Guides

Think Your Crypto Exchange Account Was Compromised? What to Do First

A safe containment order for suspected Coinbase, Kraken, or Binance account takeover: pause access, secure email and devices, change credentials, and avoid a panicked withdrawal.

Published September 22, 2026Updated September 22, 2026

A suspicious login, password-reset email, unfamiliar device, or withdrawal alert is not a time to troubleshoot casually. Treat it as a possible account takeover until you can rule it out.

The goal is containment first, investigation second, withdrawal last. That order can feel slower than immediately moving funds, but it reduces the chance that an attacker, a fake support agent, or a poisoned destination address turns one security event into a permanent loss.

The first 15 minutes

If you see thisDo this first
Unfamiliar sign-in, device, password reset, or withdrawal alertOpen the exchange only from your own app, bookmark, or typed domain. Do not use the link in the alert.
You can still access the official accountUse the exchange's lock, freeze, or suspicious-activity path before changing settings at random.
Your email may be exposed tooChange the email password and its sign-in protection from a trusted device.
You received a support call, text, or direct messageEnd the conversation. Use only official support started from the exchange site or app.
You are considering an emergency withdrawalPause until you have contained the account and independently verified the destination.

1. Contain the account through the official channel

If you still have access, use the security control the exchange provides rather than trying to outpace an attacker with trades or withdrawals.

Coinbase's Security Lock signs out devices and disables trading, transfers, and account changes while you review the account. Coinbase says crypto sends are paused for 24 hours after an unlock. That friction is intentional: it gives the account owner time to reset credentials and check activity.

Kraken directs users who suspect compromise to its official Account Security & Sign-in Issues form. Its guidance also says to secure the email and devices involved, reset the Kraken password if email access remains available, and tell the bank if a linked debit card may have been used without authorization.

The exact buttons and recovery checks differ by exchange. The rule does not: start from the real app or a domain you enter yourself, then follow the platform's official security or recovery path.

2. Secure the recovery email and the device you are using

Changing only the exchange password is not enough if an attacker can reset it through your inbox.

From a device you trust:

  1. change the email password to a new, unique password;
  2. review recent sign-ins, recovery addresses, forwarding rules, and unfamiliar devices in the email account;
  3. replace weak SMS-only protection with a passkey, security key, or authenticator method where available;
  4. update the operating system and scan the computer or phone you used to access the exchange if malware is plausible.

Kraken specifically advises compromised-account users to change email passwords and 2FA, scan devices for malware or keyloggers, and install current software updates. If you believe the phone itself is compromised, do not use it to approve a password change or a withdrawal. Our guide to what a hacked phone can still do to a hardware-wallet user explains why moving from the same questionable device is risky.

3. Reset credentials, then remove the attacker's footholds

Once the official account lock or support process is underway, reset the exchange password to a unique one. Then inspect the account for anything that could preserve access after the password change:

  • active sessions and recognized devices;
  • newly added passkeys, security keys, or 2FA methods;
  • changed recovery details;
  • API keys, especially keys with trading or withdrawal permissions;
  • unfamiliar withdrawal addresses, beneficiaries, or saved payment methods;
  • trades, conversions, and transfers you did not authorize.

Remove or revoke anything you do not recognize through the official account interface. Keep screenshots, timestamps, transaction IDs, and alert emails for the exchange's security team. Do not send those details to a caller or an account that contacts you first.

For the preventive setup once the incident is over, use the crypto exchange account security checklist. It covers passkeys, allowlisting, anti-phishing tools, API restrictions, and a safer recovery setup.

4. Do not let a fake helper create the second loss

An account alert often triggers a second scam: someone calls, texts, or messages pretending to be exchange support and offers to "secure" your funds.

They may ask you to:

  • read out a one-time code;
  • install remote-access software;
  • move crypto to a "safe" address;
  • share a wallet recovery phrase;
  • approve a new device or passkey.

None of those requests is a safe response to a suspected takeover. An exchange never needs a self-custody wallet's recovery phrase to secure an exchange login. A legitimate support flow starts from the exchange's own site or app; it does not need a stranger to rush you over the phone.

Read Crypto Support Call Scam before responding to any follow-up contact.

5. Decide about a withdrawal only after containment

Once the exchange confirms the account is secure and you have reviewed the activity, decide whether the remaining balance needs to stay on the platform.

For funds you intend to trade soon, a hardened exchange account and withdrawal protections may fit. For long-term holdings, self-custody can remove exchange-login risk from the custody chain, but only if you can protect the wallet backup yourself.

Do not use a security incident as a reason to send everything to an untested address. Verify the network, verify the receiving address independently, and use a small test transaction when appropriate. Our exchange-to-hardware-wallet transfer guide covers the safer handover order, and Tangem vs Ledger vs Trezor helps compare self-custody backup models once the immediate incident is resolved.

When this is an emergency

Escalate immediately through the official exchange path if you see an unauthorized withdrawal, an unknown bank-card transaction, a changed recovery email or phone number, or evidence that someone can still access your inbox. Contact the bank separately if a linked card or bank account may be involved.

Do not wait for a suspicious message to become proof. A temporary lock or security ticket is easier to unwind than a completed unauthorized transfer.

Bottom line

A suspected exchange compromise is a containment problem, not a speed contest. Use the official exchange channel, secure the email and devices behind the account, reset credentials, revoke unfamiliar access, and only then make a calm decision about moving funds. That order protects you from both the original attacker and the predictable scams that follow a security scare.

Explore more

Guides worth reading next