Keeping your account secure
Security shouldn't require you to understand cryptography. These are the few things that matter most for protecting your conversations, your identity and your money on Tula.
Never share your Security PIN or verification codes
Not with a friend, not with a family member, and not with anyone claiming to be from Tula. Tula support will never ask you to disclose your full Security PIN or a one-time code inside a chat.
The basics
- Keep your Security PIN private. It is one of the controls protecting your money, not just your login.
- Don't install apps from links sent in chat. Install Tula only from an official app store.
- Be careful with device permissions. Be suspicious of anything asking for unusual access, screen sharing or remote control.
- Keep your phone locked and updated. Encryption cannot protect messages that are already being displayed on a compromised phone.
- Pay attention to security notices. If Tula flags that a contact's device or account status has changed, treat that as information worth acting on.
When someone asks you for money
The most common attack is not a stranger — it is a familiar account asking for urgent help. An attacker who takes over an account borrows trust that somebody else spent years building.
Stop and verify if a message:
- creates urgency or emotional pressure;
- asks you to send money to a different number than usual;
- asks you to ignore Tula's normal payment flow;
- asks you to ignore a security warning; or
- asks for a verification code "sent by mistake".
Verify through a channel the attacker does not control — call the person on a number you already have, or ask something only they would know. A voice call is harder to fake than a text message.
What Tula does on your behalf
When you send an integrated Tula payment from a one-to-one conversation, the recipient is resolved from the registered Tula participant in that conversation. The other person cannot silently swap the destination for a different phone number.
Tula also treats moving money as a separate authority from signing in or sending a message — so a newly introduced or security-restricted device does not automatically gain the ability to move funds. Read how that works →
If you think your account has been compromised
- Act from a device you still controlIf your original phone is still working and signed in, use it. It is your strongest proof of continuity.
- Change your Security PINAssume any credential you may have typed into a suspicious link or shared with someone is already known to an attacker.
- Review devices on your accountRemove any device you do not recognise, then re-check the list afterwards to confirm it stayed removed.
- Warn the people who might be targeted nextTell close contacts not to act on money requests from your account until you confirm it is back under your control.
- Contact TulaReport it to [email protected]. Never include your PIN or a verification code in the message.
If you lose your phone
A lost phone and a stolen account are different situations, and Tula treats them differently. Recovery is designed to combine several independent signals rather than relying on a single SMS code — so expect to be asked for more than one form of verification, particularly before financial access is fully restored. That extra friction is deliberate: it is the same friction that stops somebody else from taking over your account.
Found a security vulnerability? Report it to [email protected].