All tutorials
Tutorial 03 · Security

Almost nobody gets hacked. People get talked into it.

Exchanges are hard to break into. Convincing a person to hand over a code is easy, and that is how nearly every loss in this industry actually happens. Twenty minutes of setup, and a short list of things to recognise, is the whole defence.

Elapsed: about 20 minutesDo this once
Uriel will never ask you for
Your password
A two-factor code
Your API secret
A transfer to a private wallet
When in doubt, hang up and call your adviser back on the number you already have.
If any message, call or person asks you for one of these, it is not us — whatever name, logo or phone number it shows.
1
Ten minutes

Turn on two-factor authentication properly

Two-factor means a second proof beyond your password: a code that changes every thirty seconds, generated on your phone. Without it, a leaked password is enough to lose everything.

  1. Install Google Authenticator or Authy from your phone's official store — not from a link.
  2. On the exchange, and again on your Uriel dashboard, enable two-factor and scan the QR code shown.
  3. Write the backup codes down on paper. Keep the paper somewhere physical — a drawer, a safe — not a photo on the same phone.
  4. Turn on withdrawal address whitelisting on the exchange, if it offers it. Then even a stolen session cannot send funds to a new address.
Not by SMS, if you can avoid it

SMS codes can be intercepted by someone who persuades your mobile operator to move your number to a new SIM. An authenticator app on your phone is not exposed to that.

2
Once, then out of habit

Recognise the three scams that actually work

  • The fake support call. Someone calls saying they are from your exchange, or from us, and that your account is at risk. They will ask for a code "to secure it". A real support team never asks for a code. Hang up and call back on a number you already had.
  • The look-alike website. A link by email or text leads to a page identical to the real one, on an address off by one letter. Type the address yourself, or use your own bookmark. Never sign in from a link you were sent.
  • The better offer. A message, often on WhatsApp or Telegram, promising a guaranteed return if you move funds to a "special" address. Nobody legitimate ever asks you to send crypto to a private wallet. We certainly do not.
3
Every few months

Keep the basics tidy

  • A unique password for the exchange and another for your dashboard, ideally from a password manager.
  • Check the list of active sessions and devices on the exchange, and sign out anything you do not recognise.
  • Check your API keys: there should be one, ours, with Trade permission and an IP restriction. Delete anything else.
  • Keep your phone and computer updated. Most real break-ins use a hole that was patched months ago.

How to tell it is really us

Four checks that take a second each.

  • 01Our emails come from a uriel-group.com address, and never contain a link asking you to sign in and "confirm" anything.
  • 02Your adviser has a name you already know. A new person calling about your account is a reason to stop and verify.
  • 03We ask for money in exactly one place: the invoice in your dashboard, settled to the deposit address shown there. Never to an address sent in a message.
  • 04If something feels rushed or urgent, that is the tell. Real requests survive you calling back tomorrow.

If you think something went wrong

Act first, explain afterwards. Change your exchange password, revoke every API key, and call your adviser. Nothing you do in that order can make things worse, and speed matters more than certainty. Contact us.

Not sure about a message you received?

Forward it to your adviser before you click anything. Checking costs nothing, and we would far rather look at ten harmless emails than miss one real attempt.

Talk to us
Next tutorial
Withdrawing your money