Skip to main content
BYNAI
Back

Protect your account from phishing and what to do if it may be compromised

Security

Phishing, impersonation and a possibly compromised account

Golden rules

  • Never share your password, fund password, 2FA codes, email or SMS codes, backup codes, seed phrase or private key with anyone, including people who claim to be from BYNAI.
  • Only type your credentials on the BYNAI site you opened yourself. Check the address in your browser.
  • Set an Anti-Phishing Code: it appears in all official emails from BYNAI. An email without your code is suspect (see the anti-phishing code article).
  • Do not install software or approve wallet connections for strangers. Wallet sign-in only asks for a signature ("Signature only — no gas fee").
  • Telegram sign-in works only through the BYNAI bot: "Log in with a code from @bynai_bot". The one-time code expires: enter the 8-digit code within 2 minutes. Never give this code to anyone.
  • Before withdrawing double-check address and network: "Transactions cannot be reversed once confirmed."

Signs your account may be compromised

  • Security emails or codes you did not request.
  • A device or location you do not know in Device Management.
  • A cooldown notice for a change you did not make ("Security Cooldown Active" - Password Changed, 2FA Disabled, Email Changed, Phone Changed, New Whitelist Address, Fund Password Changed).
  • Unknown addresses in Address Management, or withdrawals you did not make.

What to do now

  1. Sign in from a clean device and open Security.
  2. In Device Management use Sign Out for unknown devices or Sign Out All Others.
  3. Change your password (Advanced Security > Password > Manage). Use a unique one.
  4. Make sure two-factor authentication is On (Authenticator App > Set up).
  5. Set or change your Fund Password and your Anti-Phishing Code.
  6. Review Address Management: Remove unknown addresses. Consider turning the withdrawal whitelist on (Settings > Withdrawal).
  7. Contact Support at once if funds moved or you cannot sign in.

Be aware that password, 2FA, email, phone and whitelist changes each start a temporary withdrawal restriction (see the withdrawal cooldown article). That also slows an attacker.

If you already shared a code or clicked a link

  • Treat it as compromised: do steps 1-7 above immediately.
  • Do not reply to the sender. Keep the message for Support.

FAQ

Q: Someone from "BYNAI Support" asked for my code. A: Do not share it. Report it to Support.

Q: Will BYNAI return funds sent in a scam? A: The app makes no promise of reimbursement or reversal. Contact Support with the details.

Q: I lost access to my authenticator and my email. A: Contact Support; see the 2FA article.

When to contact Support

Open the chat widget and choose "Contact support" (or open the Help Center and start a chat there). Include:

  • Your account email or UID (shown on your profile).
  • What you were trying to do and the exact message you saw (a screenshot helps).
  • The approximate date and time it happened and the device or browser you used.
  • Never include your password, fund password, 2FA codes, backup codes, seed phrase or private key.
  • Transaction IDs, addresses and times of anything you did not authorize; the phishing email or message screenshot (do not click links).

Safety reminder

Never share your password, 2FA codes, backup codes, seed phrase or private key.

Related terms: phishing, scam, fake website, fake email, fake support, impersonation, hacked, account hacked, compromised, unauthorized access, someone logged in, suspicious activity, stolen funds, unauthorized withdrawal, security tips, safety, scam warning, seed phrase, private key, fraud

Was this article helpful?