Account security: best practices
Protecting your Uphold account is a mix of strong credentials, multi-factor protections, device hygiene, and being alert to phishing and social engineering attempts. Below are practical steps you can take right now.
Use a strong, unique password
Choose a password that's long and unique to Uphold. Avoid reusing passwords from other services. Use a password manager to generate and store complex passwords safely.
Enable two-factor authentication (2FA)
Prefer time-based one-time passwords (TOTP) via an authenticator app such as Google Authenticator or Authy. While SMS-based 2FA is better than none, TOTP is more resistant to SIM-swapping attacks.
Use biometric sign-in where available
If you're on a personal device, enabling fingerprint or FaceID (when supported) provides both convenience and an added security layer. Always ensure the device itself is secured with a strong passcode.
Recognize phishing & suspicious links
Phishing attacks attempt to trick you into entering credentials on fake pages. Always verify the URL, avoid clicking unknown links, and check for typos or unusual requests. When unsure, navigate to uphold.com manually.
Device and browser hygiene
- Keep your OS, browser, and security software up to date.
- Use browser extensions sparingly and only from trusted sources.
- Consider using a separate browser profile for financial accounts.
Account recovery
If you forget your password, use the official password reset flow from uphold.com. You may be required to complete identity verification steps for certain account actions—follow instructions closely and avoid sharing sensitive documents in unencrypted channels.
Advanced protections
For high-value users, consider hardware-based security keys (U2F/WebAuthn) where supported, and enable withdrawal whitelists or transaction approvals if available in your account settings.
Frequently asked questions
What if I lose access to my authenticator app?
Use your account recovery options and follow the instructions on uphold.com. If you set up backup codes or a secondary 2FA method, use those. Contact Uphold support if you cannot regain access.
How do I change my email address on Uphold?
Go to account settings after signing in and follow the verified email change process, which may include re-verification steps for security.
Is Uphold regulated?
Uphold operates under various regulatory frameworks depending on your jurisdiction. Check the official Uphold site and legal pages for the most current regulatory information.
Final checklist before major actions
- Confirm you're on uphold.com with HTTPS and a valid certificate.
- Use 2FA and verify device trust.
- Test small transactions before large transfers.
- Keep recovery methods secure and documented safely offline.