Crypto Exchange Login Shows an Unknown Device

Crypto Exchange Login Shows an Unknown Device

Natalie Moore
September 12, 2026· 9 min read

If your crypto exchange login shows an unknown device, treat it as a signal to investigate, not automatic proof that funds were stolen. Open the exchange through its official app or a saved bookmark, preserve the alert, compare the device with your own activity, and contain the account immediately if any detail or action remains unexplained.

Key Takeaways

  • Do not use a link, phone number, or approval button inside an unexpected message.
  • A changed browser profile, cleared cookies, new phone, or different IP can create a legitimate new-device record.
  • An unfamiliar device plus an unknown trade, address change, API key, or withdrawal is a high-risk combination.
  • Secure the primary email as well as the exchange account because email often controls recovery.
  • Preserve evidence before removing records, but use the provider's emergency lock without delay when funds may be at risk.

What does it mean when a crypto exchange login shows an unknown device?

The label usually means the service has recorded a browser, app installation, or authorized device that it does not match to a familiar login state. It does not necessarily identify a physical phone or computer with forensic certainty. A browser update, private window, cleared cookies, restored phone, new app installation, or separate browser profile can look new even on hardware you own.

Network details are also clues rather than identity proof. Mobile carriers, corporate gateways, shared internet connections, and VPN endpoints can change the visible IP address or approximate location. A location that is off by a city is weaker evidence than a device type you do not own, a login while you were offline, or account activity you did not perform.

Coinbase says an unexpected device-confirmation message can mean someone used the password and a two-step verification code to begin signing in, and it recommends reviewing sessions and strengthening both exchange and email credentials.[1] Kraken documents that its device view can show authorization time and associated location/IP and can deactivate individual or all devices.[2] These are provider-specific examples; your exchange may use different names and controls.

Review the broader online security guide if the alert is part of a wider account incident. If you already see actions you did not perform, use the incident sequence in someone logged into my account rather than spending time explaining every location label.

Which evidence should you preserve first after an unknown device login?

Start from a device you trust. Type the known exchange address yourself, use a saved bookmark, or open the installed app. Do not reply to the alert, call a number in it, or enter a code after following its link. A convincing message can be phishing even when the underlying account alert is real.

Capture enough evidence to reconstruct the event:

EvidenceWhat to recordWhy it matters
AlertFull sender, delivery time, subject, and message identifiersHelps support distinguish a real notification from phishing
Device entryDevice or browser label, authorization time, last activityTests whether it matches a reinstall or profile change
Network clueIP and approximate location shown by the providerUseful for correlation, but not proof of a person
Account activityLogins, trades, withdrawals, address-book edits, security changesReveals whether access progressed beyond authentication
Recovery stateEmail forwarding, recovery methods, MFA changesShows whether the attacker could regain access
API accessNew keys, changed permissions, connected applicationsFinds access that may survive a normal web logout

Use screenshots or an export if the official interface provides one, but do not publish account IDs, full balances, recovery codes, or complete wallet addresses. Record exact times with the time zone. If an address matters, save the complete value privately and use a shortened copy only in ordinary notes.

How can you decide whether the device is yours?

Work through a short attribution test instead of trusting one field:

  1. Match the authorization time against your own sign-in, app installation, browser reset, phone replacement, or operating-system restore.
  2. Compare the browser and operating-system family. A generic label can be imprecise, but an impossible platform is meaningful.
  3. Compare the IP with your router, mobile carrier, workplace, or VPN history when that information is available.
  4. Check whether the session performed any action after login, including viewing security settings, creating an API key, editing an address, trading, or requesting a withdrawal.
  5. Look for related email events such as password-reset requests, forwarding-rule changes, unfamiliar recovery prompts, or deleted security messages.
  6. Treat the device as unauthorized if you cannot explain it promptly and the account exposes funds or sensitive identity records.

Do not approve a new-device prompt merely to see what happens. Do not ask an unknown caller or chat contact whether the login was theirs. A real support agent should not need your password, seed phrase, remote-control access, or one-time code.

A cluster of weak clues can become strong evidence. For example, an approximate location mismatch alone may be benign. The same mismatch combined with a new API key and a withdrawal-address change warrants immediate containment.

How do you contain an unrecognized crypto exchange login?

When the device is not yours—or you cannot safely decide—prioritize stopping transfers over perfect diagnosis:

  1. Use the provider's official lock or restriction control. Coinbase documents that its security lock signs devices out and pauses trading, transfers, and account changes while leaving review and support available.[3] Other providers may expose a different emergency process.
  2. Secure the primary email from a trusted device. Change its password to a new unique value, end unknown email sessions, remove unauthorized forwarding or recovery methods, and enable strong MFA.
  3. Change the exchange password. Never reuse the new email password. Store both in a password manager if possible.
  4. Replace compromised MFA. Remove unknown authenticators or security keys, regenerate recovery codes, and prefer a phishing-resistant method when the exchange supports it.
  5. Deactivate unknown devices and sessions. Record each entry first, then revoke individual entries or all other access.
  6. Revoke API keys and connected apps you cannot verify. A key can preserve programmatic access even after a browser session ends.
  7. Inspect money-moving controls. Review new withdrawal addresses, allowlists, bank details, trades, conversions, and pending withdrawals.
  8. Contact support through the official help center. Provide timestamps and case-relevant identifiers, not passwords or recovery secrets.

If you cannot enter the account, secure email first and use the provider's official compromised-account or recovery channel. Do not create a second account to contact a person who claims they can recover funds. Do not send crypto as a “verification,” “unlock,” or “safe wallet” step.

What should you check after access is contained?

Containment stops the immediate path; recovery determines what changed and what still has access. Build a timeline from the first alert through the last verified action. Compare exchange activity with email security logs and device history. Preserve support case numbers and provider confirmations.

Review these categories separately:

  • Authentication: passwords, MFA methods, recovery codes, remembered devices, passkeys, and security keys.
  • Persistence: browser sessions, mobile sessions, API keys, OAuth or connected apps, trading bots, and tax tools.
  • Money movement: pending and completed withdrawals, address-book entries, allowlists, fiat payout methods, and conversions.
  • Identity: profile, phone number, legal name, verification documents, and support messages.
  • Endpoint risk: browser extensions, remote-access software, malware alerts, clipboard history, and unexpected configuration profiles.

If repeated prompts continue after credentials are rotated, investigate the endpoint and email account before unlocking transfers. MFA fatigue attacks rely on repeated requests until a user approves one. Session hijacking explains why a stolen token and a stolen password are different problems.

Changing networks can alter the IP and location evidence shown by an exchange. AethoVPN can change that network path, but it cannot authenticate a device, prove an account takeover, revoke exchange access, or change the exchange's security controls.

Summary

  • Treat an unknown device as an investigation signal and use account actions to calibrate urgency.
  • Enter through the official service independently and preserve alerts, device records, and activity before cleanup.
  • Lock or restrict the account quickly when funds or settings may be exposed.
  • Secure email, passwords, MFA, sessions, devices, API keys, and withdrawal controls as separate layers.
  • Rely on provider support and complete records, never a stranger offering recovery through chat.

Frequently Asked Questions

Can a VPN make my own device appear unknown?

A VPN can change the public IP and approximate location seen by a service. It does not normally change the physical device, but a new IP combined with cookies, browser-profile, or app-state changes may contribute to a new-device challenge.

Is an unfamiliar city proof that someone logged in?

No. IP location is approximate and can reflect a carrier gateway, office, or VPN endpoint. Compare time, platform, device authorization, and account actions before attributing the login.

Should I click “this was not me” in the email?

Open the official app or bookmarked website independently instead. That avoids giving a phishing message control over the destination, phone number, or credentials you use.

What if the device is mine but the login time is wrong?

Check the displayed time zone, whether the value is authorization time or last activity, and whether the app was restored or reinstalled. If the timing remains unexplained, revoke it and secure the account.

Does changing my password remove every session?

Do not assume it does. Use the provider's explicit device/session controls and review API keys and connected apps separately.

Should I delete the unknown device before taking screenshots?

Preserve the entry first if doing so does not delay an emergency lock. When transfers may be at risk, containment takes priority over collecting a perfect record.

What if I see an unknown withdrawal as well?

Lock or restrict the account immediately, preserve the transaction and destination details, secure email and authentication, and contact official support. Do not send another transfer to test the address.

Can support ask for my one-time code or seed phrase?

Do not disclose either. Use only the provider's official support route and treat any request for a seed phrase, password, remote-control session, or “safe wallet” transfer as hostile.

Disclaimer: This article provides general security education, not financial, investment, legal, or professional incident-response advice. Exchange controls and recovery procedures vary by provider and jurisdiction.

Sources:

  1. Coinbase — Why did I receive an unexpected device confirmation email? — https://help.coinbase.com/en/pro/privacy-and-security/avoiding-phishing-and-scams/why-did-i-receive-an-unexpected-device-confirmation-email
  2. Kraken — Where can I see my connected devices? — https://support.kraken.com/articles/360048970351-where-can-i-see-my-connected-devices-
  3. Coinbase — Lock or unlock your compromised account — https://help.coinbase.com/en/coinbase/privacy-and-security/account-compromised/my-account-was-compromised

Sources checked 12 September 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

Crypto Exchange Login Shows an Unknown Device | AethoVPN