Account Takeover at the On-Ramp: The Sequence That Works
How an attacker gets from an email address to a drained exchange balance, and which single control breaks the chain.
Priya Raman · 2 min read
Account takeover at an exchange follows a predictable sequence. Understanding the order tells you where to put the effort. It helps to have a reference point that is verifiable, and an on-ramp that publishes its limits publishes its licence details.
Step one: the email
Everything begins with the email account, because that is where password resets go.
The attacker gets in through a password reused from a breached site, or through a phishing page, or occasionally by convincing the provider’s support that they have lost access.
An email account protected by a password alone is the weakest link in the entire chain, and it is the one people spend the least effort on.
Step two: the reset
With email access, the attacker requests a password reset at the exchange. The link arrives, they use it, and the password is theirs.
They then delete the notification emails so the real owner sees nothing.
Step three: the second factor
This is where it either stops or does not.
If the second factor is a code sent by text message, the attacker attempts a number transfer with the mobile operator, using personal details gathered from social media or a previous breach. This succeeds more often than it should. The same attack targets businesses harder, which is what a business crypto wallet with approval controls is built to resist.
If the second factor is an authenticator application or a hardware key, the attacker is stuck. They have the password and cannot proceed.
Step four: the withdrawal address
Even with full account access, a withdrawal needs a destination.
If the exchange lets new addresses be used immediately, the funds leave within minutes.
If new addresses require a waiting period and send notifications to the account holder, the attacker has to wait, and the owner gets an email saying an address was added.
The two controls that matter
A hardware key or authenticator application on both the email account and the exchange, never text messages.
An address allowlist with a delay on additions, wherever the exchange offers it.
Those two break the chain at steps three and four respectively. Everything else is secondary.
What a business should add
Separate logins per person, so one compromise does not expose everything. Withdrawal approval by someone other than the person who requested it. And notifications to more than one person when settings change.
The last one is underrated. An attacker in one account can suppress what that account sees. They cannot stop four colleagues receiving the same alert.
Checking whether it already happened
Look at the login history and the list of registered withdrawal addresses. An address you do not recognise, or a session from a country you have not visited, is the signal. Compare anything you are offered against a regulated crypto exchange before sending funds anywhere.
Most exchanges show both. Almost nobody looks until afterwards.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.