A session keeps you signed in to Polyester on a browser or device. Security alerts help you spot important account changes and activity that may need your attention.
Your sessions
A signed-in session lets that browser use your account until you sign out or the session ends. Polyester can still ask for MFA before a sensitive action.
Signing out ends the session on the browser you are using.
API keys are separate from browser sessions. Signing out does not disable them.
Security alerts
An alert tells you that something important happened, such as a new API key, MFA change, whitelist update, order, or transfer. Open the related account page for the complete details behind the alert.
Device, IP address, and location descriptions can be approximate. Focus on the account, action, time, and related identifier when deciding whether the activity belongs to you.
For unfamiliar activity, check the matching area:
- API Keys for key creation, permission changes, and recent use.
- Security for MFA methods and recovery-code changes.
- Address Book for destinations and whitelist changes.
- Orders and Trades for trading activity.
- Transfers and Ledger for deposits, withdrawals, and internal movement.
If your account may be compromised
Secure your sign-in identity
Use your wallet, Google, or email provider's official recovery tools. Change or strengthen access there if the owner identity may be exposed.
Revoke exposed credentials
Disable unfamiliar API keys, remove unknown Subaccount members, and reduce permissions you did not approve.
Check security and balances
Review MFA methods, recovery codes, whitelists, open orders, balances, and pending transfers. Avoid sending funds to a destination you have not independently verified.
Save useful evidence and contact support
Keep event times, IDs, and screenshots that do not expose secrets. Send them through Support after immediate access risks are contained.
Recover access
- Recover a connected wallet through its wallet provider.
- Recover Google or email access through the appropriate provider.
- Use another enrolled MFA method or an unused recovery code when one factor is unavailable.
- Revoke and replace an API key if its private key is lost or exposed.
FAQ
If you suspect the wallet, Google account, or email you use to sign in has been compromised but you can still sign in to your original Polyester account, act quickly to protect your assets. From a trusted device, create a new Polyester account with a different, secure sign-in identity. Account creation is free. Move your available assets to the new account as soon as possible. If you cannot sign in or complete a transfer, contact support through the chat icon in your new account. The team can investigate, but recovery is not guaranteed.
Recovery options depend on your sign-in method. For Google or email, use your providerโs recovery steps to restore access. If you previously exported your Turnkey walletโs seed phrase or private key, you can import it into a supported wallet on a secure device and connect to the same Polyester account. For an external wallet, use its recovery phrase or private key to restore it on a secure device and connect again. If you cannot regain access to the wallet that owns your account, Polyester cannot replace it with another wallet. MFA methods and recovery codes do not restore wallet access or change ownership of your Polyester account. Learn about account creation.