Why "just change the password" is not enough
Most platforms let the original account creator recover the account through a secondary channel: a recovery email, a phone number, backup 2FA codes, a trusted device, or (on YouTube) the underlying Google account's recovery options. Changing the password alone leaves every one of those channels open. A determined seller can reclaim the account days later and disappear with both the payout and the asset.
A correct handover severs every recovery path back to the seller. The checklist below is what the escrow admin verifies before releasing funds.
Seller's pre-handover checklist
- Log out of every active session. Most platforms have a "log out of all devices" option in security settings. Use it.
- Remove your personal recovery email and phone. If the platform will not let you delete them entirely, replace them with placeholders you will provide to the buyer.
- Disable your existing 2FA (authenticator app or SMS). The buyer will re-enable it with their own.
- Revoke third-party app permissions — anything you connected via OAuth (Zapier, Buffer, Later, gaming launchers, etc.).
- Print or export any 2FA backup codes and delete them from your own storage. Hand them to the buyer.
- Prepare a written credential sheet: username, current password, recovery email + its password, any linked accounts.
The handover itself
Once the escrow admin confirms the buyer's deposit, share credentials on WhatsApp only, never in a group chat or a comment thread. Send them as a single message so the buyer can screenshot and archive it. Then stop touching the account — every extra login you make from your device increases the chance the platform flags a suspicious session on the buyer.
Buyer's first 30 minutes (the lockdown)
- Log in from a clean browser profile or private window. This starts a fresh session tied to your device.
- Change the password to a long, unique one generated by a password manager.
- Replace the recovery email with an inbox you fully control. If the platform requires re-verification, complete it before doing anything else.
- Replace the recovery phone number.
- Enable 2FA with your own authenticator app (Authy, 1Password, Google Authenticator). Save the backup codes offline.
- Log out of all other sessions in the security settings. This kicks the previous owner off any device they missed.
- Revoke every third-party app authorisation and re-add only what you actually use.
- Update the profile email shown in public settings if it was the seller's personal address.
Platform-specific gotchas
- YouTube / Google: the channel is owned by a Google account. Move the channel to a Brand Account first, then transfer the Brand Account to the buyer's Google account via Channel Settings → Managers. Never share the seller's Google password — that account controls Gmail, Drive, and everything else.
- Instagram / Facebook: unlink Facebook if it was connected to the seller's personal profile. Change the Meta Business Suite admin. Remove the seller's device from Accounts Center.
- TikTok: disconnect any linked phone number and re-verify with the buyer's number. Check "Linked Accounts" for shadow-linked profiles.
- Gaming accounts (Steam, Valorant, League, Supercell): the linked email is usually the master key. Change it, verify from the new inbox, then enable the platform's authenticator. Some titles enforce a 7-day trade-lock after an email change — factor this into the trade timeline.
- Discord servers being transferred: transfer ownership from Server Settings, then have the seller leave the server. Removing them before transfer deletes the ownership record.
Common handover mistakes that void escrow protection
- Confirming "trade complete" to the admin before actually resetting recovery email and 2FA. Once funds are released, the admin cannot reverse a later account reclaim.
- Buying an account from a phone that already has the seller's other accounts logged in — the platform may treat this as a suspicious account merge and lock everything.
- Reusing an old password the seller might guess. Always generate a new one.
- Skipping the "log out of all sessions" step. This is the single most-forgotten action.
A safe handover, summarised in one sentence
Before you confirm the trade to the admin, ask yourself: if the seller wanted to steal this account back tomorrow, what would still work in their favour? If the answer is "nothing" — no recovery email, no phone, no active session, no 2FA they control, no linked apps — you have handed over safely.