Advertise on KripZen — put your brand in front of a global crypto audience.Get in touch →

Glossary entry

Account Takeover

Wallets & Security

Account takeover is the outcome, not the technique. The five routes attackers actually use into an exchange account, and the controls that survive each one.

Definition

Account takeover is the outcome in which someone else is authenticated as you on an exchange or wallet service, with your balances, your withdrawal permissions and your history in front of them. It is worth naming separately from the techniques that produce it, because the defences that matter are the ones that hold no matter which route was taken. Five routes account for most real cases. A password reused from a breached site, replayed at scale. A session cookie lifted from an infected machine, which walks straight past a correct password and a correct one-time code because the session is already authenticated. A phone number ported away by a SIM swap, defeating SMS codes and often the password reset too. An email account compromised first, because the mailbox is the reset path for everything else. And the support desk itself, talked into a recovery by someone holding enough personal detail to sound like the account owner. Layer the response accordingly: a passkey or hardware security key instead of SMS, a dedicated email address used for nothing else, a withdrawal whitelist so that a stolen session cannot invent a new destination, a time delay on adding one, and API keys scoped to trading with withdrawals disabled. The recurring lesson from real incidents is that the second factor stopped the login and the withdrawal controls stopped the loss.

Next

Related terms

More in Wallets & Security