PECPool has improved account security with stronger two-factor authentication workflows, session controls, wallet confirmation protections, security logging, and additional safeguards for sensitive operations.
PECPool has introduced additional account security and session-control improvements to better protect user accounts, wallet information, API access, and sensitive operations.
The latest security updates focus on reducing unauthorized access risk while maintaining a practical login and account-management experience.
Two-Factor Authentication
Users can enable two-factor authentication to add an additional verification step to their PECPool account.
Two-factor authentication may be required for sensitive operations such as:
- Manual payout requests
- Transfers to external wallet addresses
- Security-related account changes
- Other high-risk operations identified by PECPool
Users are strongly encouraged to enable two-factor authentication even when it is not mandatory.
Email Verification and Security Codes
Certain security operations may require a verification code sent to the registered email address.
This helps confirm that the person performing the operation has access to both the PECPool account and the registered email account.
Improved Session Management
PECPool session controls help users and support personnel respond to suspicious or unauthorized account activity.
Security measures may include:
- Reviewing active or recent login activity
- Ending existing account sessions
- Requiring a new login after sensitive changes
- Applying temporary restrictions when suspicious activity is detected
- Recording relevant security and login information
Wallet Address Protection
Bitcoin wallet addresses must be confirmed before they can be used for eligible payouts.
Additional security checks may apply after a wallet address is created or changed. These controls help reduce the risk of unauthorized payouts following account compromise.
API Security
PECPool API integrations use separate API keys and secrets with HMAC request signing. API credentials can be restricted or revoked when suspicious activity or credential exposure is detected.
Security Logging
PECPool records relevant account, session, login, wallet, and sensitive-operation activity for security monitoring, troubleshooting, and abuse prevention.
User Security Responsibilities
Users should:
- Use a strong and unique PECPool password
- Protect the registered email account
- Enable two-factor authentication
- Never share authentication codes
- Review wallet addresses carefully before confirmation
- Protect API keys and secrets
- Sign out from devices they no longer use
PECPool will never ask users to provide passwords, private keys, seed phrases, or two-factor authentication codes through unofficial websites or unsolicited private messages.
These improvements are part of PECPool's continuing work to provide secure account access and protect sensitive mining and payout operations.