What this checklist can and cannot tell you
Warning signs are prompts for verification, not proof that a person, platform, or transaction is criminal. FATF guidance stresses that indicators must be considered in context and that combinations without a logical explanation are generally more meaningful than one isolated observation.
The same limit works in the other direction: a clean checklist does not prove safety. Platform identity, authorization, destination details, custody terms, and account controls still need independent verification.
Verify the approach before trusting the person
Treat unsolicited social messages, accidental texts, new online relationships, celebrity endorsements, and support outreach as unverified. IOSCO describes social-media contact, impersonation, fake sites, and relationship-based approaches among recurring investor-protection concerns.
Pause when a message adds urgency, secrecy, guaranteed returns, or pressure to avoid independent advice. Open the official website yourself and use a separately verified support channel.
Never disclose wallet or account secrets
Do not share a seed phrase, private key, password, one-time code, recovery code, or remote device access. A legitimate support process should not require the secret that controls a wallet.
Keep recovery material out of chat apps, email, screenshots, cloud notes, support forms, and generic security tools. If a secret may have been exposed, move through the official incident and recovery process from a trusted device.
Check domains, apps, recipients, and networks independently
A familiar logo or display name does not verify a destination. Type or use a trusted bookmark for the official domain, check the publisher of an app, and compare addresses character by character where practical.
Before a meaningful transfer, confirm the recipient, network, memo or tag requirements, fees, and minimums. Use a small test transaction when it is operationally sensible and still meets the platform's transfer rules.
Review the platform's role and custody disclosures
IOSCO highlights the need for clear disclosures about a service provider's role, conflicts, custody arrangements, handling of client assets, operational risks, and retail-facing promotions. Look for plain-language answers rather than relying on a polished interface.
Verify eligibility in your jurisdiction, the operator behind the service, how assets and private keys are held, withdrawal rules, support and complaint routes, and what happens if access is interrupted. Do not infer authorization from a global marketing page.
Protect login and recovery paths
Use a unique password, a password manager, and strong multi-factor authentication. Prefer a passkey or security key where supported, and secure the recovery email with different credentials.
Store backup codes securely offline, review logged-in devices and sessions, and investigate unexpected password-reset, device, withdrawal, or API alerts.
Limit withdrawal and API exposure
Enable withdrawal allowlists, address locks, or cooling periods where suitable and understand how recovery works before relying on them. Review approved addresses regularly.
For API access, create one narrowly scoped key per tool, avoid withdrawal permission, use an IP allowlist where supported, and revoke unused keys. Never paste an API key into a public checklist.
Treat withdrawal and recovery payments as a stop signal
A demand for another payment to unlock a withdrawal, pay a surprise tax, verify a wallet, or recover previous losses deserves immediate independent verification. Sending more money can compound the loss.
If funds or credentials were already sent, preserve relevant records and contact the platform, financial institution, and appropriate local authority through independently verified channels. Do not hire a recovery service solely because it contacted you.
Decision rule
Use this guide as a checklist, not as financial advice. Confirm current platform terms, local eligibility, and risk limits before opening or funding any account.
Sources
- https://www.fatf-gafi.org/content/dam/fatf-gafi/reports/Virtual-Assets-Red-Flag-Indicators.pdf
- https://www.iosco.org/library/pubdocs/pdf/IOSCOPD769.pdf
- https://www.iosco.org/library/pubdocs/pdf/IOSCOPD747.pdf
- https://www.fsb.org/2023/07/fsb-global-regulatory-framework-for-crypto-asset-activities/
- PartnerCrypto synthesis for visitor education; not a fraud determination or regulatory assessment.
Editorial review
PartnerCrypto prioritizes official platform, regulatory, and primary technical sources. Editorial interpretation is labeled, and unverified current claims are omitted.