BoltCopy

August 18, 2026 · BoltCopy Desk

Keeping your account and your payouts safe

Two-factor authentication, one payout wallet, and a code on every change. What each control is actually protecting you from, and the two mistakes that cost people money on every crypto platform.

Keeping your account and your payouts safe

Every serious crypto platform ends up building the same set of controls, because the same small number of things go wrong. It is worth knowing what each control on BoltCopy is protecting you from, since a control you understand is one you will not try to route around.

Two-factor authentication

A password protects your account from someone guessing. It does not protect it from someone who already has your password — from a reused password on a site that was breached, from a convincing phishing page, from malware on a shared computer.

Two-factor authentication is the control for that case. Once it is on, your password alone is not enough to move money. An authenticator app on your phone generates a six-digit code that changes every thirty seconds, and the platform will not accept the same code twice.

That last detail matters more than it sounds. A code someone captures — over your shoulder, from a screenshot, from a fake support chat — is useless the moment it has been used once, and useless again after thirty seconds. Turn it on in Settings, under Security, before you make your first deposit rather than after.

One payout wallet

Withdrawals on BoltCopy go to exactly one address: the payout wallet on your account. Not an address typed into the withdrawal form, not an address pasted at the moment of the request. One address, saved in advance.

This is the single most effective protection a crypto platform can offer, and it exists because of one specific attack. If a withdrawal form accepts a fresh address every time, then anyone who reaches your session for sixty seconds can send your entire balance to an address of theirs. Nothing about the withdrawal looks unusual. It is a valid request, correctly authorised, to the wrong place.

With a saved payout wallet, that attack requires the attacker to change the wallet first — and changing it requires your authenticator code, and so does deleting it. An attacker with your password and your session still cannot redirect your money.

A code on every change

Adding a payout wallet, replacing it, removing it, and confirming a withdrawal all require the authenticator code. This is not friction for its own sake. Each of those four actions is a step on the path between somebody reaching your account and somebody keeping your money, and the code is on all four.

The address itself is checked against the chain you selected before anything is saved. An address that is not valid for that network is refused at the form. This has nothing to do with attackers; it is there because a mistyped address on most chains is an irreversible loss, and the cheapest moment to catch it is before it is ever used.

Desk review

A filed withdrawal goes to the payout desk rather than straight to the chain. The balance leaves your account immediately — so the figure on screen is always what you can still spend — and the request is reviewed before it is sent.

If a request is refused, the money is paid back to your wallet and the reason is on the request's own screen. You can also cancel a request yourself while it is still awaiting review, and cancelling refunds it the same way.

The two mistakes

Almost every loss on a platform like this comes from one of two things, and neither is a technical failure.

The first is support impersonation. Somebody contacts you claiming to be from BoltCopy and asks for a code, a password, or remote access to your device to "verify" or "unlock" something. No member of this platform's staff will ever ask you for your authenticator code or your password. There is no situation in which we need either. If someone asks, that is the whole diagnosis — you do not need to work out whether the rest of their story is plausible.

The second is a reused password. If the password on your account is one you have used anywhere else, treat it as already known to somebody. Change it to something used nowhere else, and turn on two-factor so that it stops being the only thing standing between an attacker and your balance.

A five-minute setup

If you do nothing else this week:

  1. Turn on two-factor authentication in Settings, under Security.
  2. Save your payout wallet before you need it, and check the address character by character.
  3. Make sure the email on your account is one you still control, since every deposit, withdrawal and review decision sends a receipt to it.

None of this is interesting, and that is rather the point. The accounts that stay safe are boring accounts.

Back to the journal
Create an account