A lock is not enough

BD333 Account and Device Security Checklist

Just showing the lock icon in the browser is not enough. Domain, password, one-time password (OTP), device, files, and transaction requests—all levels must align together to reduce risk.

The content of this guide was last reviewed on: August 3, 2026

Five levels of security checks

ডোমেইন, পাসওয়ার্ড, OTP, ডিভাইস ও লেনদেনের পাঁচ স্তরের নিরাপত্তা যাচাই
  • Domain: Check the full spelling and redirect destination.
  • Credential: Keep separate passwords and wallet PINs.
  • OTP: Write it yourself, do not share with anyone.
  • Device: Check for updates, lock, permissions, and unfamiliar files.
  • Transaction request: Do not accept payment instructions outside the account page.

Note any anomalies at each level. If there is any suspicion at any one level, stop login, upload, or payment.

Follow the complete list

Verify the identity of the domain and page

BD333 and BD33 or BD3333 are not the same spelling. Write the full domain by hand, check the destination again if redirected, and observe if the language/layout has suddenly changed. Be cautious of unusual bonus pressure, wallet PIN, or file download request identity alerts.

What HTTPS saysHTTPS helps encrypt the connection; it does not prove the operator's identity, license, or complete security. Do not proceed if there is a certificate warning.
  1. Instead of the chat link, write down the known address by hand.
  2. Look for one character less/more, extra hyphen, or unusual ending.
  3. Do not open a short link without knowing the destination.
  4. Stop at browser red warnings or certificate errors.
Verify the app source

Keep passwords separate

Confirm by checking in the accountIf you see a session list, two-factor authentication (2FA), or security notification options on your current account, read the instructions before using them. There is no guarantee that these features are available here.
  • Do not reuse login passwords on other sites.
  • Keep transaction passwords and wallet PINs separate.
  • Keep the lock on trusted devices enabled.
  • Check auto-fill and saved passwords on shared phones.
  • Keep recovery information safe and updated.

If there is a data leak on another site, accounts can be taken over with reused passwords. If reuse is detected, change all related passwords from a clean device.

Password reset steps

OTP is just for you

OTP is a one-time secret code; write it only on the main page where you requested it yourself. It is uncertain whether the platform uses OTP, but if someone asks for the code, stop the signal.

  1. Check if you had a request before the code arrives.
  2. Write only the latest code yourself.
  3. Do not send via screenshot, call, SMS reply, or chat.
  4. Do not allow remote assistance to view your screen.
  5. If an unrequested code arrives, check your password and session.
If OTP does not arrive

Check the permissions of the device and files

The risks of devices and files are part of account security. Keep the system and browser updated, delete unfamiliar files, and do not grant permissions for SMS, contacts, accessibility, or device-admin without clear reasons.

Complete APK verification on the App pageSource, file name, package, signature, system scan, permissions, backup, and uninstall—complete eight-step verification is owned by the mobile and App guide.
Complete eight steps of APK testing

Urgent six steps if you see something suspicious

Stop hereIf you notice unfamiliar logins, profile changes, unauthorized transactions, unlock-fee demands, or remote control, do not argue with the suspected person; first, disconnect access.
  1. Stop: Login, upload, stop file installation and payment.
  2. Disconnect: Close suspicious session; turn off the network if the device is compromised.
  3. Change password: Change reused credentials from clean device.
  4. View payment: Check the official records of your payment account.
  5. Keep evidence: Cover Full ID, PIN, OTP, and password while noting time, domain, and errors.
  6. Report correctly: Use the visible channel of the current account and your payment service provider.
Organize transaction evidence

Weekly security review

Review devices and accounts regularly, not just after an incident. Check browser updates, installed app list, downloaded files, accessibility service, notification access, and saved passwords. Before keeping a screenshot of unknown entries, cover personal information and then remove or revoke.

When receiving email or phone notifications, do not open the link in the message; go to the account via your known path. Match the date, device, and location of the alert with your activity. If you see a device list or logout-all option in the current account, read the instructions before using it; do not claim to stay if the option is not available.

Changing one credential may not eliminate all risks. Change the same password everywhere it has been used, check the payment account, and complete the device scan. If you have sent identity documents, note what and when you sent, and consider if local qualified help is needed.

Keep separate users, screen lock, and notification privacy on family devices. Even if browser profiles are separate, everyone can see downloaded files; regularly check the download folder and saved credentials.

Phishing pages can copy familiar language, color, and navigation. Look for full domain and request behavior, not just visual similarity. If urgent countdown, reward pressure, credential re-entry, and sudden downloads occur together, the risk is higher.

Uninstalling just the app may not be enough if the device is suspected of compromise. Revoke permissions, perform system scans, clean up notifications, review payments, and change passwords from a clean device together.

If using a password manager, keep the master password unique and update recovery methods. If the browser wants to save passwords, say “no” on shared devices. Passwords copied to the clipboard can be read by other apps, so clear the clipboard after pasting if the device offers that option.

If security notification options are visible, check if the destination is yours before enabling unknown logins, password changes, and payment alerts. If you did not request a change of email or phone, stop account activity. Do not log in via any notification link; take a known route.

In the incident note, write “what was seen, when, on which device, what action was stopped.” Keep assumptions and confirmed events separate. This ensures no steps are missed in subsequent password changes, scans, and payment reviews.

After recovery, check if the phone and email destination are still yours. If there are unknown changes, do not start a new session; update the incident note and check the payment records.

Common questions in this guide

Does seeing the HTTPS lock mean the site is secure?
No. The Lock icon indicates connection encryption; it does not indicate operator identity. Verify domain, redirect, content, and request as well.
What is the risk of using the same password on another site?
If another site leaks, an account takeover attempt may occur with the same password. Stop reuse and check for unfamiliar sessions if options are available.
What should I do if I see a login from an unfamiliar device?
Change the password from a clean device, log out of any unfamiliar sessions if options are available, check payment records, and keep partial secret evidence.
Is it safe to get help by screen sharing?
If Login, OTP, wallet, or ID is involved, do not share your screen or allow remote control. Stop immediately and secure your account.