Security
Last updated 2026-08-19
MPC will never ask for your recovery phrase, private key or password, and will never ask you to send funds to receive anything. This application is served only from app.globalmpc.tech. Everything below is how to check that for yourself.
Official addresses
Nothing else is ours. A look-alike can contain the word “globalmpc” anywhere and still belong to someone else, so compare the whole host, ending to ending.
- This applicationapp.globalmpc.tech
- Company siteglobalmpc.tech
- Telegram groupt.me/official_mpc_global
- X accountx.com/mpc_miningrwa
What MPC never asks for
Your recovery phrase, private key or keystore file
No screen in this application has a field for them, and no member of the team will ever ask for them in a message. Anyone who does is stealing your wallet, whatever name they are using.
A password
This application has no user password at all. You sign in with your wallet signature and a one-time code sent to your email address, so there is no password for anyone to ask you for.
A payment to receive your badge
Issuance is sponsored, and you are never asked to send funds to any address. Nobody from MPC will ask you to pay in order to receive, unlock or speed up anything.
Permission to spend your tokens
The only transaction this application asks for is the badge issuance, which sends no funds and grants no spending allowance. A request to approve a token, increase an allowance or transfer an asset did not come from us.
To “verify”, “sync”, “migrate” or “unlock” your wallet
These phrases have no meaning in this flow. They exist to get you to sign something that drains the wallet. There is no recovery step here and there never will be.
Anything, in a message we sent first
We do not open direct messages, and we run no surprise airdrops or giveaways. Announcements come only from the channels listed above; a message from anywhere else is not from us, even if the display name matches exactly.
What MPC does ask for
These five, in this order, are the whole of joining. Anything asked outside this list is not part of it.
Connect your wallet
This shares your public address and network only. It moves nothing and approves nothing.
Sign one message to sign in
A sign-in signature, off chain and free — it is not a transaction. The message names the domain it belongs to. If your wallet shows any domain other than app.globalmpc.tech, reject it.
Open your Telegram link, and follow on X
The community step opens two links in a new tab. The Telegram one is generated for you personally and starts our bot, which has one job and asks you for nothing — the section below sets out exactly what that step does, because it is the step most easily imitated.
Enter your email and the six-digit code
The code goes to the address you typed and is only ever entered on this site. Nobody from MPC will ask you to read it out, forward it or paste it into a chat.
Sign the badge issuance
One more signature, carried for you by a relayer, so no gas leaves your wallet. It sends no funds and grants no spending allowance.
The Telegram step, in full
This step is the easiest to imitate: the real one hands you a personal link and, on some computers, asks you to paste it into Telegram yourself.
The link is yours alone
The Telegram button asks this site for a one-time link that starts our bot. The code in it binds the first account to open it, permanently, and it expires in fifteen minutes. Treat it like a password: never forward or post it, however helpful the person asking sounds. If your computer has no Telegram app the screen offers to copy it — paste it into your own Saved Messages and tap it there, and nowhere else.
The bot’s name is not the group’s name
The personal link opens a bot, so its handle is not the group address listed above. That is expected — what makes it ours is that this site just produced the link, not the name it carries. If the bot is unavailable the button opens the group instead, which does match.
The bot only ever shows you buttons
Two presses and nothing typed: Start, which hands the code over, then Join the Community, which takes you to the group. There is no field to fill in, and it never asks for your wallet address, recovery phrase, a payment, or a code you type by hand. A bot asking for any of those is not ours, however closely the name and picture match.
A Telegram link that reached you any other way is not ours
This link is only ever produced inside this application, after you sign in, and we never send it to you. One that arrived by direct message, forwarded post, group announcement or email was not made for you.
After you join: check-in and quests
Joining happens once. These are the requests you will see every day, so they are worth recognising.
Quests send you out to read, follow or post — never to connect a wallet
A quest can only link to the hosts listed above — the allow list is enforced on our server and its core entries cannot be deleted by an administrator. Whatever it sends you to look at, the signature that credits it happens back here.
Check-ins, quests and energy are signatures, not payments
Each is one typed-data signature that a relayer submits for you, so no gas leaves your wallet. It names one of our contracts and carries your address, the relayer allowed to submit it, a one-time challenge and a deadline. It moves no tokens and grants no allowance.
Paying for it yourself is only ever offered here, after the relayer fails
When the relayer cannot carry a transaction, this application offers to let you send it yourself, and then you pay the network fee — to the network. That offer appears on the screen you are already looking at, never as a message, and never asks you to send funds to an address.
How to check you are in the right place
Our server refuses work sent from anywhere else
A copied site can imitate these screens, but sign-in, email verification and issuance are rejected unless the request comes from the official address. A clone cannot complete them against us.
Check the domain your wallet shows you
Wallets print the requesting domain on every signature and transaction. That line is written by your wallet, not by the page, so it is the one thing a fake site cannot forge. Read it every time.
https://app.globalmpc.tech/security
app.globalmpc.tech
If it already happened
If you entered your recovery phrase or private key anywhere, treat that wallet as lost. Move whatever it still holds to a wallet created fresh on a device you trust. This cannot be undone by us or by anyone else, and speed is the only thing that helps.
If you approved a transaction you do not recognise, revoke the approval from your wallet or a revocation tool, then move the assets it covered.
Then tell us at mpc@globalmpc.tech, with the address you were sent to. It will not recover your funds, but it lets us warn everyone else.
Reporting a vulnerability
Send security reports to mpc@globalmpc.tech. Include the steps to reproduce and the addresses or requests involved. We read reports in English.
We ask for coordinated disclosure: tell us first, and hold public description until the issue is fixed. Testing must stay within your own account — it must not degrade the service for other users or reach anyone else’s data.
Our machine-readable contact details are published at https://app.globalmpc.tech/.well-known/security.txt.