User Safety Guide – Protect Your Money, Account & Personal Data

A deep, practical safety handbook for anyone using P2P token platforms, UPI payments and mobile wallet apps. Learn how online payment fraud actually works, how to verify every transaction yourself, how to spot fake apps and scam Telegram groups, and exactly what to do if money is lost. This page is educational and applies to any platform – not just one app.

Read the Complete Platform Guide on GoldGo.co
This safety guide explains fraud patterns, verification habits, account security, dispute steps and cybercrime reporting in India. It is reviewed and updated regularly.
First Published: 5 September 2026 | Last Updated: 5 September 2026

Why This Safety Guide Exists

Digital fraud in India has shifted from guesswork to organised operations. Fraudsters today run scripted phone calls, cloned apps, edited payment screenshots and lookalike websites that take minutes to deploy. The single most effective defence is not any app or tool – it is your own verification habit. Every section of this guide builds one core skill: confirming facts through official channels before money, data or trust moves anywhere.

Three principles run through this entire page:

  • Trust your own bank app, not anyone's screenshot or claim.
  • Trust the official website and in-app channels only – never links sent by strangers.
  • No genuine service, agent or support person ever needs your OTP, password, UPI PIN or CVV.

Start from the beginning on goldgo.co, then use this page as your personal fraud-defence reference.

How Scammers Think – The 4 Manipulation Levers

Every online scam, no matter how technical it looks, presses one or more of these four psychological buttons. Learning to recognise the feeling of being manipulated is the earliest warning system you have:

  • Urgency: "Your account will be blocked in 10 minutes", "Offer closes today", "Pay now or lose your tokens". Urgency exists to stop you from thinking. Any message that demands instant action is a red flag by default.
  • Authority: Fake "RBI officials", "cyber police", "bank managers", "platform admins". Real institutions never call you demanding remote access, OTPs or "verification payments". Verify by calling the official number printed on the official website yourself – not the number the caller gives you.
  • Greed or fear of missing out: "Double your deposit", "guaranteed daily profit", "limited referral slots". Guaranteed returns do not exist in any legitimate market. Anything promising fixed profit is structurally a scam.
  • Isolation: "Don't tell your family, this is a secret system", "Move to this private WhatsApp group". Secrecy is a scammer's tool. Legitimate services never need you to hide the relationship.
Rule of thumb: If a message makes you feel rushed, scared, greedy or secretive – stop. Sleep on it. No legitimate financial decision collapses overnight, but a scam does if you wait.

UPI Fraud Patterns in India – How Each One Works

These are the most common UPI-based fraud patterns reported across India. Understanding the mechanics makes each one obvious in real time:

1. The "Collect Request" trap

You list something for sale. A "buyer" sends a UPI collect request (a request to take money FROM you) claiming it is needed "to receive payment". If you approve it and enter your PIN, money leaves your account. Fact: entering a UPI PIN is only ever required to SEND money – never to receive it. If receiving money needs your PIN, it is theft.

2. Screen-sharing app takeover

A "support agent" asks you to install a screen-sharing or remote-access app (AnyDesk, TeamViewer, or similar) "to help fix a payment". While connected, they watch your OTPs and can operate your device. No genuine support team on any platform ever needs remote access to your phone. Refuse and report.

3. Screenshot payment proof

You are shown a polished "payment successful" screenshot. Screenshots are trivially edited or generated from failed transactions. The only valid proof of received money is the balance or statement inside your own bank/UPI app. Money not visible there has not arrived, whatever anyone says.

4. Overpayment and refund fraud

A "buyer" "accidentally" sends more than agreed, sends a screenshot as "proof", and pressures you to refund the difference instantly. The original transaction later reverses or was never real – and your refund was real money out. Never refund against a screenshot; wait until funds are visible and settled in your own app.

5. Fake customer-care numbers via search

Scammers poison search results and social media with fake helpline numbers. You call, "the agent" asks for card details, OTP or a "verification fee". Always take support numbers from the official website only, and never search for support numbers in a panic.

6. QR-code reversal trick

Scanning a QR code sent by a stranger can pre-fill a payment to them. Only scan QR codes when you intend to pay, double-check the payee name on the confirmation screen, and never scan codes sent "for verification".

The master rule: You never need to enter a PIN, share an OTP, install a remote app, or pay any fee to RECEIVE money. Any request combining these is fraud, every time, without exception.

Fake Apps & Clone Websites – How to Identify Them

Fraudsters clone popular app names and distribute modified APK files that steal credentials, read OTPs, or display fake balances. Here is a systematic verification process:

  1. Check the domain character by character. "goldgo.co" and "goldgo-login.com" or "goldg0.co" (zero instead of 'o') are different sites. Clone domains rely on you skimming. Type the official domain manually or use your bookmark.
  2. Verify the padlock is not enough. HTTPS only means the connection is encrypted – scammers get free certificates too. A padlock on a fake site means nothing about who runs it.
  3. Check app permissions after install. A trading or wallet app has no business requesting access to your contacts, SMS from unrelated apps, call logs or accessibility services. Excessive permissions are a takeover signal – uninstall immediately.
  4. Compare the package details. On Android, check the app's developer name and version in your phone's app info. Modified APKs often show odd developer names, wrong version numbers, or ask you to disable Play Protect – disabling security is itself a red flag.
  5. Test the login flow. If an app accepts any password or skips OTP verification, it may be a phishing shell harvesting whatever you type. Genuine apps validate properly.
  6. Never log in through links sent via WhatsApp, Telegram DMs or SMS. Genuine services do not send login links by chat message. Navigate to the official site yourself.

Follow this checklist before every first login on any platform, and re-verify after every app update from outside the Play Store.

Before installing anything: confirm the source, the exact domain and the developer name. Our complete platform guide on goldgo.co explains the official download-source policy in detail.

Telegram & WhatsApp Scam Groups – The Full Playbook

Because trading communities live on Telegram, scammers flood it with impersonation groups. Recognise the playbook:

  • Admin DMs first: A real admin never messages you first. Unsolicited DMs from "admins" offering help, bonuses or "account recovery" are scammers. Block and report inside the app.
  • "Verification fee" or "unlock" demands: Anyone asking for a small payment to "verify your account", "release your withdrawal" or "activate your bonus" is running advance-fee fraud. Fees to receive your own money do not exist.
  • Fake profit screenshots and paid actors: Groups posting endless "member earnings" screenshots use edited images and shills who post fake wins. Ask yourself: why would a real business need to convince strangers of guaranteed profit in a private group?
  • Lookalike names and logos: Scam groups copy names, logos and even pinned messages. Only trust the channel linked from the official website – never one you found by searching the app's name.
  • "Investment managers": A stranger offering to "trade for you" or "manage your wallet" will take the money and disappear. Never hand account access or funds to any individual.

Report impersonation groups directly to Telegram (@notoscam and the in-app "Report" option) and leave immediately.

Account Security – Lock Down Your Digital Life

Your trading or wallet account is only as safe as the weakest credential around it. Apply these in order of impact:

  • Unique password per service: Credential-stuffing attacks reuse passwords leaked from one breach against every other site. A password reused anywhere is effectively public. Use a password manager and generate a unique 16+ character password per service.
  • Strong passphrase method: Prefer a long passphrase (three or more unrelated words with numbers/symbols) over a short complex one – length beats symbol-swapping.
  • Guard the OTP channel: Your SIM is the key to every OTP. Enable a SIM PIN, and set a SIM-change lock with your carrier so a swapped SIM cannot silently receive your codes.
  • Phone lock screen: Use a 6+ digit PIN or biometric lock with auto-lock under one minute. Disable OTP message previews on the lock screen.
  • Never store credentials in chat apps: Passwords and UPI PINs typed into notes, chats or email sync to the cloud and leak in account takeovers.
  • Separate email for financial accounts: Keep the email tied to financial apps distinct from your social/shopping email, so one phishing email cannot cascade.
  • Update relentlessly: Install OS and app updates promptly – most mobile malware exploits known, already-patched vulnerabilities.
Repeat after us: No support agent, admin, bank officer or platform employee will EVER ask for your OTP, password, UPI PIN or CVV. Whoever asks, by call, chat, SMS or email, is a fraudster. End the conversation and report it.

P2P Payment Verification – The Non-Negotiable Checklist

Every P2P loss traces back to one skipped verification. Run this exact sequence before releasing tokens or shipping anything of value:

CheckWhat "Pass" Looks LikeWhat "Fail" Looks Like
Funds visible in YOUR bank/UPI appAmount shows as credited, with sender name and UPI referenceOnly a screenshot, SMS from unknown number, or "pending" status
Exact amount matches the orderEvery rupee and paisa matches, including decimalsAmount is short, or slightly higher (overpayment setup)
Sender identity matches buyer profileSender name/UPI ID matches the account in the platformPayment from a stranger's name or third-party account (mule account)
Transaction status is settled"Success"/"Credited" in your statement, not "Pending""Pending", "Processing", or funds that later disappear (cheque/reversal tricks)
No pressure signalsBuyer waits calmly for you to verifyRushed messages, threats, "my other buyer is waiting", emotional pressure

If even one row fails, do not release. Raise a dispute in the platform and wait. A genuine buyer loses nothing by waiting; only a scammer needs you to hurry.

For the platform-specific buy/sell flow, see the trading walkthrough on goldgo.co.

If You Have Been Scammed – Minute-by-Minute Action Plan

Speed matters enormously in financial fraud. Money that is reported within the first hours has a real chance of being frozen before it is layered through mule accounts. Do this immediately, in order:

  1. Stop all contact with the scammer and do not pay any "recovery fee" – secondary scams targeting victims are extremely common.
  2. Call your bank's fraud helpline (number from the official bank website or the back of your card) and request an immediate block/hold on the transaction. Ask for a complaint reference number.
  3. Dial 1930 – India's national cybercrime helpline – and register the complaint verbally, then confirm it online.
  4. File at cybercrime.gov.in (National Cyber Crime Reporting Portal) with full details: transaction IDs, UTR/reference numbers, timestamps, screenshots, chat history and the fraudster's numbers/UPI IDs. Preserve everything – do not delete chats.
  5. Secure your accounts: change passwords on the affected platform, your email and your bank apps; log out all sessions; enable every available security option; revoke app permissions on your phone.
  6. Scan your device with updated mobile security software if you installed any unknown app, and consider a factory reset if remote-access software was ever installed.
  7. Inform the platform's official support through the in-app channel so they can act on the offending account.
  8. Follow up: keep your complaint reference handy and check status on the portal. Banks and cyber units can freeze mule accounts, but only if the complaint exists.
Reality check: recovery is never guaranteed. The complaint reference and bank escalation are your genuine recovery channels. Anyone who guarantees fund recovery in exchange for a fee is running a second scam.

Reporting Channels in India – Official Reference

  • Cybercrime Helpline 1930: National helpline for immediate reporting of online financial fraud. Call as early as possible after the incident.
  • cybercrime.gov.in: The National Cyber Crime Reporting Portal, where you file a detailed online complaint with evidence. Choose the "financial fraud" category.
  • Your bank: The official fraud/customer-care number from your bank's website or card. Request transaction blocking and a written complaint reference.
  • Chakshu Portal (sancharsaathi.gov.in): Report fraudulent calls, SMS and WhatsApp numbers used for scams, so numbers get flagged and disconnected.
  • Telegram: Use the in-app "Report" on scam accounts/groups and report impersonations to @notoscam.
  • Local police: For substantial losses, file an FIR at your local police station; cyber cells handle digital-evidence cases.

Keep copies of every acknowledgement number. Documentation is what converts a complaint into an actionable case.

Daily Safety Habits – The 60-Second Routine

Security is a habit, not a one-time setup. Build this micro-routine into every trading day:

  • Before trading: confirm you are on the official site or official app (domain check), confirm your UPI app shows your real bank, and confirm the counterparty profile.
  • During a trade: verify payment only in your own bank app; never act on screenshots, calls or chat claims.
  • After a trade: review your wallet/bank statement the same day so unauthorised activity is caught within the dispute window.
  • Weekly: update apps and OS, review installed apps and permissions, and delete anything you do not recognise.
  • Monthly: rotate the password on your most important financial accounts and review login/session history where available.

Safety Myths That Cost People Money

  • "HTTPS means the site is safe." It only means encrypted transport. Scam sites have HTTPS too. Identity of the operator is what matters.
  • "The app came from an APK forwarded by a friend." Your friend may have been fooled first. Modified APKs are the number-one mobile credential thief. Use official distribution only.
  • "A verified payment screenshot proves payment." Screenshots are edited in seconds. Your bank statement is the only proof.
  • "Small KYC fee is normal for withdrawals." No legitimate platform charges a fee to give you your own money. "Withdrawal fees" demanded upfront are advance-fee fraud.
  • "The admin contacted me, so it must be official." Genuine admins do not cold-DM users. First-contact is a scam marker, not an honour.
  • "Guaranteed returns exist if you find the right platform." Guaranteed fixed returns in any traded asset are a structural impossibility – that promise alone defines the scam.

Conclusion – Your Seven Golden Rules

  • 1. Never share OTP, password, UPI PIN or CVV – with anyone, for any reason.
  • 2. Money received never requires your PIN. Money sent always does. Know the difference.
  • 3. Verify every payment in your own bank/UPI app – never in a screenshot.
  • 4. Download apps and take support numbers only from official websites such as goldgo.co.
  • 5. Refuse urgency. Any demand for instant action is a manipulation signal.
  • 6. If scammed: block, call your bank, dial 1930, and file at cybercrime.gov.in within hours.
  • 7. Trade only with money you can afford to lose, and treat every "guaranteed profit" as a confession of fraud.

For platform-specific steps – registration, login, wallet use and P2P trading – continue with the complete guide on goldgo.co, and stay updated through the official Telegram channel linked there.

User Safety FAQs

01 Someone is asking for my OTP to "verify my account". What should I do?

Refuse immediately and end contact. No genuine platform, bank or support agent ever needs your OTP, password or UPI PIN. Anyone requesting these is a fraudster. Report the account or number through official channels.

02 A buyer sent a payment screenshot but the money is not in my bank app. Should I release the tokens?

No. The only valid proof of payment is the credit visible in your own bank or UPI app. Screenshots can be edited or generated from failed transactions. Wait until funds are visibly settled, or raise a dispute.

03 Do I need to enter my UPI PIN to receive money?

Never. Entering a UPI PIN is required only to send money. If any "collect request" to receive payment asks for your PIN, it is an attempt to debit your account. Decline and report it.

04 A "support agent" wants me to install a remote-access app to fix a problem. Is that safe?

No. Screen-sharing and remote-access apps let a stranger read your OTPs and operate your device. No legitimate service requires remote access to your phone. Refuse, uninstall if already installed, and report the contact.

05 How do I know a website is the official one and not a clone?

Type the official domain manually or use a saved bookmark, check the exact spelling character by character, and never log in via links received in chats or SMS. Remember that HTTPS alone does not prove authenticity.

06 I lost money to a UPI scam. What is the very first thing to do?

Call your bank's official fraud helpline immediately to request a transaction hold, then dial 1930 and file a complaint at cybercrime.gov.in with all transaction references, screenshots and chat evidence. Speed in the first hours is critical.

07 Someone offering to "recover my lost money" for a fee contacted me. Is this real?

No. Fee-based "recovery agents" targeting fraud victims are a second scam. Recovery happens only through your bank, the 1930 helpline and cybercrime.gov.in – all free of charge.

08 Is a "guaranteed daily profit" offer ever legitimate?

No. No traded asset can offer guaranteed fixed returns. Guaranteed-profit promises are the defining feature of investment fraud and should be treated as an immediate exit signal.