Incident response

Crypto Exchange Account Hacked? Act in This Order

If an exchange account may be compromised, speed matters, but random password resets and repeated support tickets can make the investigation harder. Work from a clean device, secure the connected email first, stop new withdrawals where possible, and preserve evidence before it disappears.

Reviewed and last updated: June 17, 2026

Security decision matrix

Identify the threat before changing settings

Fast action helps only when it matches the incident. Start with the account, email, device, and withdrawal path.

SignalLikely riskFirst safe action
Unexpected login alertPossible credential exposureSecure email first, then review sessions from a clean device.
2FA device lostAccess recovery riskUse official recovery. Do not pay anyone or share backup codes.
Fake support contactPhishing or recovery scamStop replying. Open the provider through a bookmark or typed domain.
Unknown API keyAutomated account access riskRevoke it, rotate credentials, and review trades and withdrawals.
Withdrawal address changedFunds may be at immediate riskFreeze withdrawals if available and contact official support.
Account lockedSecurity, KYC, region, or policy reviewRead the exact status and use the matching official appeal route.

Stop using the possibly compromised path

Do not keep logging in from a device that may contain malware or through a link that may be fake. Move to a clean, updated device and reach the exchange through a known official domain or verified app.

If you still control a trusted session, look for any official account-freeze, withdrawal-lock, session-revocation, or authenticated support option. Do not approve unexpected prompts, read out codes, install remote-control software, or move funds to a wallet supplied by a caller.

If a withdrawal is already in progress, preserve the request ID and TXID immediately. If no withdrawal exists yet, prioritize freezing access before creating more account changes.

Secure the identity chain before the exchange reset

Secure the linked email account before relying on an exchange password reset. Change exposed or reused passwords, revoke unfamiliar email sessions, remove suspicious forwarding rules, and protect the mobile account if SIM theft is possible.

Then reset the exchange password through the verified service, revoke unknown exchange sessions, remove unfamiliar API keys and withdrawal addresses, and replace compromised authentication methods through the official recovery flow.

If the attacker controlled your email, assume password-reset links, withdrawal confirmations, and support messages may have been seen. Record that in the support case instead of treating it as a simple password problem.

Separate trading damage from withdrawal damage

Check login history, devices, security methods, API keys, address allowlists, subaccounts, trades, conversions, loans, withdrawals, and notifications. Record timestamps and transaction IDs before details disappear from the interface.

Unauthorized trading, API activity, internal conversion, and blockchain withdrawal are different evidence trails. A completed blockchain transfer may be irreversible, but the exchange still needs accurate evidence to investigate account access, security controls, and any remaining balance.

If an unknown API key exists, revoke it before reviewing trades. If an unknown withdrawal address or allowlist entry exists, capture it and then remove it if the provider allows removal during an incident.

Report once, then keep the case clean

Open one clear case through official support and state that unauthorized access is suspected. Include the timeline, affected assets, transaction IDs, email or device alerts, and security changes. Do not send passwords, one-time codes, seed phrases, private keys, or screen-control access.

Report phishing messages to the impersonated provider and relevant consumer or law-enforcement channels in your location. The FTC warns that crypto recovery promises are commonly used to steal more money, especially after a first loss.

If support asks for additional identity evidence, upload it only inside the provider's protected flow. Do not send documents to a social-media account, direct message, or personal email claiming to be an investigator.

  • Verified support case number
  • Timeline in UTC where possible
  • Login, email, device, and SIM alerts
  • Unauthorized trade, conversion, loan, withdrawal, or TXID records
  • Suspicious URLs, emails, phone numbers, and usernames
  • Actions already taken to secure email, mobile, device, and the exchange
  • Police or consumer-report reference when applicable

Rebuild security after containment

After the provider confirms the account state, use a unique password, phishing-resistant authentication where supported, protected backup methods, login alerts, and withdrawal controls. Review every device and browser extension used for financial accounts.

Do not restore access from an untrusted backup or immediately reuse the same compromised device. Continue monitoring email, mobile, exchange, bank, and identity activity because account takeover can involve more than one service.

If the account remains usable, consider a small test withdrawal only after security settings, allowlists, sessions, email, and devices have been reviewed. Do not rush to resume normal activity just because the password was changed.

Common questions

Frequently asked questions

What is the first thing to do if my exchange account is hacked?

Use a clean device, secure the linked email, reach the exchange through its verified app or domain, and use official freeze or support controls. Do not follow recovery links sent by strangers.

Can a completed crypto withdrawal be reversed?

Blockchain transfers are generally irreversible. Report the incident immediately with the TXID and account evidence, but do not trust anyone guaranteeing recovery.

Should I pay a crypto recovery service?

Treat unsolicited or guaranteed recovery offers as a scam warning. The FTC warns that recovery scams often target people who have already lost money.

Why secure email before resetting the exchange password?

The email account may receive password resets, withdrawal confirmations, device alerts, and support replies. If an attacker controls the email, they may regain access even after an exchange password reset.

Primary references

Official sources checked

These official pages were reviewed on June 15, 2026. Exchange policies can change, so open the source before acting.

  1. FTCWhat To Know About Cryptocurrency and Scams
  2. FTCHow To Recognize and Avoid Phishing Scams
  3. NISTDigital Identity Guidelines: Authentication and Authenticator Management