Skip to content
Bullish UK
Security

Crypto Account Security: A Practical Checklist

Most crypto losses start with a compromised email inbox, not a broken blockchain. A practical checklist for locking down the account that holds your funds.

5 min read Published Updated By the Bullish UK team

Almost no retail crypto loss begins with broken cryptography. It begins with an email inbox someone else can read, a password that was reused on a site that leaked, or an address pasted from a clipboard that had been quietly swapped.

That is good news, because those are all fixable in under an hour. Here is the checklist, in the order that actually reduces risk.

1. Secure your email before anything else

This is the one that matters most and it is routinely skipped. Your email address can reset your password on almost every service you use, including this one. Whoever controls the inbox effectively controls the accounts.

  • Give the email account a unique password used nowhere else.
  • Turn on two-factor authentication, using an authenticator app rather than SMS where possible.
  • Check the account's recovery options — an old phone number or a forgotten secondary address is a back door.
  • Review connected apps and active sessions, and revoke anything you do not recognise.

Hardening a trading account while leaving its recovery email unprotected is like fitting a deadbolt and leaving the key under the mat.

2. Stop reusing passwords

Credential stuffing is the most common attack on any platform, and it is not sophisticated. Attackers take username and password pairs from one breach and try them everywhere else. It works because people reuse passwords.

Use a password manager and let it generate something long and random for each site. You then only need to remember one strong passphrase. Length beats complexity: four or five random words are both stronger and easier to remember than P@ssw0rd!.

3. Treat verification codes as secrets

The one-time code we email you is a credential. Nobody legitimate will ever ask you to read it out, forward it, or type it into a chat window.

A specific scam to be aware of: an attacker who already has your password triggers a reset, then contacts you pretending to be support, saying they need "the code we just sent" to secure your account. The code they want is the one that completes their reset.

4. Verify withdrawal addresses every single time

Clipboard-hijacking malware watches for anything that looks like a crypto address and substitutes its own. The substitution is silent and the result looks completely normal. The first sign of a problem is that the funds never arrive.

  • After pasting, check the first six and last six characters against the source.
  • Do that on the screen you are submitting from, not from memory.
  • Send a small test transfer first for any amount large enough that losing it would hurt.
  • Confirm the network matches the address, as covered in the network guide.

A broadcast transaction cannot be reversed. Thirty seconds of checking is the whole mitigation.

5. Recognise phishing by its shape, not its spelling

Modern phishing is well written and visually convincing. Judge it by structure instead:

  • Unexpected urgency. "Your account will be suspended in 24 hours" is a pressure tactic, not a notification.
  • A link you did not ask for. Navigate to the site yourself rather than clicking through. Bookmark the real address and use the bookmark.
  • A request for something we would never ask for. We will never ask for your password, a verification code, remote access to your device, or a transfer to a "temporary" or "verification" address.
  • A near-miss domain. Check the address bar character by character; substituted letters and extra hyphens are the standard trick.
  • Contact from an unexpected channel. Support messages arriving by direct message on social media are, essentially without exception, not support.

6. Secure the device itself

All of the above assumes the device you are using is trustworthy. Keep the operating system and browser updated, since most real-world compromises exploit known and already-patched flaws. Install browser extensions sparingly — an extension can read everything on every page you visit. And avoid doing anything involving money on a shared or public computer.

7. Know what to do if something goes wrong

Speed matters more than diagnosis. If you suspect a compromise:

  • Change your email password first, then your password here.
  • Revoke active sessions on both accounts.
  • Email support@bullish.jo3.org and say plainly that you suspect unauthorised access, so the account can be reviewed.
  • Run a malware scan before signing in again from the same device.
  • Check whether the same password was used elsewhere, and change it there too.

The five-minute version

  • Unique password plus an authenticator app on your email account.
  • A password manager, so every password is unique.
  • Never share a verification code with anyone, for any reason.
  • Check withdrawal addresses character by character, every time.
  • Treat urgency as a warning sign.

Our side of this is described on the security page, including how identity documents are stored and who can access them.

This guide is general information, not financial advice. Trading digital assets carries risk to capital and past performance does not guarantee future results. BULLISH UK SERVICES LTD is not authorised or regulated by the Financial Conduct Authority. Read our risk disclosure before committing funds.

Put your USDT to work today

Create an account, verify your identity and choose a plan. Your first daily credit lands the day after your plan is activated.

Add to your home screen

Works offline · opens full screen

  1. 1

    Tap the Share button in the browser toolbar.

  2. 2

    Scroll down and choose Add to Home Screen

  3. 3

    Tap Add, then open Bullish UK from your home screen.

On iPhone and iPad this is the only way to install a web app — Apple does not let any browser, including Chrome, show an automatic install button.