Use only cryptotogift.com and payment details returned by the live OxaPay session. Never send to an address shown outside that session, and never share a wallet seed phrase or private key.
Blockchain transfers are generally irreversible. A wrong network, asset or amount can delay or lose funds. Secure email links expire; support should never request remote wallet access.
Payment credentials and the OxaPay merchant key belong only in the server environment. The browser receives a live payment session, never the secret. Incoming callbacks must use HTTPS, pass OxaPay signature verification and correspond to the expected order before a status changes. A detected or paying event is not fulfillment approval; only a verified final paid state enters manual processing.
Customers should open cryptotogift.com directly, inspect the complete payment address, network and expiry, and distrust unsolicited support messages. Never disclose a wallet recovery phrase, private key, passwordless sign-in link or delivered gift code. Suspected compromise should be reported with the USV reference, time and transaction ID; sensitive wallet secrets and full gift codes must be redacted. Security events are timestamped and reviewed before any manual release of digital value to an order.