Guides
Practical guideHow to secure your Stake account
Protect your Stake account with a unique password, secure email, 2FA, a passkey, domain checks and anti-phishing precautions.
Published by The Gambling Desk ·
Three safeguards cover the essentials: a well-protected email account, a unique password and 2FA. Add a passkey if one is available on your device.
Safeguards to activate first
Email and password
Protect the associated email account and use a unique password that is never reused elsewhere.
Two-factor authentication
2FA protects logins, withdrawals, tips and other operations that send funds.
Passkey
When available on your device, a passkey provides a login tied to the genuine domain.
Use a unique password
Create a long password that you do not use for any other service. A password manager can generate and store it.
Protect the email address linked to Stake as well. It is used to verify the account, receive alerts and sometimes confirm an operation or reset the password.
Never give your password to anyone claiming to be support.
Enable two-factor authentication
In Stake, open Settings, then Security. Link an authenticator application by scanning the QR code or copying the string provided. Next, enter the generated code and confirm activation through the email you receive.
The code changes regularly. Stake uses 2FA to protect sign-ins, withdrawals, tips and other operations that send funds.
Do not share the QR code or secret string. Keep the recovery method in a safe place, separate from your main phone.
Add a passkey if one is available
Stake lets you add a passkey from Settings, then Security. It is unlocked with the device's passcode, fingerprint or facial recognition.
A passkey is linked to the genuine website, which reduces the risk of entering your details on a fraudulent copy. It must still be protected through the device lock and a controlled recovery process.
Recognise fake websites and messages
Check the domain before signing in. Do not follow a link received in a private message to claim a bonus or rain, or to resolve a supposed emergency.
Stake states that its official emails use the @stake.com domain. Documented addresses include noreply@stake.com, noreply@mail.stake.com and support@stake.com.
Legitimate support does not request your password, 2FA code, QR-code secret or a wallet's private key.
Protect withdrawals
Generate the address in the receiving wallet or exchange. Check the cryptocurrency, network, address and memo or tag again before confirming.
Never approve a code request that you did not initiate. The Stake withdrawal guide explains the final checks.
What should you do if you notice suspicious activity?
From a clean device:
- secure the linked email account first;
- change the Stake password;
- review recent operations;
- use only the support available through the official website.
If you no longer have access to 2FA or your email, follow the official recovery process. Do not accept unsolicited help from an “agent” in a private message.
FAQ
Does 2FA protect withdrawals?
Yes. Stake documents its use for sign-ins, withdrawals, tips and other operations that send funds.
Does a passkey replace the password?
It can serve as an alternative sign-in method when Stake and the device offer it. Nevertheless, keep your email account and recovery methods protected.
How can you recognise an email from Stake?
Check the sender's complete domain. Stake recommends not clicking any link in a message claiming to come from Stake unless it uses the @stake.com domain.
What should you do if the 2FA phone is lost?
Use the official recovery process or support through the verified domain. Do not provide your recovery information to a third party.
Should you share a code with support?
No. Never disclose a 2FA code, password or the secret used to generate the codes.