Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case fileself-custody failures

Social Engineering at Exchanges

Attacking the support process rather than the customer. What venues do about it and what you can do to make your account harder to take over.

Priya Raman · 2 min read

Some account takeovers do not involve the customer at all. The attacker targets the venue’s support process.

The attack

An attacker contacts support claiming to be a customer who has lost access. They provide information about the account: name, email, approximate balance, recent transaction details.

The information comes from data breaches, from public on-chain activity, or from the customer having been phished earlier for details that seemed harmless.

If the support process accepts that information as proof of identity, the attacker obtains access, resets authentication, and withdraws.

Why support processes are vulnerable

They exist to help genuine customers who have lost access, which is a real and common situation. A process rigid enough to be unattackable is a process that strands legitimate users.

Every venue sits somewhere on that trade-off, and the position is not published.

What good venues do

Require identity documents with liveness checks rather than knowledge of account details.

Impose a waiting period after any authentication change before withdrawals are permitted. This is the single most effective control.

Notify through every channel when authentication changes, so a genuine customer sees it happening.

Maintain the withdrawal allowlist across resets, so a new address cannot be added and used immediately.

Separate the support agent from the ability to change credentials, requiring a second approval.

What you can do

Enable the withdrawal address allowlist. With a delay on additions. This converts an instant theft into a window.

Use a dedicated email address not used anywhere else and not published. Much of the information used in these attacks starts with an email address found in a breach.

Enable every notification the venue offers. Login alerts, authentication change alerts, withdrawal alerts.

Use hardware two-factor. It cannot be phished and it is not transferable by a support agent.

Keep the balance small. The recurring conclusion of everything on this site.

The other direction is an attacker impersonating the venue’s support and contacting you. Real venues do not initiate contact asking for credentials or codes.

A message claiming your account is at risk, asking you to confirm details or move funds to a safe address, is fraudulent without exception. No legitimate venue has a safe address.

Checking your own venue

Read the account recovery documentation before you need it. A venue that documents its process, including a delay on authentication changes, has thought about this.

Platforms publishing their security model, such as a licensed exchange with a published address, make that assessment possible in a few minutes. Venues that do not publish it have answered the question differently.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

account-takeoversupportexchanges

Related cases