Captcha, credentials, and PGP two-factor.
The BlackOps login embeds the onion in the captcha and can lock the account with a key.
Solve the login captcha and confirm the address embedded in the image matches your bar before your password.
Pick a username you have never used elsewhere, generate a unique password in a local manager, and store the recovery phrase on paper. Turn on PGP two-factor so a stolen password on its own cannot open the account. No genuine login ever asks for the recovery phrase.