Protect Your UpScalp and Exchange Accounts
Protect Telegram, exchange accounts, API keys, and trading activity with practical anti-phishing checks.
Last updated
Protect Telegram, exchange accounts, API keys, and trading activity with practical anti-phishing checks.
Last reviewed: 2026-05-23.
Most support and security problems start with a bad link, a fake support DM, or weak account protection. Use this checklist before linking UpScalp to any trading activity.
Check API-key safety, exchange credentials, withdrawal permissions, fake support messages, and any request for secrets before acting.
Open links from Official Links and Channels.
Compare Telegram usernames character by character.
Treat unsolicited support DMs as suspicious.
Do not act on urgency messages asking for funds, wallet access, or secrets.
Use unique passwords stored in a password manager.
Enable two-factor authentication where available.
Review active sessions.
Log out unknown devices.
Keep recovery email and phone access secure.
Never share:
Seed phrases.
Private keys.
Exchange passwords.
Exchange API secrets.
Account recovery codes.
UpScalp support will never ask for seed phrases, private keys, exchange passwords, exchange API secrets, or account recovery codes.
Lite and Premium do not require you to create exchange API keys.
If you are approved for a Private Beta API setup, follow only the official approved setup. Stop and contact support if any instruction asks you to:
Enable withdrawal permissions.
Send API keys through Telegram, email, chat, or support messages.
Paste exchange credentials into an unofficial form.
Use a different Telegram bot or support account.
Only continue with API setup when all checks pass.
Approval
You have explicit Private Beta approval through the official route.
Instructions
The setup instructions come from the approved setup, not a public chat or DM.
Permissions
Withdrawal permission is off. Any requested permission is limited to the approved setup.
Storage
You are not asked to send API keys or secrets through chat, email, or screenshots.
Doubt
If anything differs from the approved setup, you stop and contact support before continuing.
Stop trading actions.
Revoke suspicious sessions and permissions.
Change passwords from a clean device.
Rotate two-factor authentication if needed.
Record a UTC timeline.
Contact support with evidence that does not expose secrets.
If you have found a bug, vulnerability, or fraud attempt that affects other UpScalp users, please report it privately first.
Email upscalpbot@gmail.com with [SECURITY] in the subject line. Include:
What you found.
The exact steps to reproduce, if you have them.
The route, link, bot, or page where you saw it.
The UTC time you observed it.
Whether you believe other users may already be affected.
Do not include private keys, API secrets, account credentials, or another user's personal data in the report. A screenshot with sensitive parts blurred is fine.
Hold off on public posts (including in Telegram groups) until support has had a chance to respond, so the issue is not amplified while it is being addressed.
Last updated