Before entering credentials
Check the address independently, use a password manager to detect lookalike domains and never follow a login URL from an unsolicited message. A copied dark theme and logo are easy to reproduce.
Secure the session
Use a unique password, enable two-factor authentication where supported, review active sessions and log out from shared hardware. Do not store payment cards in a browser profile other people can access.
Recovery records
Keep account identifiers, support case numbers and recovery emails. If access changes during a withdrawal dispute, preserve the timeline without sending passwords or one-time codes to support.
Evidence checklist
- Navigate independently; do not trust message links.
- Never share passwords or one-time codes.
- Enable 2FA if current terms support it.
- Preserve recovery correspondence.