CoinFeeHub reference

How exchange accounts get stolen: 6 patterns, real cases, the fix

Six patterns come up again and again in exchange-account thefts, and each has a fix that takes minutes: an authenticator app or passkey instead of SMS codes, a withdrawal whitelist, a unique password, and checking every “support” contact through the exchange’s own verification tool. The table pairs each pattern with a documented case.

Six patterns, six fixes

PatternDocumented caseThe fixSource
SIM swap — your number is moved to the attacker’s SIM, so SMS codes go to themNicholas Truglia took part in a SIM-swap theft of over $20M in crypto from one victim; sentenced to 18 months on 2022-12-01Use an authenticator app or passkey; remove SMS as a 2FA method where the exchange allows; ask your carrier for a port-out PINU.S. DOJ 2022-12-01
Fake support and phishing — a caller or message asks for codes or a “safe” transferData leaked from Coinbase in 2025 was used to impersonate its support. Coinbase: it “will never ask for your password, 2FA codes, or for you to transfer assets to a specific or new address”End the call; check the contact with an official tool such as Binance Verify; contact support only from inside the appCoinbase 2025-05-15; Binance Verify
Fake apps and browser extensionsOKX warned on 2025-01-07 that OKX-branded wallet extensions on the Firefox add-on store were not its own. The FBI reported $42.7M lost to fake crypto investment apps (2022)Install only from links on the exchange’s official site; set an anti-phishing code so you can recognise real emailsCointelegraph 2025-01-08 (secondary); FBI IC3 2022-07-18
Address poisoning — a look-alike address is planted in your transaction historyBinance identified about 15 million poisoned addresses (13.4M on BNB Chain, 1.68M on Ethereum); one trader lost $68M in WBTC on 2024-05-03, later returnedWithdraw only to whitelisted addresses; compare the full address, not the first and last characters; never copy from transaction historyCointelegraph 2024-05-16 (secondary)
Password reuse — leaked passwords from other sites are tried on yours (credential stuffing)New York’s DFS fined PayPal $2M after attackers used compromised credentials; PayPal did not require multi-factor authenticationA unique password for every exchange, kept in a password manager, plus app-based 2FA — see account security basicsNY DFS 2025-01-23
Untrusted Wi-Fi — a look-alike hotspot can monitor your network activityThe NSA advises a personal hotspot over public Wi-Fi, or a VPN to encrypt traffic when public Wi-Fi is unavoidable. Taiwan’s Administration for Cyber Security warned travellers about look-alike hotspots on 2026-02-12Use mobile data or your own hotspot; on hotel or airport Wi-Fi, use a VPN to encrypt your traffic — see public Wi-Fi while travellingNSA 2021-07-29; CTEE 2026-02-12 (secondary)

The fix, in order

  1. Replace SMS codes with an authenticator app or a passkey (SIM swap, phishing).
  2. Turn on the withdrawal whitelist and any new-address lock (phishing, address poisoning). Feature-by-feature: 8-exchange setup matrix.
  3. Set an anti-phishing code so real exchange emails carry your code (fake support, fake apps).
  4. Use a unique password from a password manager (credential stuffing).
  5. Sign in from a bookmark and install apps only from the official site (fake apps).
  6. Avoid open Wi-Fi for account changes, or encrypt your traffic with a VPN on untrusted networks. A VPN does not change which exchanges you may use — see VPNs and exchange region rules.

Common questions

Is SMS 2FA better than nothing?

Yes, but it is the method a SIM swap defeats. Switch to an authenticator app or passkey where the exchange supports it.

Does a VPN stop phishing?

No. A VPN encrypts traffic on an untrusted network; it cannot tell you whether a website or caller is genuine.

What does an anti-phishing code do?

You choose a code that the exchange adds to its emails. An email claiming to be from the exchange without your code is fake; a correct code does not make every link in it safe, so still sign in from your bookmark.

I already clicked a suspicious link. What now?

Follow the first-hour response plan: lock the account, change the password from a clean device and revoke API keys.

Sources and editorial notes

Sources checked 2026-10-07. Government and exchange pages are primary; news reports are marked secondary. The order of fixes is CoinFeeHub editorial guidance.

Change note

2026-10-07 · Page created with six patterns and documented cases.