How to secure a crypto account after a data breach
Secure a crypto account after a data breach by changing passwords, adding app-based codes, revoking sessions and API keys, and checking withdrawals.

On this page
- A breach notice does not always mean crypto left your account.
- A new password does not end open sessions or delete API keys.
- App-based codes resist SIM swaps better than texted codes.
- Keep the breach notice and a log of every step you take.
A data breach happens when personal information is exposed without authorization. The notice tells you that data leaked, not what a thief already holds, so treat every account tied to that email as exposed.
Start with email and exchange
Email holds the password reset links for your exchanges and custodial wallets, so secure it first. A self-custody wallet does not use email resets, since the recovery phrase controls it. Use a long, unique password from a password manager for each account, then switch to app-based multi-factor authentication and remove SMS codes, which a SIM swap can intercept. A custodial provider holds your security and can freeze your access.
Lock down sessions and check activity
- 1Sign out other sessionsIn the security settings of your exchange, sign out every session and device you do not recognize.
- 2Remove connected appsDelete third-party apps and services you no longer use or do not recognize.
- 3Delete old API keysOld keys keep working after a password change, so revoke each key you do not need.
- 4Review withdrawals and ordersLook for transfers and pending orders you did not place, and search your inbox for login and withdrawal alerts you missed.
Protect keys and recovery phrase
A recovery phrase is the master key to a wallet, and anyone who has those words can move the funds. Do not share it with anyone, and skip screenshots that sync to cloud storage. If it was exposed, create a new wallet and move your assets there.
Report and monitor after the breach
If crypto left your account, contact exchange support so it can freeze the account and open a case. Transfers are usually irreversible, so support often cannot return the funds.
- Report the theft to the FBI's Internet Crime Complaint Center.
- File a fraud report with the FTC.
- Contact exchange support and keep the case number.
- Keep the breach notice, transaction IDs and support messages.
Frequently asked questions
Usually not right away. Closing it can cut off the alerts, statements and support channel you need while the breach is still open.
Not always. A unique password with app-based codes usually protects the address, though you can route crypto email to a separate inbox if the phishing does not stop.
Keep the breach notification, transaction IDs, wallet addresses, support messages and any agency report numbers. They help investigators trace the theft and support a later claim.
Watch your alerts and statements for several months, and review connected apps and API keys again whenever a new notice arrives.






