Cryptocurrency businesses are exposed because digital asset transfers are difficult to reverse, so fraud losses can become permanent quickly. Attackers also exploit weak verification, stolen phone identities, and social engineering to take over accounts and move funds. Once a scam succeeds, the business absorbs both direct loss and reputational damage, while customers often have little practical recourse.
Why crypto exchange accounts are easier to take over
Crypto exchanges concentrate a large amount of immediately movable value behind a single online login, so attackers only need one weak account path to reach funds. Compared with traditional banking, the friction to initiate transfers is often lower, the finality is higher, and the response window is much shorter once credentials, sessions, or recovery channels are abused.
That changes the attacker’s economics. A compromise does not need to become a long fraud campaign to succeed, and a scammer can often cash out through fast transfers, chain hops, or external wallets before the victim or exchange can intervene. Even when an exchange has good back-office controls, the user-facing account remains a high-value target for phishing, SIM swap, and social engineering.
The GitLocker GitHub extortion campaign and Zacks Investment Research breach are useful reminders that credential theft and account abuse scale quickly when an attacker can reuse stolen access before it is revoked.
Why scam losses are harder to unwind in crypto than in traditional finance
Traditional financial services usually sit inside more mature dispute, reversal, and consumer-protection processes. Crypto transfers are often designed to be final once they settle, which means the business and the customer may have little practical way to claw back funds after a successful scam. That finality makes the first mistake much more expensive.
Scammers also benefit from the fact that many crypto platforms blur the line between account access and value movement. If an attacker can defeat verification, intercept a reset flow, or persuade support staff, the resulting transfer may look like a legitimate customer action. Once the asset leaves the platform, tracing it is possible, but recovery is much less certain than with card disputes or bank fraud workflows.
For exchanges, this also creates a reputational and operational burden. A single successful scam can generate support load, complaints, regulatory attention, and customer trust erosion, even when the exchange itself did not directly lose the funds. The business is judged on both prevention and containment, not just on whether the blockchain transfer was technically authorised.
What makes crypto fraud patterns different from bank fraud
Traditional banks typically combine layered authentication, transaction monitoring, and established liability rules that slow down or absorb some fraud outcomes. Crypto exchanges may have similar controls, but they face a harsher environment because attackers target the weakest point in the chain: user identity recovery, support processes, mobile numbers, and session control. Those are often easier to manipulate than a properly governed bank transfer rail.
Another difference is that crypto customers often self-custody part of their journey, which increases the number of places where mistakes or coercion can occur. A scam may start on the exchange, but it often ends in a wallet transfer that the exchange cannot recall. That creates a narrower defensive window and a stronger need for real-time anomaly detection, step-up verification, and transaction hold logic when behaviour deviates from the norm.
The PCI DSS v4.0 emphasis on least privilege and system-account governance, and the EU Digital Operational Resilience Act (DORA) focus on operational resilience and incident handling, both reflect the same reality: high-value financial systems need controls that reduce abuse and preserve recovery options.
Risk and Threat Considerations
Crypto exchanges are attractive because account takeover can turn directly into immediate asset theft, and the loss path is often faster than detection and recovery. Attackers exploit weak identity proofing, support-channel manipulation, and mobile-number compromise because those paths can be simpler than attacking the exchange core directly.
Failure mechanism: A scammer compromises login, reset, or support workflows, then moves assets before risk signals, manual review, or customer escalation can stop the transfer.
Impact: The exchange may face unrecoverable customer loss, chargeback-like disputes without equivalent reversal rights, elevated support cost, and loss of trust that can outlast the incident itself.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Stolen credentials and tokens drive exchange account takeover. |
| NHI-04 — Insecure Authentication | Weak verification and reset flows enable takeover and scam abuse. | |
| NHI-05 — Overprivileged NHI | Excessive support or service access can amplify account abuse. | |
| Recommendation — Protect exchange secrets and tokens from leakage and reuse. Harden authentication and recovery for high-value exchange accounts. Restrict privileged exchange access to the minimum required scope. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Exchange APIs and sessions must resist stolen or replayed credentials. |
| Recommendation — Enforce strong API authentication and session binding. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle and reset abuse are central takeover paths. |
| AC-6 — Least Privilege | Limit support and system access that could move funds or override checks. | |
| AU-6 — Audit Review, Analysis, and Reporting | Fraud detection depends on rapid review of anomalous account activity. | |
| Recommendation — Rotate and protect authenticators through their full lifecycle. Minimise privileges for staff, services, and recovery workflows. Review anomalous transfer and recovery events quickly. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account lifecycle control is critical where takeover leads to irreversible loss. |
| Recommendation — Inventory, review, and disable risky exchange accounts promptly. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | The subject is driven by account access, recovery, and authorisation abuse. |
| Recommendation — Strengthen identity and access controls around high-value transfer actions. | ||
Practitioner Guidance
What to prioritise: Treat account recovery, phone-number changes, and outbound transfer authorisation as the highest-risk paths, because those are the points attackers most often weaponise when they cannot break primary authentication. If those paths are weak, stronger password policy alone will not materially reduce takeover risk.
What to verify: Confirm that high-risk actions trigger step-up verification, delay or hold logic, and strong customer-visible alerts, and that support staff cannot override those controls without a recorded exception path. Good control design is visible in the difficulty of moving funds quickly after a suspicious reset or device change.
Practitioner takeaway: Crypto fraud is severe because the platform is defending both identity and final asset movement at the same time; the winning strategy is to slow irreversible actions, harden recovery paths, and make unusual transfers observable before they settle.
Related resources from NHI Mgmt Group
- Why do weak session controls and missing MFA create such high account takeover risk?
- Why do breaches involving learning platforms create such a high risk of spear phishing and account takeover?
- Why do ransomware and AI-driven attacks create such high risk for financial services?
- Why does account takeover create such a high business and security risk for organisations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org