Skip to content
All library documents

Recognizing Crypto Phishing and Protecting Exchange Accounts

Article OKX Learn

Summary

The document outlines common ways criminals target crypto users, including deceptive emails, imitation exchange login pages, malicious API use, and social media accounts posing as customer support. Its practical guidance is to inspect site addresses carefully, avoid signing in when a site’s legitimacy is uncertain, be wary of requests for authentication credentials, and avoid creating API access unless it is needed.

It also recommends two-factor authentication and describes authenticator apps as an alternative to SMS codes, noting that app codes can be available without a mobile connection and avoid SMS interception. These are general account security practices rather than a complete incident response or custody guide. The examples are anecdotal, and the document does not quantify how effective each measure is; it also cautions that no security product guarantees complete protection.

Key ideas

  • Phishing emails and imitation websites can trick users into revealing login and authentication details.
  • Check website addresses carefully because familiar logos and page designs do not prove a site is genuine.
  • Avoid sharing authentication codes and be cautious of unsolicited messages claiming to offer customer support.
  • Use two-factor authentication, with an authenticator app as an alternative to SMS codes.
  • Limit API access to cases where it is necessary, since compromised credentials or keys may enable harmful account activity.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.