Use unique credentials and protect recovery channels
A unique password limits the damage caused by credential reuse. Protect the email address or mobile number used for recovery, because control of a recovery channel can be as important as the password itself.
Never send an OTP because someone contacts you and says it is needed to verify your account. OTPs are designed to prove control of a device or session, not to be read out to strangers.
Recognise phishing patterns
Phishing often uses urgency: an expiring reward, blocked account, pending withdrawal or security warning. The message may copy a brand name but lead to another domain or ask for information that a genuine flow would not need.
Open the service route independently rather than relying on a message link when you are unsure.
Protect the device
Keep the operating system updated where practical, use a screen lock and review app permissions. Be cautious with remote-control software, accessibility permissions and device-admin access because they can expose more than a normal app permission.
On shared devices, sign out and avoid leaving screenshots, credentials or OTP messages accessible.
Protect payment actions
Check the amount and destination before confirmation. Do not provide a bank password, card PIN or OTP to a person claiming they can speed up a withdrawal or unlock a bonus.
If a transaction status looks wrong, keep the reference and use the verified support route of the service that actually handled the transaction.