BitPunks All articles
Security & Wallets

Signs Your Exchange Account Is Already Compromised (And You Just Don't Know It Yet)

BitPunks
Signs Your Exchange Account Is Already Compromised (And You Just Don't Know It Yet)

Most account takeovers don't announce themselves. There's no flashing warning, no dramatic notification, no villain twirling a mustache on your screen. Instead, there's silence. A few unusual login entries buried in a settings page nobody checks. A tiny test withdrawal that looks like a rounding error. By the time the main event happens—the full drain—you're already too late.

This is your audit. Right now. Here's how to actually know.

Start With the Boring Stuff Nobody Reads

Every major exchange gives you a login history. Coinbase, Kraken, Binance US, Gemini—they all have it. Most users open it exactly once, get bored, and never return. That's a mistake.

What you're looking for isn't just failed login attempts. Those are obvious. The real threat hides in successful logins from IPs you don't recognize, at times you weren't awake, from device fingerprints that don't match your hardware. Pull that log right now. Cross-reference the IP addresses against a basic geolocation tool. If you live in Ohio and there's a successful auth from a data center in Virginia at 3 a.m., that's not a glitch—that's a flag.

Pay special attention to the session duration. Attackers who gain access often keep sessions alive using token refresh tricks, meaning they don't need to log in again once they're in. A session that started two weeks ago and never ended? That's not you.

The On-Chain Breadcrumb Trail

Here's where it gets interesting. Even if an attacker hasn't moved your funds yet, they may have already fingerprinted your wallet addresses. On-chain analysis tools like Etherscan, Arkham Intelligence, and Breadcrumbs let you trace every interaction with your deposit addresses. You don't need to be a blockchain forensics expert to spot the warning signs.

Look for these patterns:

Dust attacks. Tiny amounts—sometimes fractions of a cent—sent to your wallet from unknown sources. This isn't generosity. It's tracking. Attackers use dust to link your address to an identity, or to test whether a wallet is live before targeting it. If your address has received unsolicited micro-transactions, someone knows you exist.

Probe withdrawals. Before draining an account, sophisticated attackers often run a small test withdrawal to verify they control the pipeline. Check your transaction history for any outbound transfers you didn't initiate, even tiny ones. On-chain, everything leaves a mark.

Unusual internal transfers. Some exchanges use internal ledger systems and only settle to the blockchain periodically. But if your exchange shows internal transfers between sub-accounts you didn't set up, or consolidation moves you didn't authorize, that's a sign someone is staging a larger exit.

Your API Keys Are Probably the Leak

This one catches people off guard. A lot of crypto users connect third-party tools—portfolio trackers, trading bots, tax software—to their exchange accounts via API keys. Those keys often get forgotten. The app gets abandoned. The permissions stay active.

An API key with withdrawal permissions is essentially a backdoor. If the third-party service you granted access to gets breached (and many small crypto tools have been), your key is now in someone else's hands. Go into your exchange's API management section and revoke everything you don't actively use. If you can't remember what a key was for, kill it.

While you're in there, check the permissions on any remaining keys. Read-only is fine. Trade-enabled requires scrutiny. Withdrawal-enabled should be treated like a loaded weapon—used only when absolutely necessary and never left lying around.

Two-Factor Authentication Isn't a Guarantee

SMS-based 2FA has been dead as a security measure for years, but people keep using it. SIM-swapping attacks—where a bad actor convinces your carrier to transfer your phone number to a SIM they control—are still devastatingly effective. Once they own your number, your SMS codes are their SMS codes.

If you're still using SMS 2FA on any exchange account, change it today. Move to an authenticator app like Authy or Google Authenticator at minimum. Better yet, use a hardware key like a YubiKey for any account holding significant value. It's not paranoia—it's just math.

Also check: has your email account been compromised? Your exchange account is only as secure as the email attached to it. Run your email through HaveIBeenPwned.com. If it shows up in a data breach, assume the password has been circulating in criminal markets and rotate everything immediately.

The Withdrawal Whitelist Test

Here's a simple but underused security move: check whether your exchange supports withdrawal address whitelisting, and if so, whether it's turned on. Whitelisting means funds can only be sent to pre-approved addresses. An attacker who gains access to your account still can't drain it to an unknown wallet without triggering a delay or verification step.

If whitelisting is available and you haven't enabled it, that's your first action item after finishing this article. If it's already on, verify the list. Make sure no addresses were added that you don't recognize. Adding a malicious address to a whitelist is a known attack vector—it's quiet, it's slow, and it's patient.

What to Do If You Find Something

If any of the above checks surface something suspicious, don't panic—act fast and in the right order.

First, freeze withdrawals if your exchange has that feature. Second, revoke all active API keys immediately. Third, change your password from a clean device on a network you trust—not your usual home WiFi if you have any reason to suspect it's been compromised. Fourth, contact exchange support and flag the activity. Document everything with screenshots before you change anything.

Finally, move your assets. If you have reason to believe an account has been accessed, even partially, the only real safety play is getting your funds off that exchange and into a hardware wallet you control. Self-custody isn't just ideology—in this moment, it's survival.

Paranoia Is a Feature, Not a Bug

The crypto space rewards vigilance in a way that traditional finance never had to. There's no fraud department calling to flag unusual activity. There's no chargeback. There's no FDIC. The irreversibility of blockchain transactions means that once funds leave, they're gone—and the clock starts ticking the moment an attacker gets their first foothold.

Running this kind of audit once isn't enough. Make it a habit. Set a calendar reminder. Once a month, pull your login history, check your API keys, verify your whitelist, and run your addresses through an on-chain explorer. It takes twenty minutes. It's the most valuable twenty minutes you'll spend.

Decentralization puts power in your hands. That's the whole point. But power without vigilance is just an open door.

All Articles

Related Articles

Your Seed Phrase Is Already Out There: Inside the Markets Selling Access to Your Wallet

Your Seed Phrase Is Already Out There: Inside the Markets Selling Access to Your Wallet

SIM-Swapped and Stripped Clean: The Human Exploit That's Emptying Crypto Wallets Across America

SIM-Swapped and Stripped Clean: The Human Exploit That's Emptying Crypto Wallets Across America

From Fringe to Firewall: How Crypto's Paranoia Became America's Best Privacy Playbook

From Fringe to Firewall: How Crypto's Paranoia Became America's Best Privacy Playbook