Keeping your Vexloot account safe
Your Vexloot account holds your purchase history and, temporarily, the credentials you buy — treat it with the same care as a bank login.
Sign in strong
- Use a unique password — do not reuse the one you use elsewhere. A password manager is the easiest way to keep them separate.
- Enable passkey — once available, enrolling a passkey on your primary device makes phishing attacks practically impossible against your account.
- Add a recovery email — the recovery email is used only for account recovery and never shown to sellers or other buyers.
Session hygiene
- Vexloot sessions expire after 30 days by default. You can review and revoke any active session from the security tab in your settings.
- Sign out from shared devices. The account chip in the header always shows which account is signed in.
Purchase safety
- Vexloot buyers and sellers can only talk through the escrowed inbox on the order page. Any request to move to Discord, WhatsApp or Telegram is a red flag — report it from the order timeline.
- The one-time reveal panel shows purchased credentials only once. Copy or screenshot immediately; the platform does not keep a copy after the escrow window closes.
- When you buy an account, change every credential you can as soon as you receive it: email, password, recovery email, MFA. This is the standard practice for account transfers.
Report a compromise
If you see logins from unfamiliar devices, or your buyer inbox shows messages you did not send, revoke sessions from settings and email support from the affected account. We keep an audit log of every account action and can rebuild the timeline while investigating.