Use official links before entering account details
Open registration and login destinations from a source you trust. Check the domain or destination before entering a phone number, email or password. Avoid links sent by unknown accounts, copied profiles or unsolicited direct messages.
Check the page before you type
Confirm that the page uses HTTPS, the address is expected and the form is asking only for information relevant to account access. A login page should never require you to disclose a full bank PIN or unrelated wallet recovery phrase.
Protect passwords, verification codes and OTPs
Use a unique password that is not reused on email, social media or banking accounts. Treat verification codes as private authentication information. Support staff should not need your password or one-time code to explain a general account issue.
Use a strong password routine
A password manager can help create and store unique passwords. If you suspect a password was exposed, change it promptly and also secure the email or phone account used for recovery.
Keep the device and browser secure
Install system and browser updates, use a screen lock and avoid saving passwords on shared devices. Public Wi-Fi can be convenient, but sensitive account actions are safer on a network you control.
After using a shared device
Log out completely, remove saved credentials and clear any downloaded screenshots that contain account information.
Recognize account-safety warning signs
Be cautious if someone asks for a password, OTP, remote-control access, recovery phrase or an urgent payment to “unlock” an account. Do not send money only because a stranger promises a bonus, refund or faster withdrawal.
