Exchange Account Compromise, Anonymized and Illustrative

A Credential Stuffing Attack on an Exchange Account

A client's exchange account was accessed using a password reused from an unrelated data breach. Two factor authentication had been silently disabled weeks earlier, and several assets were withdrawn in a single session.

A Credential Stuffing Attack on an Exchange Account
ETH and other tokensASSET TYPE
Individual client, exchange account takeoverCASE CONTEXT

The Situation

A client's exchange account was accessed using a password reused from an unrelated data breach. Two factor authentication had been silently disabled weeks earlier, and several assets were withdrawn in a single session.

The Challenge

The exchange's internal access logs were not directly available to the client, so the full picture had to be modeled from the withdrawal transactions alone.

The Investigation

We identified every withdrawal in the compromised session, traced each destination address, and cross checked timing against the exchange's public status page to rule out a platform side breach.

Findings

Funds were withdrawn to a single new wallet, partially converted to a stablecoin, and moved toward a second, smaller exchange.

Outcome

Findings were submitted to both the original exchange's security team and the destination exchange, requesting a compliance hold. The matter remains open pending their internal review.

Lessons

A silently disabled two factor authentication setting is one of the clearest early signals of compromise. Account level alerts for security setting changes are worth enabling on every exchange account.

Step 1
Exchange Account
Compromised session
Step 2
Withdrawal Wallet
0x9F 2C41
Step 3
Stablecoin Conversion
ETH to USDC
Step 4
Second Exchange
Deposit pending review

Exchange Account

Access gained via a reused, breached password.

Facing a similar situation?

Every case is scoped on its own facts. Tell us what happened.