Security
Oct 9, 2026

Account Takeover Fraud in Crypto: How It Works and How to Stop It

How account takeover fraud hits crypto users: credential stuffing, fake support, SIM swaps and session theft, and the defences that stop it.

Account Takeover Fraud in Crypto: How It Works and How to Stop It

Account takeover fraud is when a criminal gains control of someone else's existing account, such as a crypto exchange login, an email inbox or a bank account, and uses it to steal money or data. In crypto it does particular damage because once coins are withdrawn to an outside address there is usually no chargeback and no easy way to reverse the transfer.

This guide covers how account takeovers happen, why crypto accounts are a favourite target, what users can do to lock their accounts down, and how exchanges detect and stop takeovers. It is written for ordinary users and for the fraud and compliance teams protecting them.

What account takeover fraud is

The FBI describes account takeover (ATO) fraud as criminals gaining unauthorised access to a target's online financial institution, payroll or health savings account "with the goal of stealing money or information for personal gain". In a public service announcement dated 25 November 2025, it said the Internet Crime Complaint Center (IC3) had received more than 5,100 ATO complaints since January 2025, with losses above $262 million (FBI IC3, I-112525-PSA).

Two details in that announcement matter for crypto users. First, the FBI said stolen funds are often wired to criminal-controlled accounts, "many of which are linked to cryptocurrency wallets", so they are dispersed quickly and are hard to trace and recover. Second, in nearly all social engineering cases the criminals changed the account password and locked the owner out.

ATO differs from new-account fraud. In synthetic identity fraud, criminals open fresh accounts with fake identities. In ATO, they hijack an account that already belongs to a real, verified customer, which is exactly why it is valuable: the account has passed KYC, has a history, and often holds funds.

How attackers take over accounts

Most takeovers use one of a handful of techniques, often combined:

  • Credential stuffing. OWASP defines it as "the automated injection of stolen username and password pairs" into login forms. Because many people reuse passwords, credentials leaked in one breach unlock accounts elsewhere. OWASP calls it one of the most common techniques used to take over accounts (OWASP).
  • Fake support and phishing. The FBI describes criminals posing as bank staff, customer support or tech support to talk people into handing over login details and one-time passcodes, then resetting the password themselves. It also flags "SEO poisoning": paid search ads that lead to convincing fake login pages.
  • SIM swaps. A criminal persuades a mobile carrier to move the victim's number to a SIM they control, then receives the SMS codes and password-reset texts. Our guide to SIM swap attacks covers this in detail.
  • Session hijacking. Instead of the password, the attacker steals a logged-in session, for example through malware on the victim's computer, and uses it to act as the user without passing the login step again.
  • Leaked customer data used for targeted scams. Data stolen from a company can make a fake support call far more convincing.

That last route is not hypothetical. In a filing dated 15 May 2025, Coinbase disclosed that a threat actor had paid contractors or employees in support roles outside the US to collect customer data from internal systems, then demanded money not to publish it. Coinbase said no passwords or private keys were compromised, refused the $20 million demand, and estimated remediation costs and voluntary reimbursements at roughly $180 million to $400 million (Coinbase Form 8-K). Its blog explained the aim: a customer list the criminals could call "while pretending to be Coinbase", tricking people into handing over their crypto (Coinbase).

Why crypto accounts are a prime target

A takeover of a crypto exchange account is attractive for three reasons:

  • Speed and finality. A withdrawal to an external address settles in minutes, and there is no card network to reverse it.
  • Verified identity. The account already passed KYC, so a criminal can use it to move or launder funds without fronting their own documents. That overlaps with money mule activity.
  • Linked access. Exchange accounts are often connected to bank accounts, cards and API keys, which widens what an attacker can reach.

Self-custody wallets have no account to take over, but they face the same social engineering aimed at a different prize: the seed phrase or a malicious signature. See wallet drainers and approval phishing.

Warning signs your account is being targeted

  • Login alerts or password-reset emails you did not request.
  • Unexpected calls or texts from "support" about suspicious activity, especially ones that ask for a code, a password, or for you to move funds to a "safe" wallet.
  • Your phone suddenly losing service, which can mean a SIM swap is under way.
  • New withdrawal addresses, API keys or devices on your account that you did not add.
  • Changes to your email account, such as forwarding rules you did not set up.

Coinbase's own warning after the 2025 incident is a good rule for any platform: it "will never ask for your password, 2FA codes, or for you to transfer assets to a specific or new address".

How to protect your account

The single biggest upgrade is moving from codes you type in to phishing-resistant sign-in:

  1. Use passkeys or a hardware security key where offered. CISA calls phishing-resistant MFA, such as FIDO/WebAuthn, "the gold standard" and notes that other forms of MFA can be defeated by phishing, push bombing or SIM swaps (CISA fact sheet). NIST's updated authentication guidelines, finalised in July 2025, state that one-time-passcode and out-of-band authenticators are not phishing-resistant, because a code typed into a fake site can be relayed to the real one (NIST SP 800-63B-4).
  2. If you must use codes, prefer an authenticator app to SMS. NIST classes SMS and voice codes as a "restricted" authenticator.
  3. Use a unique, long password for every exchange and for your email. The FBI recommends unique, random passwords of at least 16 characters (FBI IC3, April 2024). A password manager makes this practical.
  4. Turn on withdrawal address allowlisting and any delay the platform offers for new addresses. A thief who gets in then cannot send funds straight to their own wallet.
  5. Bookmark login pages. The FBI advises against reaching login pages through search results or ads, warning that "MFA will not protect you if you land on a fraudulent login page".
  6. Hang up and call back. If someone claims to be your exchange, end the call and contact the company through its official app or website.

Keep long-term holdings in a wallet you control rather than on an exchange where possible. JewelSwap's apps, for example, are non-custodial: you connect your own wallet rather than creating a JewelSwap account, so security depends on how you protect that wallet. Our self-custody guide covers the basics.

How exchanges detect and stop account takeovers

For platforms, the goal is to make a stolen password worthless and to add friction exactly where money leaves. Common controls include:

  • Device binding and risk signals. A login from a new device, a new country and a fresh IP address, followed by a password reset and a new withdrawal address, is a classic takeover sequence. Each step alone is ordinary; together they justify a block or a review.
  • Rate limiting and bot detection on login and reset endpoints, aimed at credential stuffing.
  • Cooling-off periods after security changes such as a new email, phone number, 2FA method or withdrawal address.
  • SIM-change awareness. NIST says services that still send codes by SMS should consider risk indicators such as a device swap, SIM change or number porting before relying on them.
  • Step-up re-verification. For high-risk actions, ask the customer to prove they are the same person who opened the account, typically with a live selfie matched against the original KYC record. After its 2025 incident, Coinbase said flagged accounts would need additional ID checks on large withdrawals.

Step-up checks only work if they cannot be fooled by a photo or a replayed video, which is why liveness detection matters. Identity vendors such as iDenfy offer face matching with liveness checks that platforms can trigger at these moments, not just at sign-up.

Behind the scenes, transaction monitoring helps spot a hijacked account being used to move other people's money, and a confirmed takeover used to launder funds may need a suspicious activity report.

What to do if your account is taken over

The FBI's November 2025 announcement sets out the order of operations:

  1. Contact the platform immediately and ask it to freeze the account and recall or reverse anything it can.
  2. Reset or revoke compromised credentials, including on any other site where you used the same password. On an exchange, also revoke API keys and remove unknown withdrawal addresses and devices.
  3. File a complaint at ic3.gov with as much detail as possible, including the words "Account Takeover" in the description, if you are in the US.
  4. Tell the impersonated company how you were targeted so it can warn others.

Then secure your email account and your mobile carrier account, because they are the keys to resetting everything else. Be wary of anyone who contacts you offering to get your crypto back for a fee. That is a common follow-up scam, covered in our guide to crypto recovery scams.

Frequently asked questions

What is account takeover fraud?

It is when a criminal gains control of someone else's existing online account, such as a crypto exchange, email or bank account, and uses it to steal money or information. The FBI recorded more than 5,100 complaints and over $262 million in losses from January to late November 2025.

How do criminals take over crypto exchange accounts?

Mostly through reused passwords tried automatically on login pages (credential stuffing), phishing and fake support calls that capture passwords and one-time codes, SIM swaps that hijack SMS codes, and malware that steals logged-in sessions.

Does two-factor authentication stop account takeover?

It helps, but not every type equally. Codes sent by SMS or typed from an app can be phished or intercepted. Passkeys and hardware security keys based on FIDO/WebAuthn are phishing-resistant, which CISA calls the gold standard.

Can I get my crypto back after an account takeover?

Sometimes, if you act fast and the funds have not left the platform. Contact the exchange immediately and report to the FBI at ic3.gov if you are in the US. Once coins are withdrawn to an outside address, recovery is difficult, and anyone promising guaranteed recovery for a fee is likely a scammer.

Why does my exchange ask for a selfie before a withdrawal?

It is a step-up check. Matching a live selfie to the face from your original KYC confirms the person moving funds is the account owner, which stops a criminal who has only stolen your password or codes.

Keep reading

This article is educational and is not legal, security or financial advice. Figures are as published in the sources linked inline: FBI IC3 announcement I-112525-PSA (25 November 2025), Coinbase Form 8-K (15 May 2025) and NIST SP 800-63B-4 (July 2025). Sources checked on 9 October 2026.

About the author.

Co-Founder at JewelSwap & Chief Strategy Officer at iDenfy. Viktor brings his successful track record of superb development & project management.