A Credential Stuffing Attack on an Exchange Account
A client's exchange account was accessed using a password reused from an unrelated data breach. Two factor authentication had been silently disabled weeks earlier, and several assets were withdrawn in a single session.
The Situation
A client's exchange account was accessed using a password reused from an unrelated data breach. Two factor authentication had been silently disabled weeks earlier, and several assets were withdrawn in a single session.
The Challenge
The exchange's internal access logs were not directly available to the client, so the full picture had to be modeled from the withdrawal transactions alone.
The Investigation
We identified every withdrawal in the compromised session, traced each destination address, and cross checked timing against the exchange's public status page to rule out a platform side breach.
Findings
Funds were withdrawn to a single new wallet, partially converted to a stablecoin, and moved toward a second, smaller exchange.
Outcome
Findings were submitted to both the original exchange's security team and the destination exchange, requesting a compliance hold. The matter remains open pending their internal review.
Lessons
A silently disabled two factor authentication setting is one of the clearest early signals of compromise. Account level alerts for security setting changes are worth enabling on every exchange account.
Exchange Account
Access gained via a reused, breached password.
Facing a similar situation?
Every case is scoped on its own facts. Tell us what happened.
