Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


If a crypto exchange requires identity verification again, it does not necessarily mean your original verification failed. An exchange may periodically confirm customer information, react to a profile change, review risk, or request a liveness check for a particular action. It could also be phishing. Verify the request inside an official account before disclosing anything.
Key Takeaways
- Open the exchange yourself; do not start from an email, text, search ad, QR code, or support direct message.
- Read whether the request is a profile confirmation, document re-verification, liveness check, or separate source-of-funds review.
- Submit only the stated fields through the authenticated official flow.
- Preserve the notice, deadline as displayed, case number, and status without assuming a universal review time.
- Never provide passwords, MFA codes, seed phrases, private keys, or remote device access.
Use the online security guide to secure the email, password, MFA, and recovery channels connected to the account.
It usually means the exchange is refreshing its records, because customer information can become outdated. FATF guidance describes ongoing due diligence and keeping customer data relevant and current as part of a risk-based framework.[1] Coinbase explains that customers may need to confirm personal information or complete additional verification, including after certain country changes.[2] These principles do not establish one timetable or guarantee approval.
| Request shown | What it usually checks | What to verify first |
|---|---|---|
| Confirm personal information | Address, occupation, purpose, or expected activity | Which fields changed and why they are requested |
| Re-submit identity document | Current identity and document validity | Accepted document, expiry, issuing country, and upload route |
| Liveness check | A live person is present for a sensitive action | Whether it is tied to the action you initiated |
| Full re-verification | Identity profile is being reviewed again | Scope, deadline, restrictions, and official case reference |
| Source-of-funds request | Origin and context of particular money | Use the separate evidence workflow, not extra identity uploads |
Kraken states that a liveness check is not the same as account re-verification: it uses a real-time face image for certain actions and does not by itself require document submission.[3] Read the label shown by your provider instead of treating every camera request as “KYC again.”
Close the message. Type the known official domain, use a saved bookmark, or open the installed app from the device launcher. Check the notification center and verification page after signing in. If no matching request exists, contact support from that authenticated session.
Inspect the sender and destination without clicking. Look for misspelled domains, URL shorteners, attachments, urgent threats, unusual payment demands, browser-extension installations, and requests to move the conversation to chat. A real-looking logo or correct personal detail does not prove authenticity.
Save the request type, fields, document list, displayed deadline and timezone, affected feature, status, and case number. Note whether the prompt appeared after a withdrawal, new device, password reset, country change, legal-name change, or no action you recognize.
Do not convert a narrow request into a broad disclosure. “Confirm your address” is not permission to upload a full bank statement if the official form does not ask for it. If wording is ambiguous, ask authenticated support to identify the minimum acceptable document and redaction rules.
Keep the original wording even if you contact support. A case agent may clarify the request, but a copied summary should not replace the authenticated prompt, field list, or document instructions you actually received.
Review the legal name, date of birth, residential address, nationality, tax residence if applicable, occupation, account purpose, and identity-document expiry shown in the account. Correct factual errors through the documented profile-change route. Do not invent an address, occupation, or travel status to obtain access.
A changed phone, device, IP address, or travel location can coincide with a review, but correlation does not prove the reason. Do not repeatedly change location settings or create another account. Ask the platform which profile item requires attention.
Use a supported, unexpired document that belongs to you. Before capture, remove unrelated papers from the frame and ensure no other person's document is visible. Follow the provider's rules for full edges, glare, focus, color, and file type; do not digitally alter the identity fields.
If proof of address is requested, choose an accepted recent document and redact unrelated transactions only when the provider permits it. If the request is actually about fund origin, use the source-of-funds document guide rather than uploading random identity material.
Update the official app or supported browser, close screen-sharing software, review active extensions, and use a device you control. Avoid public computers and shared scanners that retain copies. If you need network privacy while uploading sensitive documents, AethoVPN can protect traffic on the local network, but it cannot verify identity, make a request legitimate, or influence the exchange's decision.
The exchange still receives the submitted data and may record account, device, and connection signals. A VPN is not anonymity from the provider and should not be used to misrepresent your residence or bypass eligibility rules.
For a document capture, use even light, a plain background, and the original document. Make sure required corners and machine-readable areas are visible. For liveness, read the on-screen purpose and permissions, allow camera access only for the official flow, and close it when finished.
Do not send a selfie or document through ordinary email, social media, or a support agent's personal upload link unless the official authenticated case explicitly provides and documents that channel. Never let another person perform liveness on your behalf.
Record the submission time, confirmation screen, reference, file names, and current restriction. Do not publish the screenshot or repeatedly submit slightly different versions. Multiple attempts can make it harder to understand which package is under review.
Review times vary with provider, request, jurisdiction, and evidence quality. Use only the status and estimate shown in your account. If the displayed estimate passes or the case asks for a correction, reply within the same authenticated case with the missing item.
Check recent sign-ins, authorized devices, API keys, recovery changes, email forwarding rules, and MFA events. Revoke anything unfamiliar and preserve security alerts. If the account becomes restricted, follow the exchange account freeze checklist while keeping identity review and account security as separate evidence tracks.
Report the suspicious message through the provider's official abuse route. Do not argue with the sender or open its attachment to gather more evidence. A screenshot of the message headers and URL text is usually safer than interacting with it.
The platform may need current customer information, a renewed document, or a risk review. Only the authenticated notice can identify your case.
Not necessarily. A liveness check may confirm that a real person is present for one action, while re-verification may review identity documents and profile data.
Open the official site or app independently and find the matching request there. Do not rely on the message link.
Usually required identity fields must remain visible. Ask the official flow what redaction is permitted; do not alter a document in a way that misrepresents it.
There is no universal duration. Use the status and estimate displayed by your provider and keep the case reference.
Check support, expiry, lighting, glare, focus, file type, and whether all required edges are visible. Avoid repeated altered uploads.
No. It asks about the origin and context of money, although both reviews can occur together. Respond to each stated scope separately.
No. Do not disclose passwords, MFA codes, seed phrases, private keys, or remote access. Return to authenticated support and report the request.
Disclaimer: This article is for general informational purposes and is not legal, financial, investment, privacy, or platform-specific advice. Identity requirements, retention, review times, restrictions, and outcomes vary by provider and jurisdiction.
Sources checked 9 September 2026.
Related articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.





