Official Security Protocols Network-Wide Alerts

Digital Asset Security Guide

To keep your assets safe, the OKX official security team has summarized the most common ways people try to steal crypto and tips to prevent it. Please read carefully and stay alert.

一、Common Ways Crypto Gets Stolen

1.Fake Customer Support / Fake Official Notices

Scammers pretend to be platform support, project staff, or exchange risk-control personnel. They might say your account has an issue or your withdrawals are restricted and ask you to verify your identity or “unfreeze” your assets. ,They’ll try to get you to share verification codes, your seed phrase, private keys, or make transfers。

If you fall for it, they can take full control of your wallet or account.

2. Fake Links / Phishing Websites

Fraudsters send texts, emails, or messages in groups and chats with links that look like official sites. These pages often look almost identical to real exchange or wallet interfaces.

Phishing Website Example

Once a user enters their account info, password, SMS code, or Google Authenticator code, their account can be compromised, and assets can be moved out in a very short time.

3. Fake Wallets / Fake Apps / Malware

Some scammers will use fake wallets, apps, or malware to steal users' assets.

These apps or malware can be installed on users' devices, and then can steal their private keys, API permissions, or even take full control of their devices.

4. Fake USDT / Fake Token Scam

Some scammers will issue fake tokens that look like USDT or other popular tokens to trick users into thinking they received real assets.

Users who try to sell, withdraw, or transfer these assets will find that they are not real, and some may be required to pay a “thaw” fee to withdraw them.

5. Fake Transfer Screenshots / Payment Scams

Scammers can fake wallet transfer screenshots, tamper with trading pages, or even forge blockchain explorer records to claim they’ve sent funds. They then try to trick you into sending or releasing your assets first. If you don’t verify the actual on-chain record, it’s very easy to lose your funds.

6. DApp Authorization Scams

When taking part in airdrops, mining, token sales, or on-chain trading, you might be tricked into connecting to a malicious website and signing an authorization.If you grant “unlimited” or high-level permissions, scammers can move your wallet assets without asking again.

7. Seed Phrase / Private Key Exposure

Your seed phrase and private keys are the ultimate control over your wallet. If they’re leaked—through screenshots, sharing with others, entering on a fake website, or storing on an unsafe device—your wallet can be emptied immediately.

Example of Private Key Safety:
8. Watch Out for “Too Good to Be True” Traps

Don’t fall for things like “super cheap U,” “internal channels,” “send first, receive later,” “pay taxes to unfreeze,” or “deposit a guarantee before withdrawing.”

Anytime someone asks you to transfer money upfront, top up temporarily, or pay extra fees—be extremely cautious.

9. Spread Out Your Assets

Don’t keep all your funds in a single hot wallet.

It’s smarter to spread your assets around based on your needs, and store long-term holdings in a more secure cold wallet or isolated environment.

10. Emergency Steps

If you ever suspect your account, wallet, or device is at risk, act immediately.

Here’s what to do right away:

Change your login password
Switch your verification device
Revoke DApp authorizations
Stop any further transfers
Contact official customer support

二、Official Core Security Rules

nder no circumstances should you share the following with anyone:

* Seed phrase
* Private keys
* SMS verification codes
* Google verification code
* Login password
* Payment password
核心提示

Recommended Security Settings to Boost Your Account Protection:

Two-factor authentication (2FA)
Device Login Verification
Withdrawal Whitelist
Suspicious Login Alerts
Security Settings

三、Special Reminder

Once your crypto leaves your wallet, blockchain transactions usually can’t be undone.

So instead of trying to fix things afterward, it’s way better to stay alert and take precautions before anything happens.

Always remember:

Any requests for seed phrase, private keys, verification codes, or any other sensitive information should be treated as high-risk objects.

Keeping your assets safe is something we all need to take seriously together.

We really appreciate your trust and support—please stay alert to scams, act carefully, and take good care of your account and wallet info.

If you need to double-check anything security-related, always contact official support channels. Don’t trust private messages or unofficial contacts.

Wishing you a safe account and smooth trading!

OKX Official Security Team

Keeping your assets safe is a responsibility we all share.