Scam Recovery & Victim Help

Crypto Exchange Account Hacked? Here’s What to Do Right Now

If you see unauthorized activity in your crypto exchange account, act in the next 5 minutes. Here’s exactly what to do — in order.

Maybe you woke up to a login alert you didn’t trigger. Maybe your balance is lower than it should be. Maybe you see trades you never placed, or a withdrawal confirmation email you never requested. Whatever the warning sign, the path forward is the same: move fast, document everything, and don’t let panic push you into making things worse.

This is a step-by-step guide for anyone whose crypto exchange account has been hacked — covering exactly what to do whether you still have access or you’re already locked out.

Do This Right Now: Immediate Lockdown Steps

Every second you wait is a second an attacker can move more of your funds. If you still have access to your account, take all of these steps before you do anything else:

Change your password immediately. Go to account settings and create a brand-new password — long, random, and one you’ve never used anywhere else. If you’re not using a password manager, start now: Bitwarden is free and reputable.

Revoke all API keys. API keys are like digital master keys that let third-party apps — trading bots, portfolio trackers, tax tools — access your account without your password. Go to your API management settings and revoke every single one. If an attacker created a key, revoking it cuts off their automated access immediately.

Disable withdrawals if the exchange allows it. Some exchanges let you temporarily lock your withdrawal capability from account settings or by contacting support directly. Use this feature if it’s available.

Enable 2FA with an authenticator app — not SMS. Two-factor authentication (2FA) adds a second verification step every time you log in. The problem: SMS-based 2FA can be bypassed through a SIM swap attack (explained below). Download Google Authenticator or Authy, and switch off text message 2FA right now.

Check your email immediately. Look for password reset emails, “your email address was changed” notifications, or any login alerts you didn’t trigger. Screenshot every one of them — this is your evidence trail for law enforcement and any dispute process with the exchange.

Contact the Exchange — Exactly What to Say

Call the exchange fraud line now, even before you know how this happened. Most major exchanges have 24/7 fraud teams:

  • Coinbase: 1-888-908-7930
  • Binance: help.binance.com (support ticket system)
  • Kraken: support.kraken.com

Tell them exactly this: “I believe my account has been compromised — I need to freeze all withdrawals and report unauthorized access. I need a fraud incident number.”

Ask for:

  • A full account hold that stops all withdrawals
  • Suspension of any pending transactions
  • A fraud incident number or ticket ID
  • The name of the fraud team member you spoke with

Write everything down: ticket number, representative’s name, date and time of the call, and what actions they said they’d take. This documentation matters if you need to file a police report, consult an attorney, or dispute the exchange’s response later.

How Did This Happen? Diagnosing the Attack

Understanding the entry point matters — it determines what you need to clean up beyond the exchange account itself. Here are the five most common causes:

Phishing email. You received an email that looked like it came from your exchange, clicked a link, and entered your credentials on a fake login page controlled by attackers. Next step: assume your email password is also compromised and change it now.

Credential stuffing. You reused a password from another site that was previously breached. Attackers buy enormous lists of leaked email/password combinations and automatically test them on every major crypto exchange. Next step: check haveibeenpwned.com to see which of your accounts were exposed.

Malware or keylogger. Software on your computer recorded your keystrokes — including your exchange password — and sent them to the attacker. This can arrive through phishing attachments, pirated software, or malicious browser extensions. Next step: treat your device as compromised. Don’t use it for financial tasks until you’ve scanned it.

SIM swap attack. An attacker called your mobile carrier, impersonated you, and convinced them to transfer your phone number to a new SIM card. They then used your number to receive SMS 2FA codes and reset your exchange password. Next step: call your carrier, add a PIN to your account, and switch all crypto accounts to authenticator app 2FA.

Compromised API key. You gave a third-party trading bot or app access via an API key, and that app was hacked or was itself malicious. API keys can be scoped to allow withdrawals, giving the attacker everything they needed. Next step: revoke all API keys. Never grant withdrawal permissions to third-party apps.

Crypto Exchange Account Hacked: Security Cleanup Checklist

Once the immediate crisis is contained, assume everything connected to your compromised account is at risk:

Change passwords on all your accounts. Start with email, then every financial account, then everything else. Every account gets its own unique, strong password — no exceptions. A password manager makes this manageable.

Scan your device for malware. Run Malwarebytes (free version is fine for a scan) or a reputable antivirus tool. If you have reason to believe there’s a deep infection — especially a keylogger — the safest option is to wipe the device and reinstall the operating system.

Check haveibeenpwned.com. Enter your email addresses to see which data breaches exposed your credentials. This often reveals exactly how the attacker got your password.

Switch all accounts to authenticator app 2FA. Not just crypto — your email, your bank, your social accounts, everything. SMS 2FA is better than nothing, but it’s the weakest link. App-based 2FA eliminates the SIM swap vulnerability.

Review and revoke OAuth connections. Check your email and social accounts for any third-party apps with access. Remove anything you don’t recognize or no longer use.

File Your Reports — Even If You Think Nothing Will Come of It

Most exchange hack victims don’t report to law enforcement because they assume it won’t help. File the reports anyway — they feed databases that build criminal cases and protect other victims:

  • IC3.gov — FBI’s Internet Crime Complaint Center. Include the exchange name, your account email, transaction IDs for unauthorized withdrawals, and total dollar amounts.
  • ReportFraud.ftc.gov — The FTC’s fraud database. Fast to fill out and contributes to pattern analysis across millions of fraud reports.
  • Local police — File a report and get a case number. You may need this for insurance claims, bank disputes, or attorney consultations.

If you lost a significant amount, consider consulting a licensed attorney about potential exchange liability. I’m not a lawyer and can’t tell you what your specific legal options are — but when real money is on the line, a professional opinion is worth the consultation fee.

The Bigger Lesson: Exchanges Are High-Value Targets

Here’s the uncomfortable truth: when your crypto sits on an exchange, you’re not really holding it — the exchange is. As I explain in Not Your Keys, Not Your Crypto, what you actually have is an IOU. Exchange account compromises are the everyday version of what the FTX collapse showed at catastrophic scale: when you don’t control your private keys, someone else controls your crypto.

Moving to self-custody — a hardware wallet you control — means that an attacker who gets your exchange login credentials gets nothing, because there’s nothing on the exchange to steal. If you’re ready to take that step, start with Seed Phrase Security: How to Store Your Recovery Words, which covers how to protect the master key to a self-custody wallet.

Recovery from an exchange compromise is exhausting and often incomplete. Prevention means not giving attackers a target in the first place.


Overwhelmed? Book a “Was I Scammed?” session ($149) — on-chain trace + a documentation pack for the FBI/IC3, police, and your bank. I will NOT promise to recover your funds; anyone who promises that is scamming you a second time. Book here

Want the full DeFi research every Friday? Wednesday scam alerts + Friday deep dives — premium newsletter, $9/month.
Upgrade to Premium →