Module 8 · Practicing Safely / 8.2
The address bar comes before the buy button.
Make the route into an account part of its protection.
Imagine searching for an exchange. The first result has the right logo. The page looks exactly as you remember it.
The address is wrong.
A copied front door can lead somewhere else. A phishing page borrows a familiar appearance to collect a password, a code, or a signature. The first useful check happens before you type.
Verify the place, then keep the route.
If you choose a service, investigate its legal entity, availability in your jurisdiction, custody arrangements, fees and withdrawal conditions. Check any claimed registration with the relevant authority. Size and regulation can matter, but neither guarantees solvency or reimbursement.
Establish the genuine domain independently. Inspect the full address, including spelling and the part that identifies the actual domain. A padlock means the connection is encrypted; it does not mean the operator is honest.
Bookmark the verified destination or use an app obtained through a verified official route. Before installing, check the publisher and permissions. Avoid letting a sponsored result, private message or urgent email become the route into your money.
Bookmarks reduce one common mistake. They do not prevent a genuine website or your device from being compromised. Keep software current and unnecessary browser extensions to a minimum.
A logo, a bookmark and an encrypted connection each tell you different things. Establish the genuine domain first.
Protect the login and the way back in.
Use a unique, long password where passwords are required. A password manager can help generate and store it. Protect the email account that can reset your financial accounts just as carefully.
Turn on multifactor authentication. Where supported, phishing-resistant passkeys or security keys offer stronger protection against fake sign-in pages. An authenticator app’s one-time code avoids dependence on a phone number, but a fake site can still trick you into entering that code.
SMS codes can be intercepted through a phone-number takeover such as SIM swapping. Prefer stronger methods when available. If SMS is the only available second factor, it is generally better than using only a password.
Check recovery options as well as normal login. Keep backup codes and a spare supported recovery method protected. Test the replacement before disabling an old method; do not lock yourself out in the process of improving security.
Withdrawal allowlists and waiting periods can limit where funds may be sent, when supported. A separate email address may reduce unwanted exposure, but it is not a substitute for strong authentication.
A schedule is a tool, not a promise.
One optional approach to purchases is dollar-cost averaging: committing equal amounts of money at regular intervals. At a lower price the same amount buys more units; at a higher price it buys fewer.
A schedule can reduce repeated timing decisions. It cannot make an unsuitable asset suitable, prevent loss, or guarantee a better result than another approach. Fees, your circumstances and new evidence still matter. Choosing not to buy remains an option.
Before confirming any order, read the amount, quote, fee and order type. A market order seeks execution at available prices; it is not a fixed-price promise. A limit order sets a price constraint and may never execute.
A correct address is only one part of a transfer.
When moving funds, confirm that the recipient supports the exact asset on the exact network. An address with the same appearance on two networks does not guarantee that a service can credit both. Some deposits also require a memo or destination tag.
Get the destination from the intended recipient through a verified route. Compare the full address with what you are approving, preferably on the trusted display of a hardware signer. Check fees, minimum deposits and any required memo.
A small test suited to those costs and minimums can limit the amount exposed to a mistake. Confirm actual receipt through the intended account before a larger transfer. Check the larger transfer again: a successful test does not make its destination or network automatically correct.
One familiar field is not enough. Every required field must match the intended destination.
The idea to keep
Use a verified route, protect both access and recovery, and read the specific action before confirming it. Then verify the actual result.
These habits reduce avoidable errors. The next lesson explains what a hardware wallet protects, and what it still asks you to do.