Protect access without mistaking it for a guarantee
A strong account-security setup reduces some unauthorised-access risks. It does not prove that the business holding the account is solvent or that its contract is fair. Those questions require separate research.
Keep credentials distinct
Use unique account credentials and protect the email account used for recovery. Where suitable authentication options are available, understand how both normal access and recovery work. Keep recovery material securely separated from routine browsing.
Wallet recovery phrases and private keys are not customer-service credentials. Ethereum’s security guidance explicitly warns against sharing them. An operator does not need them to inspect a public transaction identifier.
Check the destination of a request
Open the service through a known address rather than an unsolicited message. Pay attention to spelling, the actual domain and whether a link redirects somewhere unexpected. A professional-looking support message can still be an impersonation.
Prepare for account recovery
Before relying on an account, understand what happens if a device is lost, an email address becomes inaccessible or an authenticator stops working. Record the official support route and the procedure, without storing passwords alongside public notes.
Security also includes the device and browser. Avoid installing unknown extensions or allowing a stranger to control the computer to “repair” a payment problem.
If access appears compromised
Use a trusted device to secure the affected email and account, contact the legitimate service and preserve relevant notices. Do not send additional funds to a person who promises to unlock an account. Follow the service’s documented incident procedure and seek local fraud-reporting assistance when appropriate.
Read phishing and fake support for common warning signs. This guide cannot certify a particular operator’s security.