How do I keep my DafriExchange account secure?
DafriExchange will keep your cryptocurrency safe but only you can protect your wallet from being accessed by intruders. If your sign in details are stolen and used to steal Bitcoin or Ethereum from your DafriExchange wallet, there is nothing you or DafriExchange can do to get it back.
That’s why we’ve written this list of good practices to help you keep your wallet safe.
Be vigilant of phishing
Website
When navigating to the DafriExchange website, make sure the website address (or URL) is the legitimate DafriExchange.com address. If you see anything else in the address bar on top of your browser, leave the site immediately and report it to us by sending a screenshot to us in a support ticket. We’ll try to have the fake site shut down.
Email
Make sure whenever you receive an email from DafriExchange that it was truly sent by DafriExchange. Check the origin of any email before interacting with any of the links – you can do this by double-checking the sender’s address.
If you do receive a phishing email, do not interact with any of the links in the message. Your email provider should have a “report as phishing” option. Use it.
Phone calls
Be vigilant when receiving phone calls and always ascertain who’s calling you. A tactic that phishers employ is to masquerade as a legitimate entity in order to gain access to your account.
When calling, we may ask you some security-related questions in order to verify your identity.
We will never ask you for the following:
Your password
Your banking details
Your two-factor authentication codes
Your OTP pin
Authorisation links
Stay alert
Read any notifications sent by DafriExchange and report any activity that looks suspicious as quickly as possible to us.
Tags are a recent feature we’ve rolled out in the Security Centre. If a new device signs in to your account, or a new API key is created on your account, you’ll notice a notification icon displaying a “New” tag next to the Security Centre menu item. This update enables you to see at a glance if there has been any new activity on your account. It is especially useful to see if an attacker has gained access to your account. If you notice a “New” tag displaying in your DafriExchange account and you have not signed in from a new device or added a new API key, you have the ability to deactivate that device or revoke the newly-created API key.
The notification tags will disappear once you proceed into the Active Device or API items in the menu.
Two-factor authentication
This is such a powerful security measure, it shouldn’t be regarded as optional. With enough time and computer power any password can be guessed.
We’ve written a piece to help you in setting up your two factor authentication security in the Security Centre.
Passwords
Bitcoin is popular and high on the list of things hackers want to steal from you. It’s extremely important you use a strong password. Not only must your DafriExchange password be strong, it must be unique.
If you’re using the same password on your DafriExchange account as your email or your social media accounts, then you’re basically betting the keys to your Bitcoin wallet on you never having clicked on a phishing link.
To protect yourself even further, it’s good practice to use a Password Manager, which allows you to create and remember secure passwords.
It’s good practice to update your password regularly. Here’s how:
Step 1 Sign in to the DafriExchange app or website, go to Menu and then Security Centre
Step 2 Select Password, on this screen you can update your password
Step 3 Now enter your four-digit DafriExchange pin and then once again to confirm the password update
Step 4 Success! You have reset your password. You will receive an SMS to confirm the change
Active Devices
This feature in Security Centre gives you the control to see which devices are currently being used to access your DafriExchange account. Here you have the ability to deactivate any suspicious devices that you may not recognise. As we covered above, be sure to look out for notification tags that may flag an unauthorised active device.
API Keys
An application programming interface key, or API key, is a unique key that allows a program to gain access to your DafriExchange account. Should you wish to view or manage your API key, you can do this in the Security Centre.
You can read more about API keys here.
Biometrics and Touch ID / Face ID
This feature gives you the option to set up biometric authentication (Touch ID or Face ID if you use iOS) for various security features within your DafriExchange account, such as unlocking your app and authorising certain actions.
Secure your email
DafriExchange will interact with you through your email. This is our way of communicating with you. If criminals have access to your email, you are at risk.
Here’s a few things you can do:
Use a unique and strong password.
It's recommended to update your password frequently. A strong password is at least 14 characters in length and contains a mix of letters, numbers and special characters.
Set up two-factor authentication for your email
Most email providers support Google Authenticator or even SMS security. Check your settings.
Check your forwarding settings to make sure.
Attackers will sometimes gain access to your email. They’ll remain stealthy. Without your knowledge, they set up a forwarding address to have all your incoming mail forwarded to them. They wait until the opportunity arises to steal from you. In this way, your Bitcoin can be stolen even if your account was compromised months ago. Check your mail forwarding settings and make sure there aren’t any unknown devices logged into your mail.
If you signed up to DafriExchange using a Gmail address, here are some additional resources for you:
Read Gmail’s help article on security
Sign up for Google’s Advanced Protection Program
In summary, no time spent on improving security is ever wasted. We know adding security means less convenience, but we’ll have peace of mind knowing you have peace of mind. Stay safe, and feel free to reach out to us if you have any security related questions. We’re here to help.
How do I secure my DafriExchange account if I suspect it’s been compromised?
If you suspect that someone got unauthorised access to your DafriExchange account, or if you’ve fallen victim to fraud - and you still have access to your DafriExchange account - we’d strongly suggest that you secure your account in a few easy steps.
Here's how
Step 1: Navigate to Profile, and then Security
Select Send cryptocurrency, and disable it by selecting DISABLE SEND
Select Password, and then change your password to a new one
Select Devices, then review and remove any devices you don’t recognise
Select API keys, then review and remove any API keys you don’t recognise
Step 2: Go to Profile on the web, and then select Settings
Select Email, then review and remove any you don’t recognise. Also, make sure your email is set to ‘primary’
On Mobile number, make sure that your number is correct. If it isn’t, change it on the web by selecting the three vertical dots to the right, and then Change
Step 3: Secure your email account (like Gmail), just in case it's been compromised
Change the password on your email account
Make sure that there are no email forwarding rules set up that you don't recognise
Tip:
Find out how to disable email forwarding on Gmail here
Step 4: Change the password of your Google, Facebook and Apple accounts if you use social login
Step 5: Set up two-factor authentication (2FA) on your account if you haven't already done so
Tip:
Find out how to set up 2FA on your account here
I don’t have access to my account. What now?
If you don’t have access to your account anymore, or if you received a sign-in notification email when you haven’t signed in, we’d suggest that you lock your account. You’ll find a lock your account link in notification emails from DafriExchange. Once you’ve locked your account, you won’t have access to it for seven days.
How do I lock my DafriExchange account?
This article describes how you can quickly lock your DafriExchange account against unauthorised use. Please note that while your account is locked you will not have access to it for seven days.
Locking your DafriExchange account
If you suspect that someone gained unauthorised access to your DafriExchange account (that you’ve been compromised or fallen victim to fraud), you can temporarily suspend your account by locking it. You will see a link in notification emails, from where you can lock your account:
Note that locking your account will disable the following features on the DafriExchange website, the DafriExchange mobile apps and via the DafriExchange API:
Buying and selling cryptocurrencies
Sending cryptocurrencies
Depositing and withdrawing local currency
Trading on the DafriExchange Exchange
Your account will be locked for a period of seven days. At the end of that period, full functionality will be restored automatically.
How to secure your account after you’ve locked it
If you have locked your account, you should immediately secure it.
Ensure that your email or social media accounts haven’t been compromised
Reset your DafriExchange password in the Security Centre and select a unique, strong password
Enable two-factor authentication in the Security Centre here.
You can read more about DafriExchange account security in the Security category
Unlocking your DafriExchange account
For security reasons, your account will remain locked for a period of seven days after you’ve locked it. The DafriExchange Community team won’t be able to unlock it, either. Kindly wait seven days and full account functionality will automatically be restored.
I think my account has been compromised. What should I do?
If you suspect that somebody else has accessed your DafriExchange account, you can follow these steps to secure it.
Step 1 Lock your DafriExchange account immediately
Locking your account ensures that no one can, send, buy, sell, deposit, withdraw or trade from your DafriExchange account for a period of 7 days. Lock your account now!
Step 2 Sign in to your DafriExchange account
Sign in to your DafriExchange account and perform the following actions:
Change your password in the Security Centre
Deactivate any active devices you do not recognise, in the Security Centre
Deactivate any API keys you do not recognise, in the Security Centre
Can’t sign in to your account? Contact us by creating a ticket explaining why you can’t sign in and we'll get in touch to assist you further. Once you have submitted your ticket, continue with the next steps.
Step 3 Secure your personal email
Change your email password
Remove or delete any automatic email forwarding that may be set up on your email account. You can turn off email forwarding in your inbox settings.
Step 4 Change your Facebook password
If you sign-in to DafriExchange using Facebook it is important to ensure that your facebook account is secure.
Step 5 Report any suspicious transactions
Report any suspicious transactions via the link in one of the payments emails you received from us (ensure that the email is from us and not a phishing attempt). You can review all of your transactions here.
Additional recommended steps
If you have completed the steps above, here are a few more recommended precautions you can take.
Enable two-factor authentication (Highly recommended). Here’s how to do it
Disable the ability to send cryptocurrency from your DafriExchange wallet
Read these tips on keeping your DafriExchange account secure
How do I keep my DafriExchange account secure?
DafriExchange will keep your cryptocurrency safe but only you can protect your wallet from being accessed by intruders. If your sign in details are stolen and used to steal Bitcoin or Ethereum from your DafriExchange wallet, there is nothing you or DafriExchange can do to get it back.
That’s why we’ve written this list of good practices to help you keep your wallet safe.
Be vigilant of phishing
Website
When navigating to the DafriExchange website, make sure the website address (or URL) is the legitimate DafriExchange.com address. If you see anything else in the address bar on top of your browser, leave the site immediately and report it to us by sending a screenshot to us in a support ticket. We’ll try to have the fake site shut down.
Email
Make sure whenever you receive an email from DafriExchange that it was truly sent by DafriExchange. Check the origin of any email before interacting with any of the links – you can do this by double-checking the sender’s address.
If you do receive a phishing email, do not interact with any of the links in the message. Your email provider should have a “report as phishing” option. Use it.
Phone calls
Be vigilant when receiving phone calls and always ascertain who’s calling you. A tactic that phishers employ is to masquerade as a legitimate entity in order to gain access to your account.
When calling, we may ask you some security-related questions in order to verify your identity.
We will never ask you for the following:
Your password
Your banking details
Your two-factor authentication codes
Your OTP pin
Authorisation links
Stay alert
Read any notifications sent by DafriExchange and report any activity that looks suspicious as quickly as possible to us.
Tags are a recent feature we’ve rolled out in the Security Centre. If a new device signs in to your account, or a new API key is created on your account, you’ll notice a notification icon displaying a “New” tag next to the Security Centre menu item. This update enables you to see at a glance if there has been any new activity on your account. It is especially useful to see if an attacker has gained access to your account. If you notice a “New” tag displaying in your DafriExchange account and you have not signed in from a new device or added a new API key, you have the ability to deactivate that device or revoke the newly-created API key.
The notification tags will disappear once you proceed into the Active Device or API items in the menu.
Two-factor authentication
This is such a powerful security measure, it shouldn’t be regarded as optional. With enough time and computer power any password can be guessed.
We’ve written a piece to help you in setting up your two factor authentication security in the Security Centre.
Passwords
Bitcoin is popular and high on the list of things hackers want to steal from you. It’s extremely important you use a strong password. Not only must your DafriExchange password be strong, it must be unique.
If you’re using the same password on your DafriExchange account as your email or your social media accounts, then you’re basically betting the keys to your Bitcoin wallet on you never having clicked on a phishing link.
To protect yourself even further, it’s good practice to use a Password Manager, which allows you to create and remember secure passwords.
It’s good practice to update your password regularly. Here’s how:
Step 1 Sign in to the DafriExchange app or website, go to Menu and then Security Centre
Step 2 Select Password, on this screen you can update your password
Step 3 Now enter your four-digit DafriExchange pin and then once again to confirm the password update
Step 4 Success! You have reset your password. You will receive an SMS to confirm the change
Active Devices
This feature in Security Centre gives you the control to see which devices are currently being used to access your DafriExchange account. Here you have the ability to deactivate any suspicious devices that you may not recognise. As we covered above, be sure to look out for notification tags that may flag an unauthorised active device.
API Keys
An application programming interface key, or API key, is a unique key that allows a program to gain access to your DafriExchange account. Should you wish to view or manage your API key, you can do this in the Security Centre.
You can read more about API keys here.
Biometrics and Touch ID / Face ID
This feature gives you the option to set up biometric authentication (Touch ID or Face ID if you use iOS) for various security features within your DafriExchange account, such as unlocking your app and authorising certain actions.
Secure your email
DafriExchange will interact with you through your email. This is our way of communicating with you. If criminals have access to your email, you are at risk.
Here’s a few things you can do:
Use a unique and strong password.
It's recommended to update your password frequently. A strong password is at least 14 characters in length and contains a mix of letters, numbers and special characters.
Set up two-factor authentication for your email
Most email providers support Google Authenticator or even SMS security. Check your settings.
Check your forwarding settings to make sure.
Attackers will sometimes gain access to your email. They’ll remain stealthy. Without your knowledge, they set up a forwarding address to have all your incoming mail forwarded to them. They wait until the opportunity arises to steal from you. In this way, your Bitcoin can be stolen even if your account was compromised months ago. Check your mail forwarding settings and make sure there aren’t any unknown devices logged into your mail.
If you signed up to DafriExchange using a Gmail address, here are some additional resources for you:
Read Gmail’s help article on security
Sign up for Google’s Advanced Protection Program
In summary, no time spent on improving security is ever wasted. We know adding security means less convenience, but we’ll have peace of mind knowing you have peace of mind. Stay safe, and feel free to reach out to us if you have any security related questions. We’re here to help.
What is authorisation and how does it work?
As an added security measure, you need to authorise actions on your DafriExchange account that are considered high risk.
These actions include:
Enabling the option to send cryptocurrency from your DafriExchange wallet
The first cryptocurrency send from a new device
Sends above $10,000
Changing your mobile number
Adding an email address
Creating an API key
Trusting a device to receive authorisations via push notification
How it works
When performing one of these actions we’ll send you an authorisation link via SMS or Push notification. Following the link will take you to an authorisation screen with a summary of the action you’re about to authorise.
If the details of the action are correct, select “Authorise” to complete the action. If the details of the action are incorrect or you did not initiate this action, select “Deny” to cancel it. If you do not recognise this activity on your account, lock your account and report it immediately.