OTP, PIN or Password? What You Should Never Send in a 918Kiss Chat
- Poh Lee Ong
- 11 minutes ago
- 6 min read
Quick question: of your OTP, your PIN, and your password — which one is safe to send in a chat message? Have a guess before you read on.
The answer: none of them. Not one. Ever. If that surprises you, good — this is exactly the knowledge that protects you from some of the most common scams around. Let's sort out what you must never send, what's actually fine to share, and why the difference matters so much. Let's play.

First, the one principle that ties it all together
Before we sort anything, here's the idea that makes everything click.
Your OTP, your PIN, and your password have something crucial in common: they're all secrets that prove you're you, or authorise actions on your account. They're the keys — to your account, and to your money. And keys have one rule: you don't hand them to other people. Anyone who has your keys can get in, or act as you. That's the whole principle. These three are keys, so they're never to be sent to anyone.
Hold that as we sort each one. And notice the pattern: it won't matter who's asking or why — because you never send a key to a person, full stop.
🚫 OTP — never send it
Let's sort the first key: the OTP.
An OTP — a one-time passcode or verification code — is a temporary code sent to you to verify a login or an action. It's a security barrier, designed so that only you, with access to your own code, can complete something. So sending your OTP to someone hands them the power to complete an action on your account — a login, a withdrawal, a change to your details.
Verdict: 🚫 Never send it. Legitimate support and legitimate systems never ask you to share an OTP with a person. It's yours to enter into the genuine app or site yourself — never to read out, forward, or type into a chat. Anyone asking you to share an OTP is trying to get into your account.
🚫 PIN — never send it
Sort the second key: the PIN.
A PIN — a personal identification number — is a secret number used to authorise access or transactions. Like the others, it exists precisely so that only you can authorise things. Share it, and you've handed someone the ability to authorise actions as you.
Verdict: 🚫 Never send it. A PIN is a secret, and secrets don't go in chat messages. No legitimate party needs you to send your PIN to them. It stays yours, entered by you into the genuine system only.
🚫 Password — never send it
Sort the third key: the password.
Your password is the secret that logs you into your account. It is, quite literally, the key to your account. Send it to someone, and they can log in as you.
Verdict: 🚫 Never send it. Legitimate support never needs your password — there's no genuine scenario where you type your password into a chat or hand it to a person. You enter it into the real login screen yourself, and nowhere else, ever.
The key distinction: enter it yourself, never send it
Here's a subtle but vital point that ties the three verdicts together.
There's a world of difference between entering a credential into the genuine system yourself, and sending it to a person. Typing your password into the real, official login screen? That's how it's meant to be used. Typing your password into a chat message, or reading your OTP out to someone, or sharing your PIN? Never — that's handing over your key.
So the rule isn't "never use your credentials" — of course you use them, by entering
them yourself into the genuine app or site. The rule is never send them to anyone, in a chat or otherwise. Enter yourself: fine. Send to a person: never. Keep that line crystal clear and you're protected.
✅ So what IS okay to share?
Now the useful flip side, because not everything is off-limits — and knowing the difference helps.
If genuine support (that you contacted, through official channels) needs to identify your account, there's information that's fine to share — the non-secret kind that identifies you without granting access. Things like your username, the email or phone number registered to the account, or a transaction reference. [confirm: what identifying details 918Kiss's official support legitimately uses, and the official support channel] These identify you; they don't unlock your account.
Verdict: ✅ Shareable — through official channels. The distinction is simple: information that identifies you (username, account email/phone, a reference) can be shared with genuine official support; secrets that authenticate you or authorise actions (OTP, PIN, password) never can. Identity: shareable. Keys: never.
Why do scammers ask for these anyway?
Worth understanding, because the pretexts can sound convincing.
Scammers ask for your OTP, PIN, or password under all sorts of plausible-sounding reasons: "to verify you," "to fix your account," "to process your withdrawal," "for security." Here's the thing — the reason doesn't matter. There is no legitimate reason to send these to a person, so no pretext, however official or helpful it sounds, changes the answer. A convincing story asking for your key is still someone asking for your key.
So don't evaluate the reason — just apply the rule. Anyone asking you to send an OTP, PIN, or password is not to be complied with, regardless of the story attached. The request itself is the red flag.
🚩 A special word on the OTP trick
One scam pattern deserves its own mention, because it's so common.
If someone asks you to "read out," "forward," or "confirm" a code that just arrived on your phone — stop. Often, that code arrived because the scammer is trying to log into your account or authorise something right now, and they need your code to complete it. So being asked to share a code you just received isn't verification — it's the final step of someone breaking in, and you'd be handing them the key at the exact moment they need it.
The rule: a code that arrives on your phone is for you to enter yourself, never to give to anyone who asks — especially not someone who's rushing you to share it.
🏁 The verdict
Let's total it up:
🚫 Never send in a chat (or anywhere, to anyone): your OTP, your PIN, your password — the secret keys that authenticate you and authorise actions. ✅ Fine to share with genuine official support you contacted: non-secret identifying info like your username, account email/phone, or a transaction reference.
The rule, simply: you enter your keys yourself into the genuine system, and you never send them to a person — no matter who's asking or why. Master that one line, and you've protected yourself from a whole category of scams.
And keep the bigger picture in view too: play is entertainment. 🎯 Never income, never a plan, never a fix for a money worry. Guarding your keys — never sending your OTP, PIN, or password to anyone — is simply part of keeping a bit of fun genuinely fun and safe. Set your limits with a clear head, use only legitimate sources and official channels (that you reach yourself), and treat any winnings as a pleasant surprise. Online gambling laws vary by state in Malaysia, so confirm what's permitted where you live before you play. And if play ever stops feeling like a free, relaxed choice, stepping back and reaching out for support is the strongest move there is.
Enter your keys yourself, never send them to anyone — and you hold onto exactly what keeps your account yours.
Quick questions
Should I ever send my OTP, PIN, or password in a 918Kiss chat?
No — never, not one of them, no matter who's asking or why. All three are secret keys that authenticate you or authorise actions on your account, so sending them to a person hands over access to your account or money. Legitimate support never needs you to send these; you enter them into the genuine app or site yourself.
What's the difference between entering a credential and sending it?
Entering your password into the real, official login screen yourself is how it's meant to be used. Sending it to a person in a chat, or reading out your OTP, or sharing your PIN, means handing over your key. The rule isn't never to use your credentials — it's never to send them to anyone. Enter yourself: fine. Send to a person: never.
What information IS safe to share with support?
Non-secret information that identifies your account without unlocking it — such as your username, the email or phone number registered to the account, or a transaction reference. These identify you; they don't grant access. Share them only with genuine official support that you contacted through official channels.
Someone asked me to read out a code that just arrived — is that okay?
No, that's a major red flag. Often the code arrived because someone is trying to log into your account or authorise something right now, and they need your code to complete it. A code sent to your phone is for you to enter yourself, never to share with anyone who asks — especially someone rushing you to hand it over.
They gave a convincing reason for needing my password — does that change anything?
No. There's no legitimate reason to send your OTP, PIN, or password to a person, so no pretext — "to verify you," "to fix your account," "for security" — changes the answer. Don't evaluate the reason; just apply the rule. Anyone asking you to send a secret credential is attempting to take your account, however convincing the story.




Comments