How account takeover fraud hits crypto users: credential stuffing, fake support, SIM swaps and session theft, and the defences that stop it.

Account takeover fraud is when a criminal gains control of someone else's existing account, such as a crypto exchange login, an email inbox or a bank account, and uses it to steal money or data. In crypto it does particular damage because once coins are withdrawn to an outside address there is usually no chargeback and no easy way to reverse the transfer.
This guide covers how account takeovers happen, why crypto accounts are a favourite target, what users can do to lock their accounts down, and how exchanges detect and stop takeovers. It is written for ordinary users and for the fraud and compliance teams protecting them.
The FBI describes account takeover (ATO) fraud as criminals gaining unauthorised access to a target's online financial institution, payroll or health savings account "with the goal of stealing money or information for personal gain". In a public service announcement dated 25 November 2025, it said the Internet Crime Complaint Center (IC3) had received more than 5,100 ATO complaints since January 2025, with losses above $262 million (FBI IC3, I-112525-PSA).
Two details in that announcement matter for crypto users. First, the FBI said stolen funds are often wired to criminal-controlled accounts, "many of which are linked to cryptocurrency wallets", so they are dispersed quickly and are hard to trace and recover. Second, in nearly all social engineering cases the criminals changed the account password and locked the owner out.
ATO differs from new-account fraud. In synthetic identity fraud, criminals open fresh accounts with fake identities. In ATO, they hijack an account that already belongs to a real, verified customer, which is exactly why it is valuable: the account has passed KYC, has a history, and often holds funds.
Most takeovers use one of a handful of techniques, often combined:
That last route is not hypothetical. In a filing dated 15 May 2025, Coinbase disclosed that a threat actor had paid contractors or employees in support roles outside the US to collect customer data from internal systems, then demanded money not to publish it. Coinbase said no passwords or private keys were compromised, refused the $20 million demand, and estimated remediation costs and voluntary reimbursements at roughly $180 million to $400 million (Coinbase Form 8-K). Its blog explained the aim: a customer list the criminals could call "while pretending to be Coinbase", tricking people into handing over their crypto (Coinbase).
A takeover of a crypto exchange account is attractive for three reasons:
Self-custody wallets have no account to take over, but they face the same social engineering aimed at a different prize: the seed phrase or a malicious signature. See wallet drainers and approval phishing.
Coinbase's own warning after the 2025 incident is a good rule for any platform: it "will never ask for your password, 2FA codes, or for you to transfer assets to a specific or new address".
The single biggest upgrade is moving from codes you type in to phishing-resistant sign-in:
Keep long-term holdings in a wallet you control rather than on an exchange where possible. JewelSwap's apps, for example, are non-custodial: you connect your own wallet rather than creating a JewelSwap account, so security depends on how you protect that wallet. Our self-custody guide covers the basics.
For platforms, the goal is to make a stolen password worthless and to add friction exactly where money leaves. Common controls include:
Step-up checks only work if they cannot be fooled by a photo or a replayed video, which is why liveness detection matters. Identity vendors such as iDenfy offer face matching with liveness checks that platforms can trigger at these moments, not just at sign-up.
Behind the scenes, transaction monitoring helps spot a hijacked account being used to move other people's money, and a confirmed takeover used to launder funds may need a suspicious activity report.
The FBI's November 2025 announcement sets out the order of operations:
Then secure your email account and your mobile carrier account, because they are the keys to resetting everything else. Be wary of anyone who contacts you offering to get your crypto back for a fee. That is a common follow-up scam, covered in our guide to crypto recovery scams.
It is when a criminal gains control of someone else's existing online account, such as a crypto exchange, email or bank account, and uses it to steal money or information. The FBI recorded more than 5,100 complaints and over $262 million in losses from January to late November 2025.
Mostly through reused passwords tried automatically on login pages (credential stuffing), phishing and fake support calls that capture passwords and one-time codes, SIM swaps that hijack SMS codes, and malware that steals logged-in sessions.
It helps, but not every type equally. Codes sent by SMS or typed from an app can be phished or intercepted. Passkeys and hardware security keys based on FIDO/WebAuthn are phishing-resistant, which CISA calls the gold standard.
Sometimes, if you act fast and the funds have not left the platform. Contact the exchange immediately and report to the FBI at ic3.gov if you are in the US. Once coins are withdrawn to an outside address, recovery is difficult, and anyone promising guaranteed recovery for a fee is likely a scammer.
It is a step-up check. Matching a live selfie to the face from your original KYC confirms the person moving funds is the account owner, which stops a criminal who has only stolen your password or codes.
This article is educational and is not legal, security or financial advice. Figures are as published in the sources linked inline: FBI IC3 announcement I-112525-PSA (25 November 2025), Coinbase Form 8-K (15 May 2025) and NIST SP 800-63B-4 (July 2025). Sources checked on 9 October 2026.