INFORMATION SECURITY AND FRAUD PREVENTION GUIDE
Last updated: 01.07.2026
1. General Provisions
1.1. This Information Security and Fraud Prevention Guide, hereinafter referred to as the Guide, sets out the principal security recommendations applicable when using the services of UNITRADE INTERNATIONAL LLC, operating under the OurExchangeClub trademark, hereinafter referred to as the Company, describes common indicators of fraud, and establishes the procedure for reporting suspicious incidents.
1.2. The purpose of the Guide is to assist Users in:
- identifying fraudulent communications and attempted fraud;
- using the Website and their user accounts securely;
- reducing the risk of loss or unauthorized use of personal, payment, and cryptoasset wallet information;
- securely verifying transaction details;
- responding appropriately to a potential security incident;
- providing information and evidence to the Company through secure channels.
1.3. The Guide is intended to raise User awareness and provide practical protection. It does not disclose the Company’s internal technical architecture, control mechanisms, risk assessment criteria, or confidential security procedures.
1.4. The terms governing the processing of personal data are set out in the Privacy Policy, the legal terms governing transactions are set out in the Terms of Use and Public Offer, and the risks inherent in cryptoassets and cryptoasset wallets are addressed in the Cryptoasset Risk Disclosure Statement.
1.5. The Guide does not constitute an absolute guarantee of security and cannot eliminate all risks arising from Users’ devices, communication channels, third-party services, or human factors.
2. Verification of Official OurExchangeClub Sources
2.1. The official OurExchangeClub website is ourexchange.club.
2.2. Users should access the Website by:
- entering the address directly into their browser;
- using a previously verified bookmark;
- or following a link from a previously verified official Company page.
2.3. A link displayed in a search engine, social network, or advertisement must not automatically be treated as official. A fraudulent website may imitate the appearance of OurExchangeClub and differ in its address by only one letter, number, symbol, or additional word.
2.4. Before accessing the Website, the User should verify the complete domain name. The presence of a padlock icon or an HTTPS connection in the browser does not, by itself, confirm that the website belongs to OurExchangeClub.
2.5. Official OurExchangeClub social media pages, messaging channels, and accounts on other platforms should be verified using links published on the Website.
2.6. Official OurExchangeClub emails may only be sent from addresses within the @ourexchange.club domain. However, the displayed sender name and even the visible email address must not be treated as the sole proof of authenticity, as they may be imitated or spoofed.
2.7. Upon receiving an unexpected or suspicious communication, the User should not reply to it or use any contact details contained in it. The User should independently open the Website and contact the Company through an official channel published there.
3. What OurExchangeClub Will Never Request
3.1. OurExchangeClub, its employees, and authorized representatives will not ask a User to:
- disclose their password;
- disclose a one-time code received by SMS, email, or an authentication application;
- disclose a private key or recovery phrase — seed phrase;
- transfer full control of a cryptoasset wallet;
- install remote-access software or provide remote control of a device;
- transfer funds, allegedly for security purposes, to a so-called “safe,” “secure,” “backup,” or “verification” cryptoasset wallet;
- make a payment to unlock an account, protect funds, or guarantee the recovery of lost cryptoassets;
- circumvent identification or compliance checks;
- conceal the source of funds, the ultimate beneficial owner, or the purpose of a transaction;
- urgently carry out a transaction under threat, pressure, or an instruction to keep the matter confidential.
3.2. The Company may, through an established procedure, request information confirming the User’s identity, a transaction, the source of funds, or ownership of a cryptoasset wallet. Such a request will not include passwords, one-time codes, private keys, or seed phrases.
3.3. Any request made in the Company’s name that conflicts with this section should be treated as a potential indication of fraud or impersonation.
4. Security of User Accounts and Communication Channels
4.1. The User should use a long, difficult-to-guess, and unique password for their OurExchangeClub account that is not used on any other website.
4.2. Reusing the same password for email, social media, cryptoasset wallets, banking, or other accounts increases the risk of unauthorized access to several accounts at the same time.
4.3. Passwords should be stored in a trusted password manager and must not be kept in plain text in messages, notes, photographs, or shared files.
4.4. Where two-factor or multi-factor authentication is available, the User is advised to enable it for both the OurExchangeClub account and the associated email account.
4.5. The User must not approve any login or transaction request that they did not initiate.
4.6. The User’s email account and telephone number are important components of account security. Unauthorized access to them may be used to reset passwords, intercept communications, or impersonate the User.
4.7. In the event of an unexpected loss of mobile service, an unrequested SIM replacement, or a suspicious notification from the mobile operator, the User should promptly contact the operator and verify the status of the number.
4.8. The User should periodically verify the personal and contact information contained in their account and immediately report any change they did not initiate.
5. Device and Software Security
5.1. The Website should be accessed using a personal and trusted device with an up-to-date operating system, browser, and security updates.
5.2. The User should not access the Website from a public device, a shared device, or a device provided by an unknown person.
5.3. Transactions should not be carried out over public or unsecured Wi-Fi networks, particularly when personal, payment, or identification information must be entered.
5.4. Applications and browser extensions should be downloaded only from official sources. Software of unknown origin may read copied data, replace a cryptoasset wallet address, or obtain login credentials.
5.5. Screen locking, biometric protection, or a secure PIN should be enabled on the device.
5.6. Before selling, transferring, submitting a device for repair, or after losing a device, the User should sign out of accounts, remove stored information, and, where possible, remotely restrict access to the device.
5.7. The User should not open unexpected attachments, run unknown files, or install software at the instruction of a person claiming to be a Company employee, bank representative, law enforcement officer, or technical support specialist.
6. Secure Verification of Transaction Details
6.1. The cryptoasset wallet address, blockchain network, memo, tag, Payment ID, amount, and other information required for a transaction must be obtained only from the relevant transaction page on the Website or from an official Company communication verified for that specific transaction.
6.2. A cryptoasset wallet address must be verified in full, not merely by its first and last characters.
6.3. The User should not copy an address solely from previous transaction history. Fraudsters may send a low-value transaction from a visually similar address so that it appears in the wallet history and is later copied by mistake.
6.4. After copying an address, the User should compare it again with the original source, as malicious software may replace copied wallet addresses.
6.5. A QR code should be scanned only where its source has been verified. After scanning, the displayed address, network, amount, and other details should be checked before the transfer is confirmed.
6.6. For a high-value transfer, the User is advised, where technically possible and permitted by the transaction terms, to first carry out a small test transfer.
6.7. Any unexpected communication received through a messaging application, by telephone, or by email concerning a change to transaction details must be independently verified through the Website.
6.8. The User should not regard a transaction as completed solely on the basis of a screenshot, payment receipt, banking notification, or statement by a third party. The official status displayed on the Website and the actual receipt of funds in the relevant account or cryptoasset wallet must be verified.
6.9. If the transaction details, recipient, or payment method differ from the information confirmed on the Website, the User must discontinue the action and contact the Company.
7. Common Forms of Fraud
7.1. Impersonation of the Company or Its Employees
A fraudster may use the OurExchangeClub name, logo, an employee’s name or photograph, or a similar email address to gain the User’s trust.
Communications are particularly suspicious where they require an urgent transfer, disclosure of confidential information, installation of software, or secrecy regarding the communication.
7.2. Phishing, Smishing, and Vishing
Fraudulent communication may take place by email, SMS, messaging application, or telephone call and may contain a fake link, an urgent warning, or a threat that the User’s account will be restricted.
The User should not enter a password, authentication code, banking information, or identification data through a link contained in such a communication.
7.3. Fake Technical Support
A fraudster may claim that the User’s account, device, or cryptoasset wallet is at risk and offer “assistance” through remote access, screen sharing, or transfer of funds to another address.
Legitimate technical support does not require complete remote control of a device or disclosure of confidential security credentials.
7.4. Fraudulent Investment Offers
Promises of guaranteed or excessively high returns, “risk-free” offers, pressure to participate within a limited time, and repeated demands for additional transfers should be treated as suspicious.
The use of the OurExchangeClub name, logo, or Website imagery in a third party’s investment offer does not mean that the offer has been approved by the Company.
7.5. Fake Giveaways, Prizes, and Airdrops
A fraudster may promise a prize, bonus, or cryptoasset in exchange for an advance payment, connection of a cryptoasset wallet, approval of a suspicious smart contract, or disclosure of confidential information.
Genuine OurExchangeClub bonuses and promotions are published on the Website or through the Company’s verified official channels.
7.6. Fake Identification or Document Collection
A fraudster may create a false identification page or request an identity document, selfie, bank statement, or other information in the Company’s name.
Identification information should be submitted only through the official process available on the Website or through a service provider approved by the Company.
7.7. Remote-Access and Malicious Software
A fraudster may ask the User to install “security,” “verification,” “wallet recovery,” or “technical support” software. Such software may control the device, read communications, view the screen, or alter transfer details.
7.8. Address Substitution or Address Poisoning
A fraudster may create a cryptoasset wallet address visually similar to one familiar to the User and cause it to appear in the transaction history. Comparing only the first and last characters of an address is not sufficient.
7.9. Impersonation Using Voice or Video
Voice messages, video calls, and video recordings may be manipulated or fabricated. Any unexpected request to transfer funds, change transaction details, or disclose confidential information should be confirmed through a separate, previously known, and trusted communication channel.
7.10. Fraudulent Asset-Recovery Services
Persons who have already become victims of fraud may be contacted by individuals claiming that, for a fee, they can guarantee the return of lost funds or “unfreeze” cryptoassets.
Requests for advance payment, confidential information, or control of a cryptoasset wallet may indicate a further fraud attempt.
7.11. Requests to Use an Intermediary or Third Party
The User should not permit another person to use their account, banking details, or cryptoasset wallet to receive, transfer, or exchange funds or to earn a commission.
8. Key Indicators of Social Engineering
8.1. Common warning signs of suspicious communication include:
- a demand for immediate action;
- a threat that the account will be closed or funds will be lost;
- an excessively attractive or guaranteed offer;
- a request to keep the communication confidential;
- a proposal to circumvent an official procedure;
- a request to transfer funds to a new or unfamiliar address;
- a request for a password, code, or seed phrase;
- an instruction to install remote-access software;
- linguistic, formatting, or address inconsistencies;
- use of an unusual communication channel.
8.2. A professionally designed website, document, email, invoice, or employee photograph does not, by itself, establish the authenticity of a communication.
8.3. A fraudster may know the User’s name, telephone number, previous transaction details, or other accurate information. Knowledge of such information does not prove that the communicating person is a representative of the Company.
8.4. In case of doubt, the safe course of action is to stop, end the communication, and independently contact the Company through an official channel.
9. Secure Communication with the Company
9.1. The User should provide the Company only with information necessary to review the relevant matter.
9.2. Before sending a document, photograph, video, or screen recording, the User should ensure that it does not display:
- passwords;
- one-time authentication codes;
- private keys;
- seed phrases;
- complete bank card details;
- unnecessary personal data of third parties or information relating to other accounts.
9.3. Where a screen recording or image is required, the User should disable notifications, conceal confidential information, and display only the portion relevant to the issue.
9.4. The Company may request additional identification to verify that the request is being submitted by the authorized User of the relevant account.
9.5. The User should not simultaneously send sensitive information concerning the same security incident to multiple unverified addresses or social media pages.
10. Actions in the Event of a Potential Security Incident
10.1. If the User suspects fraud, unauthorized access, or a data breach, the User should, as soon as possible:
- stop communicating with the suspicious person;
- refrain from making further transfers;
- not open additional links or install any proposed software;
- change the passwords of affected accounts from a safe and trusted device;
- first secure access to the relevant email account;
- terminate unknown sessions and remove unfamiliar devices;
- where necessary, contact the relevant bank, payment service, mobile operator, or cryptoasset wallet provider;
- notify OurExchangeClub of the potential incident through an official communication channel.
10.2. If the User has disclosed a one-time code, password, or other login credential, deleting the relevant message is not sufficient. The access credentials of the affected accounts must be changed and active sessions reviewed.
10.3. If suspicious or remote-access software has been installed on the device, the User should discontinue its use, disconnect the device from the network, and consult a trusted technical specialist.
10.4. If the suspicious activity concerns a bank card, bank account, or payment service, the User should promptly contact the official security or fraud prevention department of the relevant service provider.
10.5. If a cryptoasset transfer has already been made, the User should preserve the transaction hash — TXID, wallet addresses, network, amount, and transfer time and promptly notify the relevant service providers.
10.6. Reporting an incident does not guarantee that a transfer can be suspended, reversed, or recovered, particularly where the transaction has already been confirmed on a blockchain network or was conducted outside the Company’s control.
10.7. In the event of a criminal offence or financial loss, the User may also contact the competent law enforcement or other public authority.
11. Preservation of Evidence
11.1. In the event of suspected fraud, the User should not hastily delete messages, emails, or transaction information.
11.2. Where possible, the User should preserve:
- complete copies of messages and emails;
- the sender’s address, telephone number, username, and page link;
- the full address of any fake or suspicious website;
- the date and time of the communication;
- photographs and screen recordings;
- payment details and receipts;
- cryptoasset wallet addresses and TXIDs;
- the names of downloaded files or installed software;
- a brief chronology of events.
11.3. Evidence should be stored securely and transmitted only through official channels of the Company, the relevant service provider, or a competent authority.
11.4. For the purpose of preserving evidence, the User should not continue communicating with the fraudster, follow their instructions, or compromise the security of their devices or accounts.
12. Reporting an Incident to OurExchangeClub
12.1. Any misuse of the OurExchangeClub name, fake website, impersonation of a Company employee, suspicious communication, potential unauthorized use of an account, or other Company-related security incident should be reported promptly.
12.2. A report may be sent to info@ourexchange.club or submitted through another official communication channel published in the “Contact” section of the Website.
12.3. The email subject line should preferably state:
“SECURITY INCIDENT”
12.4. Where possible, the report should include:
- the User’s name and the email address associated with the account;
- the type of incident and a brief description;
- the date and time of the incident;
- the communication platform used;
- details of the suspicious person or page;
- the relevant transaction number or TXID;
- protective measures already taken;
- evidence attached through a secure method.
12.5. The report must not contain a password, one-time authentication code, private key, or seed phrase.
12.6. The Company may request additional information or identity verification in order to assess the authenticity of the report, the relevant account, and the potential risk.
12.7. Reports concerning ethics, corruption, conflicts of interest, or employee conduct may be sent to ethics@ourexchange.club. For security incidents and attempted fraud, the primary communication channel is the address specified in Clause 12.2 of this section.
13. Actions the Company May Take
13.1. Upon receiving a security incident report, the Company may, depending on the nature of the matter and the available capabilities:
- verify whether the report relates to the Company’s Website, account, or transaction;
- request additional confirmation or information from the User;
- temporarily restrict certain functions;
- subject the relevant transaction or account to enhanced review;
- preserve available records and evidence;
- notify an involved service provider or partner;
- take measures available to the Company to restrict the dissemination of a fake page, website, or communication;
- provide information to a competent authority where required by law;
- issue a public warning to Users concerning a widespread or significant threat.
13.2. The Company is not required to disclose its complete internal security procedures, risk assessment criteria, technical logs, or information whose disclosure could reduce the effectiveness of its security systems or prejudice the rights of other persons.
13.3. The Company’s response is limited to the scope of its lawful authority, technical capabilities, and direct control.
14. Official Security Notices
14.1. The Company may publish information on the Website or through official communication channels concerning:
- fake websites or pages;
- fraudulent attempts carried out in the name of OurExchangeClub;
- material changes affecting Website security;
- protective actions required from Users;
- temporary restrictions or security reviews.
14.2. Upon receiving a security notice, the User is advised not to click a link contained in the notice but instead to open ourexchange.club independently and verify whether the relevant information has been published there.
14.3. An official Company security notice will not request a password, one-time code, private key, or seed phrase.
15. Third-Party Services
15.1. When using OurExchangeClub services, the User may also use services provided by banks, payment systems, identity verification providers, cryptoasset wallets, blockchain networks, or other third parties.
15.2. The User must independently verify the official website, application, security rules, and communication channels of the relevant third party.
15.3. A fraudster’s use of the name of a third party cooperating with OurExchangeClub does not mean that the communication has been approved by the Company or that third party.
15.4. A security incident involving a third-party service should also be reported to the relevant service provider through its official communication channel.
16. Amendments to the Guide
16.1. The Company may amend or supplement the Guide in light of new fraud methods, technological developments, changes to Website functionality, information security experience, and applicable legal requirements.
16.2. An amended version of the Guide shall apply from the moment of its publication on the Website unless a later date is specified in that version.
16.3. Users are advised to review the Guide and the security notices published on the Website periodically.
17. Final Provisions
17.1. The Guide is published on the Company’s official Website and is available to all Users and interested persons.
17.2. The Guide applies together with the Company’s other documents published on the Website and does not amend the rights and obligations established by those documents.
17.3. In the event of any inconsistency between the Guide and another document specifically governing a particular legal relationship, the document specifically governing that relationship shall prevail.
17.4. If any provision of the Guide is held to be invalid, unlawful, or unenforceable, this shall not affect the validity or enforceability of the remaining provisions.
17.5. The Armenian-language version of the Guide shall prevail over versions published in other languages.