Start with the device, not just the account
Account security depends heavily on the device used to access it — a device with an outdated operating system, no screen lock, or unknown installed software is a weak link regardless of how secure the account provider's own systems are. Keeping devices updated is a basic, high-value habit.
Strong authentication matters more than a strong password alone
A password alone is one of the weaker forms of protection available today. Passkeys, biometric authentication and multi-factor authentication all add a layer that a stolen password alone can't defeat, and are worth enabling wherever a provider offers them.
Recognising social-engineering attempts
Most account compromises don't come from breaking encryption — they come from convincing someone to hand over access voluntarily, through urgency ('your account will be locked'), impersonation of support staff, or requests to 'verify' an account by sharing a code, password or approving a transaction.
What a legitimate provider will never ask for
No legitimate bank, card issuer or digital-asset provider will ever ask for your full password, a one-time passcode meant to stay private, your seed phrase, or ask you to approve a transaction purely to 'verify' your account or wallet. Any message asking for these is a scam attempt, regardless of how official it looks.
How GEF One fits in
GEF One's own account and device security combines identity verification during onboarding with passkey-based authorisation for wallet actions, so sends are authorised locally on your own device rather than by GEF One itself. See the full Security Centre for the complete picture of how these controls work together.