Use a unique password

A password reused on another site can become unsafe if that other service is breached. Use a long, unique password for VX and store it in a trusted password manager if possible.

Treat recovery information like a password

Recovery codes and authentication secrets can bypass normal sign-in protections. Keep them offline or in a protected password manager. Do not post them in Discord, screenshots, support tickets, or public chats.

Review active sessions

The Account page can show browser sessions associated with the member account. If a session is unfamiliar, sign out other sessions and change the password. Do the same after using a shared or public computer.

Recognize safe support requests

Support may need a username, order ID, visible error, public crypto transaction hash, or approximate event time. It does not need passwords, recovery codes, private keys, seed phrases, or full payment credentials.

Verify the website and release source

Use the official VX domain for account and order actions. Download desktop releases only from the VX Download Center and compare the published SHA-256 value before opening the file.

If you suspect compromise

Change the password from a trusted device, review active sessions, rotate recovery information where supported, and contact VX support. Include the approximate time of suspicious activity so server records can be checked.