Security & safety

The rules that keep you
hard to steal from.

Almost every crypto loss starts the same way: a message from someone claiming to be official. This page tells you exactly how we behave, so anything that doesn't match is easy to spot.

We never DM first

No admin, moderator, team member or bot will ever message you first — not for support, not for an opportunity, not to verify anything. Anyone who does is an impersonator. There are no exceptions and there never will be.

We never ask for your keys

Not your seed phrase, not your private key, not your password, not a wallet-connect signature to "verify membership". There is no situation in which we need any of them. Nobody legitimate ever will.

We don't custody your assets

The platform never holds your funds. When you take part in a launch you do so from a wallet you control, through channels published here. We cannot move your assets, and neither can anyone pretending to be us.

Your account

How your account
is protected.

Membership is free and deliberately low-stakes: an account here is a place to learn, not a place that holds money.

01

Sign-in is passwordless. We send a one-time link to your email, so there is no club password for us to store, read or expose.

02

Everything runs over HTTPS. If your browser warns you that a page claiming to be us is not secure, close it and come back to nextcoinclub.com directly.

03

Your account holds no funds. There is nothing in it to drain. Losing it costs you progress, not assets.

04

Your data isn't the product. We don't sell member data or share it with advertisers, and you can delete your account and data at any time.

05

Account emails are transactional only. Sign-in links and session reminders. We will never email asking you to move funds or connect a wallet urgently.

Protect the email account that receives your sign-in links, and turn on two-factor authentication wherever your email, wallet or exchange offers it.

Never, under any circumstances

Things that are
always a scam.

If you see any of these, you are not talking to us. Not a new member of staff, not a special case, not an exception.

No matter who appears to be asking

  • A request for your seed phrase or private key. In any wording, for any reason, including "wallet recovery" or "validation".
  • A private message offering early access. Access is announced in the community and on this site, never in a DM.
  • A wallet address sent to you privately. Any address we ever publish appears on this website first.
  • A "send X, receive 2X" offer. We have never run a giveaway of this kind and never will.
  • Pressure to act within minutes. We don't manufacture urgency. Real deadlines are explained in public, well ahead.
  • Someone asking you to install remote-access software. Support here never needs to see or control your screen.
  • A promise of guaranteed returns. We are not permitted by our own standards to say this. Anyone who does is not us.

If you are unsure, stop and do nothing. Nothing we run is time-sensitive enough that pausing to check will cost you an opportunity. Come to nextcoinclub.com, or ask openly in the community where others can see the question.

Verification

How to check you're
on the real site.

Cloned sites are cheap to make and usually differ by one character. Ten seconds of checking is the whole defence.

01

Read the domain character by character. The only correct one is nextcoinclub.com. Watch for extra words, hyphens, swapped letters, and endings like .net, .io, .app or .finance.

02

Check the padlock. The address must begin with https://. A warning about the certificate means leave immediately.

03

Type it yourself, or bookmark it. Once you are here safely, bookmark this page. Use the bookmark from then on instead of searching.

04

Distrust paid search results. Scammers buy ads against project names. Scroll past the ads, or use your bookmark.

05

Cross-check on two channels. Anything real is on the website and in the community. If it appears in only one place, or only in a DM, it is not real.

06

Look for the tell. Clones copy the design but rarely the substance — they usually cannot reproduce the standards page, the session history, or a named founder who shows up weekly.

Reporting

Found someone
pretending to be us?

Tell us. Impersonation is the single most common way members get hurt, and reports are the fastest way we find out.

01

Don't reply, and don't click anything. Engaging confirms your account is active and worth targeting again.

02

Screenshot it. Capture the username, the profile, and the message. Include the full handle — impersonators change display names constantly.

03

Send it to security@nextcoinclub.com, or post it openly in the community so other members see it immediately.

04

Report it on the platform too. Telegram and X both remove impersonation accounts, and reports from several people move faster than one from us.

05

If you already sent something, tell us anyway. We cannot recover funds and will not pretend otherwise — but we can warn everyone else within the hour, and you will not be judged for it here.

We will never blame you for being targeted. These attacks are professional, well-written, and designed to work on careful people. The only mistake is staying quiet about it.

Responsible disclosure

Found a vulnerability
in something we built?

If you have found a security flaw in this website, the member app, or anything else we operate, please report it privately to security@nextcoinclub.com before disclosing it publicly.

Include what you found, the steps to reproduce it, and what an attacker could do with it. We will acknowledge your report within three working days and keep you updated until it is resolved.

We ask that you avoid accessing or modifying other members' data, avoid degrading the service, and give us reasonable time to fix the issue. In return, we will not pursue action against good-faith research that follows those limits, and we will credit you publicly if you would like to be named.

We are a small company and do not currently run a paid bug bounty. We would rather tell you that plainly than imply a reward that does not exist.

In writing

These aren't policies.
They're commitments.

Every rule on this page also appears in our published standards, which apply to every launch we ever do and to every person who represents this company.

Read the standards