How to protect your account
Your password, two-step verification, fake messages and what to do if you think someone has got into your account.
By Pitiklini · · 6 min read
Key points
- Use a long password that is different from the ones for your other services. A password manager helps you do it.
- Turn on two-step verification with an authenticator app.
- Nobody from Pitiklini will ask for your password or your codes: not by email, not by phone, not by chat.
- Always sign in by typing pitiklini.com, not through the links in a message.
A good password
- Long. Length matters more than mixing symbols. A phrase of several unrelated words is simple to remember and hard to guess. The US National Institute of Standards and Technology (NIST) recommends at least 15 characters when the password is the only protection.
- Unique. If you use the same one on several sites, a breach at one of them opens the others.
- Kept in a password manager. It creates different passwords, remembers them for you and only fills them in on the right website.
- Change it if there is a reason, for example if it shows up in a breach or you suspect someone knows it. Changing it every so often for no reason does not help: it tends to lead to more predictable passwords.
Pitiklini does not accept the most common passwords, or those that have appeared in known data breaches.
Two-step verification
Two-step verification asks, besides your password, for a one-time code that changes every short while. That way, knowing your password is no longer enough to get in.
On Pitiklini it works with an authenticator app on your phone. Once it is on, it asks for the code when you sign in, and you cannot withdraw without it. Each withdrawal also asks for a code sent to your email that only works for that withdrawal.
Why an app and not a text message? With a SIM swap, a fraudster can receive your text messages on their phone. The codes from an app are generated on your phone and do not travel over the phone network.
Codes do not protect against everything. If someone tricks you into giving them, or into typing them on a fake website, they can use them straight away. That is why you never give them to anyone.
- If you change phones, move your authenticator app accounts to the new one first.
- If you lose it, write to support. After checking that it is you, the team can remove two-step verification so that you can set it up again.
Fake emails, messages and calls
Phishing is a scam in which someone pretends to be a trusted company. What they want is your passwords, your codes or your money. It arrives by email, text message, social media or phone, and it imitates logos, senders and addresses.
Warning signs:
- they rush or scare you: "your account will be blocked", "there is a suspicious transaction";
- they ask for your password, a code or a recovery phrase;
- they ask you to install a program so they can "help you" remotely;
- they ask you to move your funds to another wallet "to protect them";
- a link leads to an address that looks like pitiklini.com, but is not exactly that.
Your anti-phishing code helps you tell them apart. You choose it in your account and it appears in Pitiklini emails. If you have turned it on and an email that looks like ours does not carry it, be suspicious. If it does carry it, look at the rest just as carefully: it helps rule out imitations, but it does not guarantee anything.
And the padlock in your browser only shows that the connection is encrypted, not that the website belongs to whoever it claims to be.
We will never ask, by email, by phone or by chat, for your password, your verification codes or a recovery phrase. Nor will we ask you to install a remote access program, to move your funds to another wallet or to remove a security measure.
Your email, your phone and your devices
- Protect your email like your account, because it is how your password gets reset. Give it its own password and turn on its two-step verification too.
- Keep up to date the operating system and the apps on your phone and computer.
- Install apps only from the official stores and check who publishes them: fake copies of crypto apps are around.
- Lock your phone's screen with a code or your fingerprint.
Pitiklini's alerts
We alert you in your account and by email when any of these happens:
- your password changes;
- two-step verification is turned on or off;
- someone signs in from an internet address (IP) that had not been used before.
If it was not you, act straight away.
After a security change, withdrawals are paused for a while, to give you time if the change was not made by you.
If you think someone has got into your account
- From a device you trust, change your Pitiklini password: all open sessions will be signed out.
- Change your email password too, and check that nobody has added rules to forward your messages to another address.
- Set up two-step verification again.
- Write to us at the support address on the contact page, never to a contact someone gave you in a message.
- If you installed a remote access program, uninstall it.
- Keep the evidence (emails, messages and screenshots) and report it to the police. In Spain, you can do it online with the Policía Nacional or the Guardia Civil (in Spanish).
If you are in Spain, you can call 017, the cybersecurity helpline of the Spanish National Cybersecurity Institute (INCIBE), for guidance. It is free and confidential.
And be wary of anyone who promises to recover your money for a fee: it is usually a second scam.
Sources
- SP 800-63B-4, "Digital Identity Guidelines: Authentication and Authenticator Management", from NIST.
- "Gestión de contraseñas seguras", "SIM swapping: cómo evitar esta estafa", "Suplantación de identidad y secuestro de cuentas" and "Recovery Room", from INCIBE (in Spanish).
- "Tu Ayuda en Ciberseguridad", INCIBE's 017 helpline (in Spanish).
- European supervisory authorities' factsheet on crypto fraud and scams (January 2026; the link leads to the Spanish version).