Skip to content

Top-up safety: how to buy without losing your account

The key rules for safely buying game top-ups: which data delivery actually needs, how to read the delivery method on a product page, and how to tell an honest service from scammers.

·4 min read

Context: why this matters

Since 2022, the market for unofficial top-up shops has grown rapidly in Russia — dozens of sites sell currency for Genshin, PUBG, Standoff and hundreds of other games. Among them are honest services, but there are also outright scammers who either take your money without delivering or hijack accounts.

If you follow a few rules, the chance of losing your account or your money is close to zero.

Rule 1: Check the delivery method on the product page

Most top-ups are delivered by UID, without logging into your account. You tell the shop "credit the currency to ID 123456789", and the supplier calls the game server's API and credits it. No password is needed anywhere in that chain, and we never ask for one on those items.

Less common is "delivery via an operator" / "by login". These are games where the publisher hasn't opened an API for direct top-ups, so the purchase is made by signing into the account. Worth keeping in mind:

  • The delivery method and the data it needs are stated on the product page — read them before paying.
  • If the data you are asked for does not match the stated delivery method, stop and check with support.
  • After a "by login" delivery it makes sense to change your password and enable 2FA.
  • Signing into an account always means trusting whoever does it, so buy those items from a shop you trust.

Rule 2: A one-time code confirms an operation — it is not a password

A one-time code (from SMS, an email or an Authenticator app) confirms one specific operation and does not reveal your password. In some games logging in has no password at all: a Supercell ID or a Yostar account opens with an email plus a code from a message — there the code simply is how delivery works.

That is why some items ask for a code at delivery time as a normal part of the process: they carry the "By UID + code" badge, and you can see it on the product page before paying.

One healthy habit is enough: a code that arrives on its own — with no order of yours and no request from the shop you ordered from — does not need to be confirmed. That is someone else's login attempt, not your delivery.

Rule 3: Pay through secure channels

Payment methods at a trustworthy shop:

  • MIR card through a certified payment gateway — the card data is processed by the bank and never reaches the shop.
  • SBP (Faster Payments) — the safest option: no card data at all, a transfer by phone number/QR.
  • YooMoney — payment via Yandex.

Suspicious methods:

  • A direct transfer to a private individual's card (no acquirer at all)
  • WebMoney, QIWI without identity verification
  • "Crypto" from wallet to wallet (no protection whatsoever)
  • "Through a Telegram bot with a QR code" without a website

Rule 4: Check the site before buying

A checklist for a new shop:

1. HTTPS — the padlock icon in the address bar. Without HTTPS, don't buy at all. 2. Legal details in the footer — the company's registered name, OGRN/INN (Russian company IDs). If they're absent, the shop doesn't legally exist. 3. Reviews on external platforms — Trustpilot, Yandex Maps and similar. On-site reviews are easy to fake. 4. Domain age — whois shows the registration date. If the domain is less than a month old, the risk goes up. 5. Legal documents — the offer agreement, refund policy, data-processing policy. These should be meaningful texts, not a "placeholder".

Rule 5: Start with a small purchase

Your first purchase at a new shop should be the smallest package. If it arrives correctly, you can raise the amounts. It's the loss of a small sum in the worst case versus the loss of a large one.

After 2-3 successful purchases you can go for bigger packages — repeat-customer protection: a shop won't risk its reputation over a single customer who has already placed several successful orders with it.

Rule 6: If something feels off — stop

Signs of a scam attempt during a purchase:

  • The data you are asked for does not match the delivery method stated on the product page
  • After payment, a demand for "extra fees" / "verification" arrives
  • They ask you to move to Telegram "for speed" instead of the on-site chat
  • The support chat suddenly goes quiet
  • "Urgent countdown promotions" appear, pressuring you to decide fast

At any of these signs — close the tab, don't pay, and check the site via 2ip.ru or Whois.

Rule 7: Enable 2FA on your game accounts

The best protection is 2FA on the account itself, so that even if someone learns your password they still can't log in. All the major games support it: Genshin (HoYoverse Account), PUBG (Krafton), Standoff 2 (via Google or email), Brawl Stars (Supercell ID).

A sensible rule: prefer delivery by UID — no account login involved — and keep 2FA via an Authenticator app on every account.

Rule 8: Keep your receipts

After payment you should have:

  • The email confirming the order from the shop
  • The bank receipt for the charge
  • A record in your account area on the shop's site

These three documents are your legal grounds for a refund if something goes wrong. A chargeback through the bank only works if you have proof that you tried to resolve the issue honestly through the shop.

Conclusion

Top-up safety isn't a hard technical task, just a matter of following simple rules:

1. The delivery method is on the product page — read it before paying 2. Only proven payment methods 3. The company's legal details in the site footer 4. A small first purchase 5. 2FA on your game accounts

If a shop says nothing about the delivery method, or asks for something other than what it stated — close the tab.

ASHOP delivers by UID by default, and no password is needed there. Where delivery needs a one-time code or an account login, the item is labeled and you can see it before paying. Ready to give it a try? Catalog →

Read also