SkyHills welkomstbonus banner — 200% first-deposit match bonus up to €1

200% first-deposit match bonus up to €1

Get Bonus | PLAY NOW

SkyHills Casino — Security Guide: Password, 2FA, Recovery

Security at a Glance

SkyHills — Security & Account Protection
CasinoSkyHills — skyhillscaasino.com
LicenseCosta Rica
KSA StatusNo KSA License
Founded2024
SSL/TLS256-bit SSL, TLS 1.3
Password RequirementsMin. 8 characters
Brute-force ProtectionAccount lockout after 5 attempts
Session TimeoutAutomatic logout after inactivity
Login NotificationsEmail alert on new device login
Withdrawal NotificationsEmail + dashboard notification for every withdrawal
RNG AuditsPeriodic audits by independent third party
Transaction HistoryAccessible via dashboard, 12 months
Self-exclusion24 hours / 1 week / 1 month / 6 weeks / permanent
Anti-phishing PolicyPasswords are never requested via email
Support OrganizationsGamCare, Gambling Therapy
Bonus TermsSee our guide →
Mobile ExperienceSee our guide →

Quick Overview: Security at SkyHills

SkyHills Casino was founded in 2024 and holds a license from Costa Rica. The platform offers an integrated sportsbook alongside the casino section and processes transactions via both crypto and traditional payment methods. The welcome bonus is 200% on the first deposit up to €1,500, with a minimum deposit of €20 and a wagering requirement of 35x (deposit + bonus) within 7 days.

On the security front, the infrastructure relies on TLS 1.3 transport encryption for all connections between your browser and our servers. Account security is implemented in layers: in addition to a strong password, we offer two-factor authentication (2FA) via TOTP apps. KYC verification is mandatory before the first withdrawal. For mobile use, a responsive mobile site is available; no iOS or Android app is available.

The sections below cover each security topic in technical depth: exact steps, decision trees, comparison tables and checklists. Bonuses and payments are only covered at a high level here — for details, please refer to the bonus page.

Key Security Facts: TLS 1.3 · 2FA via TOTP · Mandatory KYC before withdrawal · Costa Rica license · No KSA license

Two-Factor Authentication (2FA): Step by Step

What is TOTP and How Does It Work

TOTP stands for Time-based One-Time Password (RFC 6238). Every 30 seconds, the authenticator app on your phone generates a new 6-digit code based on a shared secret (a QR code you scan once) and the current Unix time. Our servers independently calculate the same value. If the code matches, you are logged in. The code expires after 30 seconds, making replay attacks pointless.

Because the code is generated locally on your device — without any network traffic — TOTP is more robust than SMS verification. SMS codes are vulnerable to SIM swapping; TOTP codes are not.

Enabling 2FA: Exact Steps

  1. Log in via SkyHills login with your existing password.
  2. Go to Account Settings → Security → Two-Factor Authentication.
  3. Click Enable 2FA. The page will display a QR code and a text-based secret key (26 characters, base32-encoded).
  4. Open your authenticator app (see comparison table below) and scan the QR code, or enter the text key manually.
  5. The app will immediately display a 6-digit code. Enter this in the confirmation field. You have up to 30 seconds; wait for the next cycle if needed.
  6. Save your backup codes. We display ten single-use codes of 12 characters each. Store these offline — in a password manager or printed and kept in a safe.
  7. Click Confirm and Activate. From this point on, 2FA is required for every new session.

TOTP App Comparison

Not every authenticator app offers the same backup and recovery capabilities. The table below compares the three most widely used options on the points most relevant for account recovery.

App Cloud Backup Multiple Devices Export Feature Open Source Recommended For
Google Authenticator Yes (Google account, v6.0+) Yes (via backup) QR export to new device No Users already in the Google ecosystem
Authy Yes (Authy cloud, encrypted) Yes (up to 5 devices) No (intentionally restricted) No Users who use multiple devices
Microsoft Authenticator Yes (Microsoft account) Yes (via backup) Limited (backup/restore) No Users in a Microsoft 365 environment
Aegis (Android) No (local only) No (manual export) Yes (encrypted JSON) Yes Users who prioritize control over their own data
Raivo (iOS) Yes (iCloud, encrypted) Yes (iCloud devices) Yes (encrypted ZIP) Yes iOS users who prefer open source

Lost Your Phone: What Now

If you have lost your phone and cannot access your authenticator app, there are two routes. Route 1: use one of the ten backup codes you saved when activating 2FA. Each code works only once. Route 2: contact our customer support and go through the identity verification process — you will need a government-issued ID that matches your KYC documents. See the account recovery section for the full decision tree.

Please note: We will never send a 2FA code via email or SMS as an alternative to the TOTP app. Any message claiming to do so is a phishing attempt.

Password Policy and Password Management

Minimum Password Requirements

Our system will only accept a password if it meets all of the following criteria:

  • At least 12 characters long
  • At least one uppercase letter (A–Z)
  • At least one lowercase letter (a–z)
  • At least one digit (0–9)
  • At least one special character (!@#$%^&* and similar)
  • No three or more consecutive identical characters (e.g., "aaa")
  • Not identical to your email address or username
  • Not present in our list of 100,000 known compromised passwords (based on the Have I Been Pwned dataset)

Common Mistakes

Adding a capital letter at the beginning and an exclamation mark at the end of a recognizable word ("Casino1!") technically meets the minimum requirements, but is in practice easily guessable for an attacker running dictionary attacks. A password like "Blue3Bicycle!Moon" — four random words with variation — already has an entropy of over 50 bits at 12 characters, making brute-force attacks with standard hardware practically infeasible.

Reusing the same password across multiple platforms is the single greatest security risk when it comes to account compromise. If another platform suffers a data breach and your password is exposed, automated scripts will immediately attempt that password on hundreds of other services — including online casinos.

Recommended Password Managers

We recommend using a password manager to generate and store unique passwords. Bitwarden (open source, free basic version), 1Password and KeePassXC (fully local) are popular choices. A password manager generates random strings of 20+ characters per service, making password reuse structurally impossible.

Do not store your SkyHills password in your browser's built-in password manager if that browser is synced to an account whose security you do not fully control. A standalone password manager with its own master password provides an additional layer of isolation.

Account Recovery: Decision Tree for Five Scenarios

Below you will find a structured decision tree for the five most common situations where you cannot access your account. Follow the steps in order; do not skip any step.

Account Recovery Decision Tree

Scenario First Step Second Step Third Step Expected Processing Time
1. Forgot Password Click "Forgot Password" on the login page Check your email inbox for the reset link (valid for 15 minutes) Set a new password that meets the policy requirements 2–5 minutes
2. Account Locked (too many failed attempts) Wait 30 minutes; the lock is lifted automatically Log in with the correct password + 2FA code If password is unknown: see scenario 1 30-minute wait
3. 2FA Device Lost, Backup Codes Available Log in with your password; enter a backup code on the 2FA screen Go to Security → 2FA and disable the old 2FA Link a new device and re-enable 2FA 5–10 minutes
4. 2FA Device Lost, No Backup Codes Contact our customer support Provide a government-issued ID matching your KYC documents After verification, our team manually disables 2FA; you then link a new device 1–3 business days
5. Account Compromised (unauthorized login) Use "Forgot Password" to immediately block the attacker's access Contact our customer support immediately and report the incident Our security team freezes withdrawals, reviews session logs and sends an incident report Initial response within 4 hours; full investigation 2–5 business days
6. Session Expired (automatically logged out) Sessions expire after 60 minutes of inactivity or when the browser is closed Log in again via SkyHills login with password + 2FA Not applicable Immediate
7. Email Address No Longer Accessible Contact customer support with your account name and KYC documents Our team verifies your identity via document + liveness check After verification, the email address is updated; you receive a confirmation at the new address 2–4 business days

Exact Flow for an Account Lockout

When you enter an incorrect password five times in a row, our system records a timestamp and blocks further login attempts for 30 minutes. You will automatically receive an email notification at your registered address showing the time of the lockout and the IP address of the last attempt. If you did not make that attempt yourself, treat this as scenario 5 above.

After 30 minutes, the lockout is automatically lifted without any customer support intervention. There is no button to speed up the waiting period. This is a deliberate security measure to slow down automated attacks.

Encryption and Data Protection

Transport Layer Security (TLS)

All connections between your browser and our servers use TLS 1.3. TLS 1.0 and 1.1 are disabled on our servers; TLS 1.2 is available as a fallback for older devices but is not prioritized. The certificate is issued by a publicly trusted CA and has a validity of 90 days with automatic renewal.

You can verify the connection security yourself: click the padlock icon in your browser's address bar and check that the certificate is valid for the domain skyhillscaasino.com. A valid TLS connection effectively eliminates man-in-the-middle attacks over the network.

Data Storage

Passwords are never stored in plain text. We use bcrypt with a work factor of 12 for password hashing. This means that even in the hypothetical event of a database breach, the passwords would not be directly usable by an attacker — cracking a single bcrypt hash with work factor 12 takes several seconds per attempt on standard hardware.

Payment details (card numbers, banking details) are not stored on our servers. Transactions are processed through certified payment processors that maintain PCI DSS Level 1 compliance. We receive only a transaction ID and a masked reference.

What Data We Collect

We collect: name, date of birth, address, email address, phone number, IP address logs (retained for up to 12 months for fraud investigation), session data, gaming history and deposit/withdrawal history. KYC documents (proof of identity, proof of address) are stored encrypted and are accessible only to our compliance team.

8-Point Security Audit: Check Your Own Account

  1. 2FA enabled? Go to Account Settings → Security and verify that 2FA is active.
  2. Backup codes saved? Check that you have stored your ten backup codes offline.
  3. Password unique? Do not use this password anywhere else. Check via haveibeenpwned.com whether your email address appears in a known breach.
  4. Email address current? Log in and verify that the registered email address is still active and exclusively yours.
  5. Check active sessions? Go to Security → Active Sessions. Do you recognize all devices and locations? If not, log out of all sessions and change your password.
  6. KYC complete? A fully verified account blocks withdrawals to unverified methods, providing an additional layer of protection in the event of account compromise.
  7. Notifications enabled? Make sure email notifications are enabled for login attempts, password changes and withdrawals.
  8. Recovery details up to date? Verify that your phone number and recovery email address are correct and still belong to you.

KYC Verification: Documents, Processing Times and Rejections

Why KYC Is Mandatory

KYC (Know Your Customer) is a legal requirement under anti-money laundering regulations that applies to Costa Rica-licensed operators as well. Practically speaking, KYC protects you: a withdrawal to an unverified account is blocked, which prevents an attacker from transferring your balance to an unknown account.

Accepted Documents

Document Type Purpose Requirements
Passport Proof of identity Valid, both sides, all four corners visible, no flash glare
National identity card (ID card) Proof of identity Valid, front and back, legible MRZ line
Driver's license (with photo) Proof of identity (secondary) Valid, both sides, name and date of birth legible
Bank statement Proof of address No more than 3 months old, name + address + bank logo visible, not cropped
Utility bill Proof of address No more than 3 months old, name + address + supplier name visible
Selfie with ID document Liveness check (if requested) Face and ID document fully visible in one photo, no filters

Processing Times

During periods of high request volumes, this can take up to 72 hours. You will receive an email confirmation once verification is complete or when additional documents are requested.

What Happens When a Document Is Rejected

If a document is rejected, you will receive an email with the specific reason: illegible text, expired document, name mismatch, or document is cropped. You may resubmit the document. There is no limit on the number of resubmissions, but each new submission starts a new processing period of 24–48 hours. Make sure photos are taken in good lighting, without flash and without any deliberate editing.

Withdrawals are blocked until KYC is fully completed. Deposits and gameplay are possible without full KYC, but we recommend completing verification immediately after registering with SkyHills to avoid delays when withdrawing.

Phishing and Fraud Protection

How to Recognize Our Official Site

The only official domain for this platform is skyhillscaasino.com. Always check the full URL in the address bar before logging in or entering payment details. Phishing domains use variants such as "skyhills-casino.com", "skyhi11s.com" or subdomains like "bonus.skyhillscasino.net" — these are not official domains.

What We Will Never Ask via Email or Chat

  • Your full password (we never ask for a password — only you know it)
  • Your 2FA code outside of the login process
  • Credit card details via email or chat
  • Payment of a "verification fee" or "processing fee" before a withdrawal
  • Access to your device via remote desktop software
  • Your PIN or CVV code

Common Attack Patterns

Bonus phishing: An email or message claims you have won an exclusive bonus and asks you to log in via an external link. The link leads to a fake login page that captures your credentials. Always verify the sender and navigate to the site manually rather than clicking links.

Customer support impersonation: An attacker contacts you via social media or a chat platform, posing as a SkyHills Casino employee. Our customer support team never proactively reaches out via external social media channels and never asks for login credentials. If someone claims to be one of our staff members, log in yourself via the official site and contact us through the official channel to verify.

SIM swapping: An attacker convinces your mobile carrier to transfer your phone number to a new SIM card, then intercepts SMS verification codes. This is one reason why we recommend TOTP-based 2FA over SMS verification — TOTP codes cannot be intercepted via your phone number.

How to Report a Suspicious Incident

If you suspect phishing or fraud targeting your account, contact our customer support immediately via the official channel on the site. If possible, include a screenshot of the suspicious message. Our security team will document the incident and can, if necessary, preventively freeze your account while the investigation is ongoing.

Technical check: Examine the email headers of messages claiming to be from us. The "From" field must end with @skyhillscaasino.com. A "Reply-To" pointing to a different domain is a direct indicator of spoofing.

Responsible Gambling and Self-exclusion Tools

Available Limits on Our Platform

We offer the following self-management tools via Account Settings → Responsible Gambling:

Tool Description Effective From Removal Procedure
Deposit Limit Daily, weekly or monthly maximum on deposits Immediately Increase: 24-hour waiting period. Decrease: immediate.
Session Limit Maximum play time per session Immediately Increase: 24-hour waiting period. Decrease: immediate.
Loss Limits Maximum loss per day, week or month Immediately Increase: 24-hour waiting period. Decrease: immediate.
Cooling-off Period Temporary exclusion from 24 hours to 6 weeks Immediately Automatically lifted after the chosen period ends
Self-exclusion Permanent or long-term exclusion (minimum 6 months) Immediately Reactivation only after the set period + written request
Important — fair disclaimer: We are not licensed by the Netherlands Gambling Authority (KSA) and are not affiliated with CRUKS. Our own self-exclusion tools apply exclusively to this platform. For exclusion from all KSA-licensed operators simultaneously, register via cruks.kansspelautoriteit.nl.

Support Organizations

If you are concerned about your own gambling behavior or that of someone close to you, the following organizations are available:

Organization Website Phone
AGOG (Anonymous Gamblers / Family of Gamblers) agog.nl
Jellinek jellinek.nl 0900-1090
Loket Kansspel loketkansspel.nl
CRUKS (KSA-licensed operators only) cruks.kansspelautoriteit.nl

Playing from the Netherlands: What You Need to Know

SkyHills Casino NL partly targets Dutch-speaking players, but the platform does not hold a license from the Netherlands Gambling Authority (KSA). This has direct implications for your legal position and the availability of certain protective mechanisms.

Topic Situation
KSA License Not applicable — license is issued by Costa Rica
CRUKS Affiliation Not applicable — only KSA-licensed operators are affiliated with CRUKS
Own Self-exclusion Available via Account Settings → Responsible Gambling (platform-specific)
Tax on Winnings (NL) Dutch gambling tax applies to winnings above the exemption threshold. Consult the Dutch Tax Authority or a tax advisor for your personal situation.
Minimum Age 18 years — identity verification mandatory via KYC
Currency Euro (€) as primary currency; cryptocurrency also available
Local Payment Methods Specific availability not published; refer to the main page for current payment options
Consumer Protection Dutch consumer law may not apply; disputes fall under the jurisdiction of Costa Rica
Legal disclaimer: This platform is not licensed by the Netherlands Gambling Authority (KSA). It is not affiliated with CRUKS. For self-exclusion from KSA-licensed operators, you can register via cruks.kansspelautoriteit.nl. We offer our own self-exclusion tools.
Gambling can be addictive. Play responsibly. 18+.

SkyHills Bonus: Key Facts

The welcome bonus at SkyHills Casino is 200% on the first deposit up to a maximum of €1,500. The minimum deposit to activate the bonus is €20. No bonus code is required — the bonus is automatically credited on your first deposit after registering with SkyHills.

Wagering Requirement: Worked Example

The wagering requirement is 35x on the combined total of deposit and bonus. Below is a worked example using the maximum bonus:

Parameter Value
Deposit €750
Bonus amount (200% of €750) €1,500
Total wagering required (35 × (€750 + €1,500)) €78,750
Time limit 7 days from activation
Required wager per day (average) €11,250

This is a substantial wagering volume. Read the full bonus terms on the bonus page before activating the bonus. The wagering requirement also affects how quickly you can withdraw: as long as the wagering requirement has not been completed, withdrawals of bonus funds are blocked. Your own deposited funds remain withdrawable at all times, unless the bonus terms state otherwise.

Tip: If you do not wish to take on the wagering requirement, you can ask customer support to decline the bonus before you start playing. Once accepted, the terms are binding.

Conclusion: Security Status of SkyHills

The platform's security infrastructure is built on TLS 1.3, bcrypt password hashing, TOTP-based 2FA and mandatory KYC verification before withdrawal. These are solid foundational measures. Your own contribution — a unique strong password, 2FA enabled, backup codes saved and KYC completed — largely determines how well your account is actually protected.

Use the registration page to create an account and activate 2FA immediately after signing up. Consult the bonus page for the full bonus terms before making a deposit.

Gambling can be addictive. Play responsibly. 18+. This platform is not licensed by the Netherlands Gambling Authority (KSA) and is not affiliated with CRUKS. For self-exclusion from KSA-licensed operators: cruks.kansspelautoriteit.nl.

Last updated: 29 juli 2026

Frequently Asked Questions

Under what license does SkyHills Casino operate, and can I verify this myself?

SkyHills Casino operates under a Costa Rica license, which is a commonly used jurisdiction for online casinos operating internationally. While Costa Rica does not offer the same level of strict oversight as Malta or the United Kingdom, the casino commits to transparent gaming rules and fair payouts. You can find the license information in the footer of skyhillscaasino.com, so you can always verify this yourself before making a deposit.

How does SkyHills Casino protect my personal data and payment information?

SkyHills Casino uses SSL encryption (256-bit) to secure all data transfers between your browser and its servers, which is the industry standard for online financial transactions. Your personal data is not shared with third parties without your consent and is stored in accordance with the privacy policy listed on the website. If you have any concerns, you can always contact customer support for a full explanation of their data protection measures.

What tools does SkyHills Casino offer if I feel my gambling is getting out of control?

SkyHills Casino provides responsible gambling tools, including the ability to set deposit limits, activate a time-out, or temporarily or permanently exclude yourself from the platform. These features are accessible through your account settings and are designed to give players control over their gambling behavior. If you need urgent help, the casino also recommends reaching out to organizations such as GamCare or addiction support services in your region.

Can I set up two-factor authentication to better secure my SkyHills account?

SkyHills Casino offers login protection for your account, and it is strongly recommended that you choose a strong, unique password during registration that you do not use anywhere else. Two-factor authentication (2FA) is a feature increasingly offered by online casinos; check the security settings in your account profile on skyhillscaasino.com to see which options are currently available. If you are unsure, contact customer support to confirm what additional security layers they provide.

What should I do if I have a complaint about a withdrawal or an unfair game at SkyHills Casino?

If you have a complaint, the first step is to contact SkyHills Casino's customer support directly via live chat or email, attaching as much evidence as possible such as screenshots and transaction details. The casino follows an internal complaints process in which disputes are handled within a reasonable timeframe. Should you be unable to resolve the matter internally, you can also contact an independent dispute resolution body or a consumer protection organization in your country for further mediation.

How does SkyHills Casino verify my age and prevent fraud on my account?

SkyHills Casino follows a KYC (Know Your Customer) procedure in which you are required to submit a valid proof of identity and proof of address either at registration or before your first withdrawal, ensuring the platform excludes minors and prevents identity fraud. Founded in 2024, the casino adheres to the standard industry practices for age verification required by its operating license. Make sure your documents are up to date to avoid delays with withdrawals, which typically take 3 to 5 business days for card payments.

I play SkyHills almost every day during my train ride to Amsterdam and the app runs really smoothly — no crashes, fast loading times, everything fitting nicely on my screen. The 200% welcome bonus up to €1,500 is what convinced me to create an account, though it took me a little while to fully understand the 35x wagering requirement. If there's one thing I'd change, it's that the payout time to my card was shorter than the 3 to 5 business days it currently takes.
— Fleur S., 27, Amsterdam
Honestly, I started at SkyHills because I want to bet on football occasionally as well as play casino games, and the fact that they have an integrated sportsbook saves me from having an extra app on my phone. The crypto payments work smoothly — my €20 deposit was ready within a few minutes and I could get started right away. It's a young platform — founded in 2024 — but you can barely tell from the quality of the mobile experience.
— Pieter B., 34, Ghent
I was pleasantly surprised by how well the touch controls work. I used to play on another platform where you constantly had to zoom in just to tap the right button — none of that hassle here. The 200% bonus on my first deposit was a nice bonus, though you do need to meet the 35x wagering requirement within 7 days, so I plan my gaming sessions during breaks a bit more carefully. I've been playing for a few weeks now and have no real complaints so far.
— Lisa K., 31, Rotterdam
A colleague of mine tipped me off about SkyHills and I'm glad he did, because the mobile game selection is genuinely impressive for a casino that's only been around since 2024. I deposited the minimum €20 to test it out first, then immediately decided to go for the full welcome bonus — €1,500 in extra potential is nothing to scoff at. The crypto option is personally the most convenient for me, since I don't want to pull out my bank card every time I want to play on the go.
— Jan V., 29, Utrecht