Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


If a crypto withdrawal address was changed without your permission, treat the exchange account as potentially compromised. Preserve the exact address and timeline, use the provider's official lock or transfer restriction, secure email and authentication, revoke every access path, and inspect pending and completed withdrawals before changing evidence.
Key Takeaways
- Do not send a test transfer to the changed address and do not copy it into a new transaction.
- Distinguish an address-book edit from a pending withdrawal, completed transfer, or poisoned wallet history.
- An API key with address-management permission can create persistence outside the normal web session.
- Preserve the complete address privately, transaction IDs, alerts, timestamps, and security changes.
- Use only the exchange's official support and recovery routes; no legitimate helper needs your seed phrase.
Start by identifying the object that changed. A custodial exchange may store an address book, an allowlist of approved withdrawal destinations, a one-time withdrawal destination, a fiat payout beneficiary, or an API-managed destination. These records have different security effects and waiting periods.
This guide covers an unauthorized change inside a custodial exchange account. It is not the same as a look-alike address inserted into a self-custody wallet's transaction history, nor is it the same as copying the wrong deposit address before sending. Use the deposit-address verification checklist for a pre-send comparison and the online security guide for wider account recovery.
Classify the event before deleting anything:
| Observation | Likely object | Immediate question |
|---|---|---|
| New saved destination | Address book or allowlist entry | Who added it, when, and through which access path? |
| Existing label now points elsewhere | Edited saved record | Is the full address different or only the display label? |
| Withdrawal request uses a new address | Transaction destination | Is it pending, held, canceled, broadcast, or completed? |
| History shows a similar address | Possible address poisoning | Was the exchange record changed, or was a look-alike copied? |
| API log shows an address action | Programmatic credential | Which key and permissions performed it? |
Kraken documents that an API permission can add and remove withdrawal addresses without logging in through the website or app. It warns that combining address-management and withdrawal permissions increases the impact of a compromised key.[1] Coinbase documents exchange address-book and whitelisting controls, illustrating why a saved destination and its activation state must be checked separately.[2]
Open the exchange through its official app, a typed address, or a trusted bookmark. Do not follow a security-alert link, call an advertised “support” number, or share your screen with an unsolicited helper. Work from a trusted device when possible.
Preserve:
Keep complete addresses in a private incident record. When speaking in a public forum, shorten them carefully so you do not expose account history or invite impersonation. Never rely on the first and last characters alone to prove two long addresses match; compare the full value with a trusted source.
Do not remove the suspicious entry before preserving it unless deletion is the only available way to stop an imminent transfer. If the platform offers an emergency lock that pauses transfers, use it first and capture evidence afterward.
Move in this order:
Do not send funds to the changed address to discover who controls it. Do not move assets to an address supplied by a caller, chat agent, recovery company, or social-media account. A genuine provider does not need your wallet seed phrase or private key to secure a custodial exchange account.
If a withdrawal is pending, use the provider's cancel or freeze option if available, but do not assume cancellation is possible. If it has been broadcast, record the transaction hash, asset, network, amount, destination, and time. Blockchain settlement may be irreversible even when the account compromise can still be contained.
An address change is the outcome, not necessarily the entry point. Build a timeline that includes email access, device authorization, password resets, MFA changes, sessions, API keys, and connected applications.
Investigate these paths:
If an API key may be involved, follow the separate exchange API-key leak response. Revoking a browser session is not enough. Conversely, an address-book problem does not prove that a private wallet's seed phrase is compromised; keep custody boundaries clear.
Do not unlock money movement merely because the suspicious address disappeared. Verify the account as a system:
When rebuilding an allowlist, source the destination from a channel you already trust and compare the complete network-specific address. The withdrawal-address whitelist guide explains activation and lock behavior; a disabled control is covered separately in exchange withdrawals disabled.
No. A test can create another irreversible loss and does not establish who controls the address. Preserve it as evidence and use official account controls.
The full value determines the destination, but an unauthorized label change is still evidence of account access. Preserve both and review other settings and activity.
Some exchanges expose that permission. Review every key's permissions and recent use and revoke any key you cannot verify.
First use an emergency lock or transfer restriction when available and preserve the record. Delete or disable the address after evidence capture unless removal is the only way to stop imminent use.
Save the transaction hash and complete details, keep the account restricted, and contact official support. Do not trust anyone who guarantees recovery in exchange for an upfront transfer or secret.
Not by itself. A custodial exchange address book, an exchange API key, a copied address, and a wallet seed phrase are separate trust boundaries and need separate evidence.
Use the recipient's authoritative channel, verify the exact asset and network, compare the complete address, and follow the provider's allowlist process. Do not rely only on a familiar label.
Provide timestamps, the full address through the provider's private case system, asset/network, transaction IDs, alerts, session/API evidence, and actions taken. Never provide passwords, private keys, seed phrases, or one-time codes.
Disclaimer: This article provides general security information, not financial, investment, legal, or professional incident-response advice. Exchange controls and recovery options vary, and blockchain transfers may be irreversible.
Sources:
Sources checked 12 September 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.





