Skip to main content

Common scam patterns

What do all scams have in common?

Urgency. Every scam relies on getting you to act before you think. If anyone is pressuring you to decide fast, that pressure itself is the warning sign. Slow down.

What should you never share?

Your OTP codes. No legitimate platform, exchange, or person will ever need them. Anyone asking for them is trying to access your account.

Not sure if something is a scam?

Stop where you are and contact Roxom support directly through official channels before doing anything else.

Basic security practices

Protect your email first

Since Roxom uses passkey and OTP-based authentication, your email is the most critical external dependency. Use a strong, unique password and enable 2FA.

Secure your login: prefer a Passkey

Roxom recommends a Passkey as your strongest protection: it’s phishing-resistant and tied to the real roxom.com, so it can’t be used on a fake site. If you can’t use a passkey, an authenticator app (Google Authenticator or Authy) is the next best option. Email OTP alone is the weakest, use it only as a fallback.

Double-check withdrawal addresses

Before confirming any withdrawal, verify the destination address carefully. Malware and scams can swap a copied address for the attacker’s. Confirm the first and last characters, and when possible send a small test amount first.

Keep everything updated

Most attacks exploit known vulnerabilities that patches already fix. Keep your devices, browsers, and apps updated.

Be careful on public networks

Avoid accessing financial accounts on public Wi-Fi, or use a VPN if you have to.

Always verify URLs

Attackers register domains that differ from the real one by a single character. Always check that you’re on exactly roxom.com before authenticating.

Impersonation & phishing

How to verify Roxom communications and avoid phishing.

How to secure your account

Set up passkey and authenticator app.
Last modified on June 15, 2026