. Such measures will not exclude mandatory user rights under applicable law and will not unreasonably deprive users of valid claims established before the relevant measures took effect.

If any provision of these Terms is found to be invalid or unenforceable, the remainder of the Terms will continue in full force and effect. A failure or delay by OKX in exercising any right under these Terms will not constitute a waiver of that right. These Terms apply only to the extent permitted by applicable law; any mandatory rule that cannot lawfully be excluded or limited will prevail.

In the event of any inconsistency or conflict between the English versions of these Terms and any translated versions, the English version will prevail. Unless expressly stated otherwise in these Terms, no person other than the user and the applicable OKX entity has any right to enforce any provision of these Terms.

12.2 Appeals and Complaints

(a) Suspension of eligibility. Where a user's OKX Shield eligibility has been suspended, cancelled, or adjusted under Section 11, the user may submit a formal appeal to appeal such action through the formal complaint submission process for the relevant OKX platform applicable to them.

(b) Rejection of claims. Where a claim is rejected in whole or in part, OKX will provide a written decision stating the principal reasons for the rejection, and the available appeal routes and deadlines. OKX is not required to disclose internal decision thresholds, signal weightings, model logic, or other information the disclosure of which may impair account security, fraud prevention, or the effectiveness of the review process. Within 15 business days of receiving the decision, the user may submit an appeal or complaint through the formal complaint submission process for the relevant OKX platform applicable to them and provide the relevant case number, the grounds for the appeal, and any supplemental evidence.

(c) In each case above, subject to any shorter timelines required by applicable law, OKX generally seeks (but does not guarantee) to acknowledge receipt of a complaint or appeal within 5 business days and provide a further update in the form of a written update or a conclusion within 15 business days of acknowledgement. Any decisions made through the appeal process shall be deemed as final, but for the avoidance of doubt does not affect the user's right under applicable law to seek relief from a competent regulator, dispute-resolution body, or court.

13. Personal Data and Privacy

13.1 Relationship with the privacy notice

OKX processes personal data in connection with the Programme as a controller. This Section 13 describes processing specific to the Programme and supplements, and does not replace, the Privacy Notice of the OKX entity with which the user contracts.

13.2 Activation and ongoing eligibility checks

To activate the Programme and to determine whether it remains active, OKX carries out account, device and security checks. These checks may examine the security configuration and integrity status of devices used to access the user's OKX Exchange account, including indicators of malware, root access, jailbreaking, system tampering and known vulnerabilities. The results determine activation, suspension, restoration and claim eligibility, and may result in the Programme being shown as Inactive. Further information about these checks, the data involved and how often they are carried out is set out in the applicable privacy notice and in the information presented at activation.

13.3 Claim assessment

Where a user submits a claim, OKX processes the information described in Sections 7 and 8, including account and device records, authentication and session records, network address and location information, transaction and on-chain records, materials submitted by the user and, where relevant, official documentation issued by a competent authority. OKX may verify submitted documentation with the issuing body or through a service provider engaged for that purpose.

13.4 Fraud prevention and cross-referencing

To detect organised fraud and connections between cases, OKX may cross-reference claim information with other claims and with information held by other OKX group entities and by third-party sources, as described in Section 5.8. OKX carries out this processing on the basis of its legitimate interest in preventing fraud and protecting the Programme and its users.

13.5 Device inspection

Where OKX requests a device-security inspection or forensic review under Section 6, the inspection will be limited to what is necessary and relevant to the claim.

13.6 Retention

Personal data processed in connection with the Programme is retained for no longer than is necessary for the purposes described in this Section 13, and in accordance with the applicable privacy notice. Where OKX is required by law to retain records for a longer period, that period applies.

13.7 Automated processing

Some Programme decisions, including the automatic suspension of Programme status under Section 11, are made using automated processing. A user affected by such a decision may request human review, express their point of view and contest the decision through the process in Section 12.2.

13.8 Transfers

Where personal data processed in connection with the Programme is transferred outside the European Economic Area, OKX applies a transfer mechanism recognised under applicable data-protection law.

13.9 Rights

The user's rights in relation to their personal data, and how to exercise them, are set out in the applicable privacy notice. Exercising those rights does not affect the appeal and complaint process in Section 12.2.