Key points
- Navigate from the verified official domain rather than an ad or message.
- Confirm the entity in the terms and the product offered in your market.
- Treat social-media support and direct messages as untrusted by default.
- Keep screenshots or records of important terms at the time you act.
Verify the path to the platform
Phishing sites can copy a brand, interface and even support language. Start from an independently verified official domain and move to the app store or documentation from that domain. Avoid logging in from links sent through unsolicited messages.
Check domain spelling carefully, especially around hyphens, alternate top-level domains and look-alike characters. If a platform publishes an official list of domains or social accounts, use that as a reference rather than search ads alone.
Verify the company and product
Read the terms that apply to your account and identify the operating entity. Then confirm whether the exact product you intend to use is offered by that entity in your market. Registration status, permissions and consumer protections can vary across entities and jurisdictions.
Do not assume that a brand-level statement automatically applies to every product, country or service. Keep claims scoped to the entity and product you can verify.
Verify communications and money movement
Before sending funds, confirm deposit instructions inside the authenticated product and use small test transfers when practical. Be cautious with any request to send assets to 'unlock', 'verify' or 'recover' an account.
Support staff should not need a seed phrase or private key. Unexpected pressure, secrecy or guaranteed-return language should trigger a stop-and-verify process.
Primary reading
These official sources provide background for the risk and custody concepts used in this guide. Product-specific facts should still be checked against the relevant operator and jurisdiction.