CoinFeeHub reference
How exchange accounts get stolen: 6 patterns, real cases, the fix
Six patterns come up again and again in exchange-account thefts, and each has a fix that takes minutes: an authenticator app or passkey instead of SMS codes, a withdrawal whitelist, a unique password, and checking every “support” contact through the exchange’s own verification tool. The table pairs each pattern with a documented case.
Six patterns, six fixes
| Pattern | Documented case | The fix | Source |
|---|---|---|---|
| SIM swap — your number is moved to the attacker’s SIM, so SMS codes go to them | Nicholas Truglia took part in a SIM-swap theft of over $20M in crypto from one victim; sentenced to 18 months on 2022-12-01 | Use an authenticator app or passkey; remove SMS as a 2FA method where the exchange allows; ask your carrier for a port-out PIN | U.S. DOJ 2022-12-01 |
| Fake support and phishing — a caller or message asks for codes or a “safe” transfer | Data leaked from Coinbase in 2025 was used to impersonate its support. Coinbase: it “will never ask for your password, 2FA codes, or for you to transfer assets to a specific or new address” | End the call; check the contact with an official tool such as Binance Verify; contact support only from inside the app | Coinbase 2025-05-15; Binance Verify |
| Fake apps and browser extensions | OKX warned on 2025-01-07 that OKX-branded wallet extensions on the Firefox add-on store were not its own. The FBI reported $42.7M lost to fake crypto investment apps (2022) | Install only from links on the exchange’s official site; set an anti-phishing code so you can recognise real emails | Cointelegraph 2025-01-08 (secondary); FBI IC3 2022-07-18 |
| Address poisoning — a look-alike address is planted in your transaction history | Binance identified about 15 million poisoned addresses (13.4M on BNB Chain, 1.68M on Ethereum); one trader lost $68M in WBTC on 2024-05-03, later returned | Withdraw only to whitelisted addresses; compare the full address, not the first and last characters; never copy from transaction history | Cointelegraph 2024-05-16 (secondary) |
| Password reuse — leaked passwords from other sites are tried on yours (credential stuffing) | New York’s DFS fined PayPal $2M after attackers used compromised credentials; PayPal did not require multi-factor authentication | A unique password for every exchange, kept in a password manager, plus app-based 2FA — see account security basics | NY DFS 2025-01-23 |
| Untrusted Wi-Fi — a look-alike hotspot can monitor your network activity | The NSA advises a personal hotspot over public Wi-Fi, or a VPN to encrypt traffic when public Wi-Fi is unavoidable. Taiwan’s Administration for Cyber Security warned travellers about look-alike hotspots on 2026-02-12 | Use mobile data or your own hotspot; on hotel or airport Wi-Fi, use a VPN to encrypt your traffic — see public Wi-Fi while travelling | NSA 2021-07-29; CTEE 2026-02-12 (secondary) |
The fix, in order
- Replace SMS codes with an authenticator app or a passkey (SIM swap, phishing).
- Turn on the withdrawal whitelist and any new-address lock (phishing, address poisoning). Feature-by-feature: 8-exchange setup matrix.
- Set an anti-phishing code so real exchange emails carry your code (fake support, fake apps).
- Use a unique password from a password manager (credential stuffing).
- Sign in from a bookmark and install apps only from the official site (fake apps).
- Avoid open Wi-Fi for account changes, or encrypt your traffic with a VPN on untrusted networks. A VPN does not change which exchanges you may use — see VPNs and exchange region rules.
Common questions
Is SMS 2FA better than nothing?
Yes, but it is the method a SIM swap defeats. Switch to an authenticator app or passkey where the exchange supports it.
Does a VPN stop phishing?
No. A VPN encrypts traffic on an untrusted network; it cannot tell you whether a website or caller is genuine.
What does an anti-phishing code do?
You choose a code that the exchange adds to its emails. An email claiming to be from the exchange without your code is fake; a correct code does not make every link in it safe, so still sign in from your bookmark.
I already clicked a suspicious link. What now?
Follow the first-hour response plan: lock the account, change the password from a clean device and revoke API keys.
Sources and editorial notes
Sources checked 2026-10-07. Government and exchange pages are primary; news reports are marked secondary. The order of fixes is CoinFeeHub editorial guidance.
- U.S. DOJ (SDNY) · SIM-swap sentencing · 2022-12-01
- Coinbase · Standing up to extortionists · 2025-05-15
- Binance · Official verification (Binance Verify) · checked 2026-10-07
- Cointelegraph · Fake OKX plugins on Firefox · 2025-01-08 (secondary)
- FBI IC3 · Fake crypto investment apps · 2022-07-18
- Cointelegraph · Binance address-poisoning research · 2024-05-16 (secondary)
- NY DFS · PayPal cybersecurity settlement · 2025-01-23
- NSA · Securing wireless devices in public settings · 2021-07-29
- CTEE · Administration for Cyber Security travel warning · 2026-02-12 (secondary)
Change note
2026-10-07 · Page created with six patterns and documented cases.