Skip to content
All library documents

Crypto Account Compromise: Emergency Response and Security Practices

Article OKX Learn

Summary

This guide gives a response sequence for suspected wallet or exchange account compromise: move remaining assets from a device believed to be safe, scan and update devices, replace credentials, and contact the provider and relevant authorities. It recommends collecting transaction records and other evidence when reporting theft. It also identifies warning signs such as unrecognized withdrawals, login alerts, and unexpected two-factor authentication activity.

For prevention, it recommends unique passwords, authenticator-based two-factor authentication, hardware wallets for significant holdings, withdrawal address whitelists, and offline seed phrase backups. The document also discusses account freezes, session controls, proof-of-reserves, and possible insurance or compensation, with examples centered on OKX. Those provider-specific claims and recovery options are not independently assessed here; the guide notes that protection programs have limits and does not offer a guarantee that stolen funds can be recovered.

Key ideas

  • When compromise is suspected, the guide prioritizes securing remaining funds from a device believed to be clean.
  • It recommends scanning devices and changing credentials only from a trusted device.
  • Incident reports should include transaction identifiers, timestamps, wallet addresses, and relevant screenshots.
  • Prevention measures include authenticator-based two-factor authentication, hardware wallets, and withdrawal whitelists.
  • Insurance, compensation, and recovery options depend on provider policies and do not guarantee reimbursement.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.