Seven concrete habits that protect 99% of users from the most common attacks. Read once, set up in 10 minutes, and you're already ahead of most crypto users.
We will never ask for your password, seed phrase, or 2FA code.
Spotted something wrong?
Report a hack, scam, phishing, harassment or team misconduct — with a clear response SLA (1h critical · 24h high · 7d medium).
1. Use a strong, unique password
Minimum 12 characters, mix of letters, numbers and symbols.
Never reuse a password from another site — one breach there compromises you here.
Use a password manager (Bitwarden, 1Password, Apple/Google Passwords) to generate and remember it.
2. Turn on two-factor authentication (2FA)
Enroll a TOTP app (Aegis, Raivo, Google Authenticator) — not SMS, which is vulnerable to SIM swap.
Download and store your 10 recovery codes offline (printed or in a password manager).
Without 2FA, anyone with your password can log in. With 2FA, even a leaked password is not enough.