Night Study/Tools/Hacked account plan
Crypto exchange account hacked? Get your next steps in the right order
The order of a response depends on what you still hold, not on what happened. Answer the three below and the plan comes back sequenced for your situation, including the steps people usually do too late.
Before anything: use a device other than the one you suspect if you have one, and do not delete the message, email or notification involved. You will be asked for it.
Answer all three to build the plan
The sequence changes substantially depending on the email answer, so that one matters most.
About this plan — why the order is what it is
The three questions, in full
(1) Can you still sign in to the exchange account, or are you locked out? (2) Is the email address registered on the account still yours, has it been changed, or can you not tell? (3) Does your phone still have mobile service, or has it gone dead? From those three the plan is assembled out of the same set of steps: assume a SIM takeover, secure the email account first, disable the account if activity is happening in front of you (left out when the email has been changed, because reporting that change from your live session comes first), screenshot before changing anything, revoke every session and device, change the password, check the withdrawal address list, check the API keys, check the verification methods, start official account recovery, contact the mobile operator, re-enrol the second factor, and check the withdrawal list again a day later and when the waiting period runs out.
What problem this solves
Almost every guide to a compromised account is a list of causes. At the moment it happens, causes are useless. What you need is the next action, and the correct next action is different depending on whether the email address on the account is still yours.
Why email comes before the exchange
Whoever controls the registered email controls the recovery path. Securing the exchange while the inbox belongs to somebody else means they can undo everything you just did, at leisure. It feels wrong to walk away from the money to deal with an inbox, and it is still the right order.
Why screenshots come before revoking
Revoking sessions clears the device list. That list is the record you would want to show a support agent later, so it gets captured first — it costs about thirty seconds.
Why the withdrawal address list is checked twice
An intruder who cannot withdraw immediately, because a waiting period is in force, will often plant an address and an API key and come back when the hold expires. Checking once during the incident is not enough; the list is worth checking again after the dust settles. The reasoning behind those holds is in the allowlist guide.
What it deliberately does not tell you
How long recovery takes, or how likely it is to work. Either figure would be a guess, and in this situation a guess does more harm than a blank.
Afterwards
Expect to be contacted with an offer to recover the funds. That approach is built on the fact that people post about losses publicly — how it works is worth reading before it arrives rather than after.