Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


When a crypto exchange session will not log out remotely, first determine whether you are looking at a web session, an authorized device, an API key, or a connected application. Preserve the record, use the exchange's official revoke or account-lock control, then confirm the result from a trusted device and close every other access path.
Key Takeaways
- A device record and a live browser session are not always the same object.
- A stale activity page can keep showing a revoked entry, so verify state after a fresh sign-in.
- Password changes must not be assumed to invalidate API keys, OAuth grants, or every token.
- If the session is suspicious, secure email and MFA and restrict transfers before extended troubleshooting.
- Support needs timestamps, session identifiers, and attempted actions—not your password or one-time code.
“Session” is often used loosely. An exchange may separately track web cookies, mobile-app installations, trusted devices, remembered browsers, API credentials, and third-party connections. Removing one record may leave another valid. The activity page may also show historical devices or update after a delay.
Kraken documents a Device Management view that lists active devices, authorization times, location/IP clues, and controls to deactivate one or all devices.[1] Coinbase describes separate web sessions and confirmed devices, with controls for individual or broad revocation.[2] The exact labels are provider-specific, so read the heading and help text before assuming a failed logout.
Common explanations include:
| What you see | Possible explanation | Verification |
|---|---|---|
| Entry remains after clicking revoke | Cached or delayed activity view | Sign out locally, reopen the official service, and refresh the activity page |
| Device disappears but activity continues | Separate web token, API key, or connected app | Review every access category and new account events |
| Device returns immediately | App automatically signs in, syncs, or reauthorizes | Close the app on that device if owned; otherwise lock the account |
| “Last active” changes | Token is still being used or the timestamp has another meaning | Preserve exact times and ask support to interpret the field |
| Revoke control errors | Network/UI failure, permissions, or provider incident | Record the error and use an official emergency lock if risk is material |
Start with the online security guide for the wider account layers. The technical difference between password theft and token theft is covered in session hijacking.
Use a device you trust and open the exchange independently. Avoid links in email, text messages, advertisements, search-result support numbers, or direct messages. If the potentially compromised device is your only device, do not install remote-support software or share its screen with a stranger.
Record these fields when available:
Evidence matters because repeated clicks can erase the distinction between an initial compromise and your own recovery activity. However, do not delay a provider's emergency account lock to perfect the record when a withdrawal or settings change is underway.
Treat revocation and verification as separate steps:
A successful result means more than a toast message. The suspicious entry is inactive or absent according to the provider's current view, no new activity is attributable to it, and no alternate credential remains. If the page does not explain whether it is historical, support must clarify that distinction.
Do not attempt to “test” the remote session by messaging whoever might control it. Do not share a login code to force a logout. Never send funds to a “safe” address as part of session removal.
Escalate from narrow revocation to account containment:
Do not rely on password rotation as the only step. An API key can be independent of a browser password; a connected application can hold its own grant; and a stolen endpoint can capture the replacement credential. If new sessions keep appearing, inspect the trusted device for malicious extensions, remote-control tools, information-stealing malware, or a compromised password manager.
Use a layered exit checklist rather than a quiet screen:
If financial activity is disputed, keep recovery and transaction evidence separate. The article on a leaked exchange API key covers key permissions and programmatic access. If the initial clue was a new device, follow the unknown-device attribution checklist.
Changing the network path does not invalidate an exchange token. A VPN cannot revoke sessions, disable API keys, lock an exchange account, or confirm that server-side logout succeeded.
It may be cached, delayed, or retained as history. Refresh through a new trusted login and ask official support whether the entry is active if the interface does not say.
Not necessarily. A provider may store device authorization separately from browser cookies, mobile tokens, API keys, and third-party grants.
Do not assume so. Use the provider's explicit all-session and all-device controls, then review API keys and connected apps separately.
No. Record the first result, refresh deliberately, and escalate through the official lock or support path if the state remains uncertain. Rapid retries can obscure evidence.
An owned app may be reauthorizing, or an attacker may still control email, credentials, MFA, an endpoint, or an API key. Restrict the account and investigate every persistence layer.
Yes, depending on the platform. Treat API credentials as a separate access category and revoke unknown or unnecessary keys explicitly.
Lock or restrict it when the session is unexplained and funds, security settings, email, or identity data may be exposed, especially if unknown actions continue.
Send the session/device identifiers, timestamps with time zone, screenshots, errors, related account events, and steps already taken. Never send a password, seed phrase, recovery code, or one-time code.
Disclaimer: This article provides general security education, not financial, investment, legal, or professional incident-response advice. Session terminology and emergency controls vary by exchange.
Sources:
Sources checked 12 September 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.