Protect your access
Use a unique password or passphrase and keep your recovery information secure. If your account offers multifactor authentication or a passkey, review how to enable it and recover access if your device is lost. Keep your browser and device software current. Never send passwords, verification codes, private keys, or recovery phrases to another person, including someone claiming to represent a platform.
Know the service behind the account
Before providing identity documents or funding an account, confirm the operator named in your account agreement and the service you are using. Review how authentication, account recovery, session controls, and sensitive account changes work. A polished interface does not establish regulatory status or asset protection. Look for specific, current explanations that apply to your account, and request clarification where a material detail is missing.
Separate account safety from investment risk
Access controls help address unauthorized use, but they do not protect an investment from market losses. Custody, ownership, segregation, insurance, and compensation arrangements are separate questions governed by the relevant provider and product documents. Check who holds any money or assets, what rights you have, and what happens if a provider fails. Do not infer these protections from an asset name or security-themed illustration.
Respond carefully to suspicious activity
If you notice an unfamiliar sign-in, account change, or transaction, use a trusted route to your account and follow the provider’s published recovery or reporting process. Avoid links and contact details supplied in the suspicious message itself. Preserve relevant dates, messages, and transaction references. Do not grant remote access to your device or transfer assets to an unfamiliar address at someone else’s direction.