Your account holds real money
That makes it a target. Nothing here is exotic - reward-site accounts are almost never lost to clever hacking, they are lost because somebody was persuaded to hand over access. Every scam below relies on that.
The console code scam (Self-XSS)
Somebody - a friend, a stranger in chat, someone with an admin-looking avatar - tells you to press F12, open the browser console, and paste a block of code that will "unlock" something, "hack coins" or "enable a hidden feature".
Never do this. The code runs with your logged-in session and can send your session token straight to the attacker. From their side it looks like you logged in yourself. There is no code that gives you free coins, and no legitimate reason anybody would ever ask you to paste anything into a console.
The one rule that covers this entirely. We will never ask you to paste code, run a script, install software or share your screen. Anyone who does is not from Shark Earnings, whatever their name or avatar says.
The fake admin
An account with a similar name and the same avatar messages you privately, usually within minutes of you posting a problem in a public channel. They offer to "verify your account", "release your held balance" or "fix your withdrawal" - and then ask for your password, a login link, or a reward code.
Real staff behave differently in three checkable ways:
- They contact you through the on-site ticket system or from an address ending in @sharkearnings.com. Nothing else counts.
- They never ask for your password. Support can already see everything they need without it.
- They do not open the conversation with a private message offering to fix something you did not raise with them.
If somebody claiming to be staff messages you first, verify through the official support route before replying to anything.
Lookalike domains
Phishing pages copy the login screen exactly and sit on an address that reads almost right - an extra word, a different ending, a hyphen. The page works, accepts your password, and forwards you to the real site so nothing seems wrong.
Check the address bar before typing a password, every time. The only domain that is ours is sharkearnings.com. Bookmark it and use the bookmark instead of following links out of emails or chat messages.
Cookies, tokens and "just send me a screenshot"
A session cookie is as good as your password, and in some ways better - it can skip the login screen entirely. So treat these as equivalent to your password and never share them:
- Screenshots of your browser storage or developer tools
- Any long token string, however it is described
- Password reset links from your email
- Screen sharing while logged in
The habits that actually matter
| Do this | Because |
|---|---|
| A unique password, used nowhere else | Most account takeovers are credentials leaked from an unrelated site being tried here |
| Keep your registered email working and secure | Whoever controls that email can reset your password - it is the real key to the account |
| Log out on shared or public computers | An open session needs no password at all |
| Check your transaction history occasionally | An unexplained withdrawal is the first visible sign something is wrong |
| Never accept help that requires access | No genuine fix on this platform needs your password or your screen |
If you think you have been compromised. Change your password immediately, then change the password on your email account as well, then contact support. Do it in that order - resetting the site password is pointless if somebody still controls the inbox that receives the reset link.
One thing that is not a security problem
A balance that dropped on its own is almost never a hack. Far more often it is a partner reversing a conversion they had already paid for. Before assuming the worst, read why your balance decreased and what a chargeback is.
Related reading: the community chat rules, which exist largely to keep these approaches out of public channels, and how your data is protected for what we hold on our side.

