Illustration of an institutional exchange building icon with a broken padlock, representing a compromised account

Crypto exchange platforms are generally more heavily defended than an individual wallet holder's own devices and accounts, which is exactly why most exchange account compromises do not start with the exchange's own systems being broken. They start somewhere upstream, a phishing email, a SIM swap, a reused password exposed in an unrelated data breach, or a fake support interaction, and the exchange account is simply the most valuable thing that upstream access eventually leads to.

Crypto related hacks and scams stole an estimated 2.1 billion dollars in 2025, and while headline coverage tends to focus on large scale platform breaches, a substantial share of individual losses on exchanges trace back to this kind of account level takeover rather than a flaw in the exchange's core infrastructure.

The typical sequence behind an account takeover

Credential exposure

Many account takeovers begin with a login credential that was exposed somewhere else entirely, often years earlier, in an unrelated website's data breach. Because password reuse remains common, attackers routinely test exposed email and password combinations against exchange login pages, a technique known as credential stuffing, hoping to find accounts where the same password was never changed.

Phishing aimed at exchange credentials specifically

A more targeted route involves a phishing message or fake website built to closely resemble a specific exchange's login page, login alert, or verification request. Because these messages frequently reference real account activity or urgent sounding security language, they can convince even experienced users to enter credentials or a one time code directly into the attacker's page.

SIM swapping to bypass verification

Where an exchange account relies on SMS based verification, a SIM swap can bypass that protection entirely by redirecting the victim's phone number to a device the attacker controls. This specific mechanism, and how to recognize it in progress, is covered in depth in our guide on SIM swap attacks, since the two topics are closely linked in practice.

Insider and support channel compromise

A less common but well documented path involves a compromised or bribed customer support employee at the exchange or a linked service provider, who accesses account details or approves changes that should have required stronger verification. Incidents involving bribed support staff at major platforms have exposed customer records at scale, subsequently enabling more convincing, personalized impersonation attempts against the affected users.

Key Point

Most exchange account compromises are not caused by a weakness in the exchange's core systems. They are caused by an attacker gaining control of something upstream of the account, most often an email inbox or a phone number.

A realistic scenario: from a phishing email to a drained exchange account

  • A victim receives an email formatted to look exactly like a real security alert from their exchange, warning of a suspicious login attempt and providing a link to secure the account immediately.
  • The link leads to a cloned login page, visually identical to the real exchange, where the victim enters their email and password, which are immediately captured by the attacker.
  • The cloned page also prompts for a one time authentication code, which the attacker relays in real time to the real exchange login page, completing the login on the actual account within the same minute.
  • Once logged in, the attacker changes the account's withdrawal address allowlist or disables it entirely where the exchange permits that change without additional delay, then initiates a withdrawal to a wallet under their control.
  • The victim receives a legitimate withdrawal confirmation email from the real exchange shortly after, often the first indication that anything is wrong, by which point the funds have typically already left the platform.

This kind of real time relay attack, where a fake page passes stolen credentials and codes straight through to the real service within the same session, defeats standard two factor authentication entirely, since the one time code is genuine and used within its normal validity window. It is one of the reasons hardware security keys, which cryptographically bind an authentication attempt to the real site's exact domain, provide meaningfully stronger protection than a one time code of any kind.

How exchanges decide whether to freeze funds

When a victim reports a compromise quickly enough, an exchange's fraud and compliance teams typically look at several factors before deciding what action is possible. If the stolen funds are still sitting in a wallet the exchange itself controls, an internal freeze is straightforward and can often be applied within the exchange's own systems immediately. If funds have already moved to another platform, the exchange can only request cooperation from that receiving platform, which depends on an existing relationship or a formal law enforcement channel, and there is no guarantee the receiving platform will act before funds are withdrawn again. Exchanges generally will not freeze an account based on an unverified report alone, since a false claim could itself be used to interfere with a legitimate account holder, so some identity verification is typically required even in an emergency freeze request. This verification step, while sometimes frustrating for a victim who wants immediate action, exists specifically to prevent the freeze process itself from becoming a new attack vector. For more on how this kind of platform to platform cooperation has evolved, see our guide on exchange cooperation trends.

Exchange account compromise compared to a self custody wallet hack

A self custody wallet hack and an exchange account compromise share many of the same upstream causes, phishing, malware, and SIM swapping among them, but the two situations diverge sharply once the theft has occurred. A self custody wallet has no intermediary to appeal to. Once a transaction is signed and confirmed, there is no company, support line, or account freeze mechanism standing between the victim and the loss. An exchange account, by contrast, involves a regulated intermediary that holds the actual assets on the user's behalf until withdrawal, which means there is at least a window, however narrow, during which human or automated intervention at the exchange level can still prevent or limit the loss. This is one of the few practical advantages of custodial exchange accounts over self custody from a pure security standpoint, offset by the fact that an exchange account depends entirely on trusting that intermediary's own security and internal controls.

What an exchange typically does once notified

Reputable exchanges generally offer an emergency account lock or freeze feature specifically for this situation, which halts withdrawals while the account holder regains control through identity verification. Following notification of a compromise, exchanges typically review the account's recent login and withdrawal activity, may temporarily freeze outbound transfers tied to flagged addresses, and in some cases can work with receiving exchanges to flag or freeze funds that have not yet been withdrawn or converted, particularly when notified quickly.

That cooperation is not automatic or guaranteed, and it depends heavily on speed. The longer funds sit in a flagged account before being moved further, the more likely intervention becomes possible, which is part of why immediate reporting to the exchange, rather than attempting to resolve the issue independently first, tends to produce better outcomes.

Steps to take immediately if your account is compromised

  • Contact the exchange's official support channel immediately through its verified website or app, and request an emergency account freeze or lock.
  • Change your email password from a separate, trusted device, since a compromised email is frequently the root access point behind an exchange account takeover.
  • Review and revoke any API keys connected to the account, since a stolen API key can allow automated withdrawals without requiring further login access at all.
  • Document every unauthorized transaction, including destination addresses, transaction identifiers, and timestamps, which forms the basis of both an exchange investigation and a formal report.
  • File a report with your national cybercrime reporting body, such as the FBI's IC3 in the United States, in addition to the exchange's own investigation.

Once access is regained, a few specific account settings deserve direct verification, since an attacker with sufficient access sometimes leaves behind a quieter, more durable foothold rather than relying solely on the original login.

  • Confirm the registered email address and phone number on the account have not been silently changed to ones the attacker controls, which would allow them to regain access even after a password reset.
  • Review the withdrawal address allowlist, if the exchange offers one, and remove any address you do not recognize before re enabling withdrawals.
  • Check for any newly created API keys, sub accounts, or linked payment methods, since an attacker with sufficient access sometimes creates a persistent access point rather than relying solely on the original login.
  • Review recent account activity logs for login locations and devices that do not match your own history, and log out of all active sessions from every device.

Once funds have left an exchange account entirely, the path forward typically shifts toward blockchain tracing, identifying where the funds moved and whether they passed through another regulated exchange where a freeze request could still apply. Firms that specialize in this kind of investigation, including Coin Trace, work directly with this evidence to build a documented account of the fund flow, which can support both a law enforcement referral and, where a viable path exists, a recovery effort, though no outcome can be guaranteed in advance.

exchange securityaccount takeovercrypto investigationsphishing

Frequently asked questions

Not reliably. In a relay attack, a fake login page passes a stolen one time code through to the real exchange within its normal validity window, completing a genuine login. A hardware security key, which cryptographically verifies the exact domain being logged into, provides much stronger protection against this specific technique than a one time code delivered by SMS or an authenticator app.

No exchange can reverse a blockchain transaction once it has confirmed on chain. What an exchange can sometimes do is freeze funds that have not yet left a receiving account, which is why speed in reporting the compromise matters significantly.

It substantially reduces risk but is not absolute protection, particularly if it relies on SMS codes that can be intercepted through a SIM swap. An authenticator app or hardware security key provides materially stronger protection than SMS based verification.

That is a personal decision, but if you continue using the account, ensure the password, email, and all connected API keys and authentication methods are fully replaced first, since any of them could still be compromised even after the immediate incident is resolved.

Investigators follow the blockchain record of each subsequent transfer, looking for patterns that indicate deliberate obfuscation, and identify points where the funds interact with a regulated service that can be contacted to flag or freeze the account involved.


Sources and further reading


Related reading

How a SIM Swap Attack Leads to a Drained Crypto AccountWhy Exchange Cooperation Has Improved in Recent YearsWhat Happens After a Crypto Wallet Hack