Keep merchant and wallet logins separate

A merchant account and a wallet account have different credentials. A merchant should not need you to send your wallet password to its support agent. If a payment flow redirects to a wallet, inspect the complete destination address before entering credentials.

Which account are you trying to open?

A casino account displays the operator’s games, promotional balance and withdrawal requests. A wallet account displays wallet transactions and funding methods. An approved payment redirect may send you from a merchant to a provider’s authorisation screen, but a social-media message asking you to hand over wallet credentials is a different situation.

ScreenWhat belongs there
Casino sign-inCredentials for that casino account.
Wallet sign-inCredentials for the wallet provider on its verified domain or app.
Payment confirmationRecipient, amount and currency to review.
Support chatA transaction reference or issue description; never a password or one-time code.

A short link-checking routine

Brand colours and a padlock are not enough. A secure connection can still lead to a fraudulent site.

  1. Open the provider through your own bookmark or its official app.
  2. Read the complete hostname, including spelling and the ending.
  3. Reject requests to send passwords or one-time codes in a message.
  4. If uncertain, stop and contact support through the known official channel.

If you already entered credentials

Open the provider independently, change the affected password and review recent activity and connected sessions. Contact the provider about any unauthorised payment. If the same password was reused elsewhere, change it there too.

A new address is not proof of legitimacy

Repeated replacement links and social-media pages do not establish authorisation. For Australian users, check ACMA’s guidance on illegal gambling operators instead of treating a working replacement address as a safety signal.