If you suspect that your registered email or Client Portal has been accessed by someone else, secure your email first and then secure your Client Portal from a trusted device. Review all security settings, sessions, Payout details and recent transactions, and report any unauthorised activity immediately.
Signs that your account may be compromised
A password-reset email or one-time code that you did not request.
A new login, device, security-method change or session that you do not recognise.
An unfamiliar local-bank, international-wire or cryptocurrency destination in Payout details.
An email confirming that a new cryptocurrency wallet address was added when you did not add it.
A withdrawal, internal transfer or other transaction that you did not initiate.
You can no longer sign in with the password or security method that you configured.
What should I do if I notice suspicious activity?
If you can still sign in:
Change your Client Portal password under Security → Password → Update.
Review the security methods and account details registered to your profile.
Open Security → My Devices. Review Device, Device ID, Operating System, IP Address, Location and Last Login, and remove any unfamiliar or suspicious device to revoke its login access.
Open Security → Account Activity and review account operations you do not recognise.
Report the incident through Service Hub → Create Ticket → Account & Security. If you cannot sign in, use official Live Chat.
Review bank and cryptocurrency Payout details
Bank payout details are subject to account-holder or recipient-name matching against the customer's verified name. This control reduces risk, but it does not make unauthorised activity impossible. Report every bank destination that you did not add and do not submit a withdrawal to it.
Adding a cryptocurrency wallet requires an OTP through the security method configured for the profile, such as the registered phone, email or Authentication App. After verification, a newly added wallet is subject to a 24-hour security cooling period, and a notification is sent to the registered email address.
If you receive a wallet-addition notification for an address you do not recognise, delete the wallet in the Client Portal during the cooling period when the control is available, secure your email and Client Portal, and report the incident immediately. If you cannot delete it or cannot sign in, open Service Hub
Protect your credentials and digital assets
Never share your password, OTP, private key or recovery phrase. Do not approve an Authentication App request that you did not initiate, and do not install remote-access software because an unsolicited person asks you to do so.
Customers are responsible for keeping their email accounts, devices, passwords, verification methods and digital assets secure. Security controls reduce risk but cannot prevent every form of unauthorised activity or loss. Reported activity will be reviewed according to the applicable account terms, law and the circumstances of the case. Nothing in this article limits any right or obligation that cannot lawfully be excluded.
