Dear MAX User,
Amidst a recent increase in phishing incidents, we have observed that fraudulent groups and hackers are using phishing emails and websites to obtain users' personal data, including account passwords.
To counter this, we have implemented a 24-hour withdrawal hold following any password reset. This feature provides a critical safety buffer for users, preventing the malicious withdrawal of assets. Concurrently, our internal teams are continuously working to strengthen our system's security mechanisms to protect your assets.
We urge you to raise your vigilance and partner with us in creating a more secure trading environment by adopting the following protective measures.
Common Attack Methods
Be aware of these common tactics used by attackers:
- Taking control of a user's computer to access their registered email account, then using that access to reset the platform password.
- Using fake third-party verification pages or exploiting cloud-sync features of authenticator apps to steal 2FA codes and seize account control.
- Combining a stolen platform password with a compromised 2FA code to steal account information and assets.
Essential Security Measures for Your Account
To protect your account, you must take the following actions:
- Set a Strong Password: Avoid passwords related to your personal information (like birthdays or names) and change your password periodically.
- Enable Two-Factor Authentication (2FA): Use a dedicated authenticator app. For maximum security, avoid using the cloud sync or backup features within the authenticator app.
- Maintain Device Security: Regularly scan your computer and mobile phone to ensure they are free from malware.
- Beware of Phishing: Do not click on suspicious links or attachments in emails. Never provide your personal information on unverified websites.
- Be Alert to Abnormal Activity: If you notice any unusual activity in your account, contact customer support immediately.
- Use Official Channels Only: Our official social media accounts (Facebook, Instagram, Telegram, X/Twitter) will never initiate a private message with you. Please always contact us through our official website or customer support channels.
Finally, to ensure the safety of your assets, be vigilant for any SMS verification codes you did not request or suspicious emails about a MAX password reset or 2FA removal. If your phone is lost, your device is compromised, or your email account has been hacked, it is crucial that you contact customer support or self-freeze your account immediately.
Thank you for your continued support.
Sincerely,
MAX Digital Asset Exchange