Yes. Recovery and device rebinding can restore control over a live account and often over assets, so they deserve the same or higher assurance than initial enrolment. Lower standards in recovery create the easiest path for takeover and undermine the whole identity programme.
Why recovery needs the same assurance as onboarding
Recovery is not a back-office convenience step, it is an alternate control path into a live account. In a crypto exchange, that path can let someone rebind a device, reset authenticators, or replace recovery factors and then move funds or change withdrawal settings. If the recovery process is weaker than onboarding, attackers will target the weaker door, not the stronger one.
The practical rule is that recovery should be treated as an account-control event with the same or higher assurance target as first-time enrolment. That is especially true where the exchange can restore access to custody, trading, withdrawal permissions, or API-linked operational controls. The more the recovery flow can re-establish authority, the more it behaves like a high-risk identity event rather than a support task.
Where exchanges get the comparison wrong
Many programmes overestimate onboarding because it is visible and underprice recovery because it appears to be exception handling. In practice, recovery often has more attack surface: help desk interactions, lost-device workflows, fallback emails, SIM-based resets, and documentary review can all be abused if they are easier to socially engineer than initial verification.
Device rebinding deserves particular scrutiny because it can silently swap the trusted authenticator while leaving the account history intact. If the exchange allows a lower-friction path for a “known customer” to rebind a new device than for a new customer to open an account, the system rewards attacker persistence. Strong enrolment does not compensate for weak recovery if the latter can overwrite the former.
For customer identity assurance, the recovery path should be aligned to the same assurance logic used in onboarding, including evidence quality, step-up checks, and resistance to account-recovery abuse. A useful reference point is the NIST SP 800-63 Digital Identity Guidelines, which frames assurance as something that must hold across the full lifecycle, not only at sign-up.
What good recovery design looks like for exchanges
Good recovery design assumes that compromise may already be underway and that the attacker may know partial account history, possess a stolen session, or control a secondary channel. That means the recovery flow should not rely on one weak factor, one help desk script, or one out-of-band channel that can be intercepted or repurposed. Strong exchanges add step-up verification proportional to the asset impact of the account.
Practically, the best recovery journeys distinguish between low-impact account repair and high-impact authority restoration. Resetting a password is not the same as restoring the ability to withdraw assets or rebinding a hardware key. The latter should trigger stricter proofing, stronger audit trails, and stronger delay or review controls than the former.
Where onboarding verifies who is opening the account, recovery verifies whether the requester should be allowed to regain control of an account that already has value and history. That is why recovery controls should be evaluated alongside identity proofing and KYC and not treated as a separate support workflow. The same logic also applies to device rebinding and fallback-factor resets, which are effectively reassignment of trust.
For exchanges that support passwordless or passkey-based access, recovery must preserve the assurance level of the original authenticator rather than downgrade it through backup codes or weak fallback channels. NHIMG’s Passwordless and Passkeys Guide is useful here because it treats recovery as part of the secure sign-in model, not an afterthought.
Risk and Threat Considerations
Weak recovery is one of the most attractive paths for account takeover because it targets the control path most organisations try least hard to secure. In an exchange, that can expose balances, withdrawal rights, and linked devices even when initial enrolment was strong. It also creates a privileged social-engineering target for support teams, because the attacker only needs one successful exception to bypass the normal assurance model.
Failure mechanism: The attacker exploits a lower-assurance recovery path, such as help desk reset, email compromise, SIM swap, or weak identity re-verification, to replace the legitimate user’s authenticator or recovery factor and take control of the account.
Impact: The exchange can lose account integrity, trust in its enrolment standard, and potentially customer funds or withdrawal control, because recovery has become the easier path to authority than onboarding.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL3 — Identity Assurance Level 3 | Recovery and rebinding need strong assurance when account authority and assets can be restored. |
| AAL3 — Authenticator Assurance Level 3 | Device rebinding and recovery should preserve or exceed the authenticator strength used at enrolment. | |
| SP 800-63B — Digital Identity Guidelines, Authentication and Lifecycle | The subject is lifecycle assurance across enrolment, recovery, and authenticator binding. | |
| Recommendation — Require high-assurance reproofing before restoring control of a high-value exchange account. Use phishing-resistant authenticators for recovery paths that can rebind account control. Align recovery and enrolment to the same lifecycle assurance standard. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Recovery can reactivate or rebind access after trust should have been removed. |
| NHI-04 — Insecure Authentication | Weak recovery or rebinding can bypass the original authentication standard. | |
| Recommendation — Revoke and revalidate recovery paths when control is transferred or reset. Harden recovery so it cannot authenticate lower than initial enrolment. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | High-assurance identity proofing and reauthentication matter when control can be restored. |
| IA-5 — Authenticator Management | Recovery often replaces or resets authenticators and must be tightly governed. | |
| Recommendation — Enforce strong reauthentication before restoring sensitive account control. Manage reset, replacement, and revocation of authenticators with strict controls. | ||
Practitioner Guidance
What to verify: Check whether recovery and device rebinding require the same evidence quality, step-up checks, and approval thresholds as the highest-risk onboarding path. If not, treat that gap as a design flaw, not an operational exception.
Decision rule: If the recovery flow can restore access to assets, withdrawal rights, or security settings, require assurance that is equal to or higher than onboarding, and add stronger controls where recovery can overwrite an existing trusted factor.
What good looks like: Recovery events are rare, auditable, time-bounded, and hard to complete without fresh proof of control, with clear separation between low-risk account repair and high-risk authority restoration.
Practitioner takeaway: For exchanges, recovery is not a weaker version of onboarding, it is a second chance to seize the account, so the assurance bar should rise with the value and authority the recovery flow can restore.