Lock down your account in two minutes
Use a unique password you do not reuse anywhere else, confirm your email, and enable two-factor authentication with an authenticator app. These three steps stop nearly every account takeover we see. Back up your authenticator's recovery codes somewhere offline the day you enable it.
Two-factor authentication
With 2FA on, signing in needs your password plus a six-digit code that changes every 30 seconds. If you lose the device, a recovery code gets you back in — each code burns on use, so generate fresh ones afterwards. Support cannot disable 2FA on request alone: you will have to prove ownership through the verified email and, for larger balances, an ID check.
Spotting phishing
We never ask for your password outside the sign-in form on this domain, never request remote access to your device, and never promise bonuses over chat or social DMs. Fake login pages are the most common attack: bookmark the real site and ignore links promising free points. Report impersonators to [email protected] with a screenshot.
If something looks wrong
Unknown sessions, a changed email you did not request, or points moving without you — change the password immediately, sign out everywhere from account settings, and open a ticket. Fast reports let us freeze payouts before anything leaves, and our logs show exactly what happened.
