Money and safety

How do you keep your account and your money safe?

Never share your login code or an account key you've exported. Treat every unexpected message as a scam until proven otherwise, and check an address before you send. Nobody can reverse a blockchain transaction, so prevention is your only defense.

Can a blockchain transaction be reversed?

No. A card payment can be charged back, and a bank transfer can sometimes be recalled. A blockchain transaction can't: once it confirms, it's final, and no help desk anywhere has a button that undoes it.

There's no safety net under a mistake, so the mistake has to be prevented.

How do you protect your login code and your account key?

You sign in with your email or your Google account, so whoever controls your inbox or your Google account can sign in as you. Keep both secure and never share the login code. Nobody from CoFunders will ever ask you for it: not by email, not by message, not ever.

You can also export your account key. If you ever do, treat it as the account itself: anyone with this key controls your money, right away and for good, and it can't be reset the way a password can. No real service will ever ask for it, and every request for it is a theft in progress.

Where your pledges sit

A pledge you've made is held differently. Here's exactly where it sits:

Your pledge sits in an escrow account the program controls, not in a CoFunders account. Under the program's rules, only the creator can claim a campaign's funds once it reaches its goal, and only you can take your pledge back if it misses. The program can still be upgraded, and today one key we hold can upgrade it (see /security).

The escrow checker shows a campaign's escrow on chain, so you can see it for yourself.

Which scams actually work?

The ones that work aren't clever, they're urgent. A message saying your account is about to be suspended, a help desk agent who contacted you first, a campaign closing in 10 minutes, a friend whose account was taken over asking for a favor.

The pattern is always a deadline plus a link. Slow down, leave the message, and reach the service through an address you typed yourself. An offer that disappears when you take an hour to check was never real.

What if you think someone got into your account?

Act in this order. First, secure your email or your Google account, because that's how you sign in. Then turn on Extra verification under Security in the app's menu, so sensitive actions ask for Face ID, a passkey or an authenticator code. Then tell us, from Feedback and beta in the menu.

If you sent money to a scammer, tell your bank and the police too, and keep the messages. Nobody can pull a transfer back, but a report can stop the next one.

Your next step

Turn on Extra verification today, before you need it. Then learn how to spot a fake campaign.

Sources

Read in
English

Ready?

Free to join. Free to look around.

Browse for free