Email hacked and exchange account locked recovery steps
The chain usually begins with a single compromised credential. An attacker gains access to your email account, often through a reused password from a previous data breach. They then search your inbox for exchange registration confirmations, withdrawal emails, and security notifications.
Once the attacker identifies which exchange you use, they initiate a password reset. The reset link lands in your now-compromised inbox. They change your exchange password. They may also disable or reset your two-factor authentication if your 2FA recovery options rely on email.
This is where the exchange's detection systems typically activate.
Exchanges monitor for session invalidation events. When someone changes a password, all existing sessions are terminated. A user logged in from a known IP suddenly appearing from a different country triggers a flag. Unusual withdrawal requests to non-whitelisted addresses also raise alerts.
Many exchanges now freeze accounts automatically when they detect a pattern consistent with account takeover. This is not a termination. It is a protective freeze.
Understanding the freeze vs closure distinction matters. A closed account means the exchange has severed the relationship; the assets are typically gone or locked permanently. A frozen account means the exchange has paused activity while they verify your identity. Your funds remain in the account. They are not lost. They are inaccessible until you prove you are the legitimate owner.
The exchange will typically send a notification to your compromised email address. If the attacker still has access, they will see the freeze notice too. The legitimate owner often discovers the freeze only when they attempt to log in and receive an error stating the account is locked.
Recovery begins with securing your email. Change your email password immediately. Enable hardware-based 2FA on your email account if you have not already. Do not use SMS-based recovery for that email account. The attacker may have set up forwarding rules to hide incoming security emails; check your email forwarding settings and delete any unknown rules.
Next, contact the exchange's support channel. Most major exchanges require identity re-verification to unfreeze a compromised account. This typically involves submitting a government-issued ID and a selfie. The exchange will compare these against the documents you submitted during original account creation.
The anti-phishing code presents a complication. If the attacker changed your anti-phishing code, you will not know the new code. Support agents may ask for it during verification. Explain that the account was compromised and the code was changed by the attacker. Exchanges have procedures for resetting the anti-phishing code after identity verification, but the process takes longer.
Some exchanges also require a signed message from your exchange-registered wallet address to prove ownership. This is less common. Prepare for it if you previously linked a non-custodial wallet.
Re-verification can take anywhere from a few days to several weeks. Exchanges prioritize these cases differently. The key factor is whether you can produce matching identity documents and demonstrate that you have regained control of your email account.
Once the exchange confirms your identity, they will unfreeze the account. They will force a full password reset and require you to set up new 2FA from scratch. They may also require you to set a new anti-phishing code.
After regaining access, review all account activity. Check withdrawal addresses. Check API keys. Check whitelisted withdrawal addresses. The attacker may have added addresses for future use even if they did not complete a withdrawal.
The entire incident often leaves users without access for a week or more. The exchange is not being difficult. They are following a standard security protocol that protects both your assets and their platform from liability. A frozen account is a sign that the detection systems worked, not that the exchange failed.
The data for the underlying token on Solana, as of August 31, 2026, shows a contract address of 5mbK36SZ7J19An8jFochhQS4of8g6BwUjbeCSxBSoWdp, trading on Raydium across 30 pairs with $405,732 in liquidity.
If your exchange account held this asset and becomes locked due to an email compromise, the steps above are the only path to recovery. There is no shortcut. There is no way to bypass identity verification. The process exists because the alternative - allowing anyone who accesses your email to drain your account - would make exchange storage worthless.
Not financial advice. michimeme.com publishes market data and general information about michi. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.