Security decision matrix
Identify the threat before changing settings
Fast action helps only when it matches the incident. Start with the account, email, device, and withdrawal path.
| Signal | Likely risk | First safe action |
|---|---|---|
| Unexpected login alert | Possible credential exposure | Secure email first, then review sessions from a clean device. |
| 2FA device lost | Access recovery risk | Use official recovery. Do not pay anyone or share backup codes. |
| Fake support contact | Phishing or recovery scam | Stop replying. Open the provider through a bookmark or typed domain. |
| Unknown API key | Automated account access risk | Revoke it, rotate credentials, and review trades and withdrawals. |
| Withdrawal address changed | Funds may be at immediate risk | Freeze withdrawals if available and contact official support. |
| Account locked | Security, KYC, region, or policy review | Read the exact status and use the matching official appeal route. |
Account takeover response desk
Work in time windows, not panic steps
A compromised exchange account is usually an email, device, 2FA, API, and withdrawal problem at the same time. The order matters.
Contain the account from a clean device
Open the exchange through a typed official domain or verified app. If a trusted session is still open, look for account freeze, withdrawal lock, or authenticated support before making broad changes.
Secure the linked email first, then freeze exchange access where the provider allows it.Remove the attacker's paths
Reset exposed passwords, revoke unknown sessions, remove unfamiliar API keys, check withdrawal allowlists, and replace compromised 2FA only through the official recovery flow.
Do not approve new prompts or follow links from alerts while you are cleaning access.Map the damage before opening many tickets
Record login alerts, device changes, API activity, conversions, loans, withdrawals, TXIDs, and order IDs. A clean timeline gives support something they can investigate.
Open one official case and keep updates in that case unless support tells you otherwise.Rebuild the security stack
Move financial accounts to unique passwords, phishing-resistant 2FA where supported, reviewed devices, withdrawal controls, and monitored email and mobile accounts.
Treat the email account, mobile number, device, and exchange as one connected incident.Recovery scam filter
Do not turn one compromise into two losses
- Do not pay an upfront recovery, tracing, tax, or unfreezing fee.
- Do not move remaining funds to a wallet supplied by a caller or private message.
- Do not install remote-control software for someone claiming to be support.
- Do not share screenshots that reveal full identity numbers, seed phrases, or codes.
Stop using the possibly compromised path
Do not keep logging in from a device that may contain malware or through a link that may be fake. Move to a clean, updated device and reach the exchange through a known official domain or verified app.
If you still control a trusted session, look for any official account-freeze, withdrawal-lock, session-revocation, or authenticated support option. Do not approve unexpected prompts, read out codes, install remote-control software, or move funds to a wallet supplied by a caller.
If a withdrawal is already in progress, preserve the request ID and TXID immediately. If no withdrawal exists yet, prioritize freezing access before creating more account changes.
Secure the identity chain before the exchange reset
Secure the linked email account before relying on an exchange password reset. Change exposed or reused passwords, revoke unfamiliar email sessions, remove suspicious forwarding rules, and protect the mobile account if SIM theft is possible.
Then reset the exchange password through the verified service, revoke unknown exchange sessions, remove unfamiliar API keys and withdrawal addresses, and replace compromised authentication methods through the official recovery flow.
If the attacker controlled your email, assume password-reset links, withdrawal confirmations, and support messages may have been seen. Record that in the support case instead of treating it as a simple password problem.
Separate trading damage from withdrawal damage
Check login history, devices, security methods, API keys, address allowlists, subaccounts, trades, conversions, loans, withdrawals, and notifications. Record timestamps and transaction IDs before details disappear from the interface.
Unauthorized trading, API activity, internal conversion, and blockchain withdrawal are different evidence trails. A completed blockchain transfer may be irreversible, but the exchange still needs accurate evidence to investigate account access, security controls, and any remaining balance.
If an unknown API key exists, revoke it before reviewing trades. If an unknown withdrawal address or allowlist entry exists, capture it and then remove it if the provider allows removal during an incident.
Report once, then keep the case clean
Open one clear case through official support and state that unauthorized access is suspected. Include the timeline, affected assets, transaction IDs, email or device alerts, and security changes. Do not send passwords, one-time codes, seed phrases, private keys, or screen-control access.
Report phishing messages to the impersonated provider and relevant consumer or law-enforcement channels in your location. The FTC warns that crypto recovery promises are commonly used to steal more money, especially after a first loss.
If support asks for additional identity evidence, upload it only inside the provider's protected flow. Do not send documents to a social-media account, direct message, or personal email claiming to be an investigator.
- Verified support case number
- Timeline in UTC where possible
- Login, email, device, and SIM alerts
- Unauthorized trade, conversion, loan, withdrawal, or TXID records
- Suspicious URLs, emails, phone numbers, and usernames
- Actions already taken to secure email, mobile, device, and the exchange
- Police or consumer-report reference when applicable
Rebuild security after containment
After the provider confirms the account state, use a unique password, phishing-resistant authentication where supported, protected backup methods, login alerts, and withdrawal controls. Review every device and browser extension used for financial accounts.
Do not restore access from an untrusted backup or immediately reuse the same compromised device. Continue monitoring email, mobile, exchange, bank, and identity activity because account takeover can involve more than one service.
If the account remains usable, consider a small test withdrawal only after security settings, allowlists, sessions, email, and devices have been reviewed. Do not rush to resume normal activity just because the password was changed.
Common questions
Frequently asked questions
What is the first thing to do if my exchange account is hacked?
Use a clean device, secure the linked email, reach the exchange through its verified app or domain, and use official freeze or support controls. Do not follow recovery links sent by strangers.
Can a completed crypto withdrawal be reversed?
Blockchain transfers are generally irreversible. Report the incident immediately with the TXID and account evidence, but do not trust anyone guaranteeing recovery.
Should I pay a crypto recovery service?
Treat unsolicited or guaranteed recovery offers as a scam warning. The FTC warns that recovery scams often target people who have already lost money.
Why secure email before resetting the exchange password?
The email account may receive password resets, withdrawal confirmations, device alerts, and support replies. If an attacker controls the email, they may regain access even after an exchange password reset.
Primary references
Official sources checked
These official pages were reviewed on June 15, 2026. Exchange policies can change, so open the source before acting.