Protect account access
Use a unique password, enable available multi-factor controls and review active sessions. Secure the associated email account because password resets often depend on it.
Keep secrets offline and private
Never send a recovery phrase, private key, password or one-time code to support, an investigator or someone contacting you unexpectedly. Treat remote-access requests as high risk.
Verify every transaction
Check the complete destination, network, asset and amount before approving. For a new route, use the service’s official documentation and consider an appropriately small test that still meets deposit minimums.
Review unusual activity calmly
Preserve hashes, timestamps and session notices before changing account state. Revoke unfamiliar sessions or approvals through trusted interfaces and contact the relevant provider using independently verified details.