Crypto Withdrawal Address Was Changed: What to Do

Crypto Withdrawal Address Was Changed: What to Do

Natalie Moore
September 12, 2026· 9 min read

If a crypto withdrawal address was changed without your permission, treat the exchange account as potentially compromised. Preserve the exact address and timeline, use the provider's official lock or transfer restriction, secure email and authentication, revoke every access path, and inspect pending and completed withdrawals before changing evidence.

Key Takeaways

  • Do not send a test transfer to the changed address and do not copy it into a new transaction.
  • Distinguish an address-book edit from a pending withdrawal, completed transfer, or poisoned wallet history.
  • An API key with address-management permission can create persistence outside the normal web session.
  • Preserve the complete address privately, transaction IDs, alerts, timestamps, and security changes.
  • Use only the exchange's official support and recovery routes; no legitimate helper needs your seed phrase.

If your crypto withdrawal address was changed, what kind of change was it?

Start by identifying the object that changed. A custodial exchange may store an address book, an allowlist of approved withdrawal destinations, a one-time withdrawal destination, a fiat payout beneficiary, or an API-managed destination. These records have different security effects and waiting periods.

This guide covers an unauthorized change inside a custodial exchange account. It is not the same as a look-alike address inserted into a self-custody wallet's transaction history, nor is it the same as copying the wrong deposit address before sending. Use the deposit-address verification checklist for a pre-send comparison and the online security guide for wider account recovery.

Classify the event before deleting anything:

ObservationLikely objectImmediate question
New saved destinationAddress book or allowlist entryWho added it, when, and through which access path?
Existing label now points elsewhereEdited saved recordIs the full address different or only the display label?
Withdrawal request uses a new addressTransaction destinationIs it pending, held, canceled, broadcast, or completed?
History shows a similar addressPossible address poisoningWas the exchange record changed, or was a look-alike copied?
API log shows an address actionProgrammatic credentialWhich key and permissions performed it?

Kraken documents that an API permission can add and remove withdrawal addresses without logging in through the website or app. It warns that combining address-management and withdrawal permissions increases the impact of a compromised key.[1] Coinbase documents exchange address-book and whitelisting controls, illustrating why a saved destination and its activation state must be checked separately.[2]

What evidence should you save immediately?

Open the exchange through its official app, a typed address, or a trusted bookmark. Do not follow a security-alert link, call an advertised “support” number, or share your screen with an unsolicited helper. Work from a trusted device when possible.

Preserve:

  1. The complete changed address, asset, network, destination tag or memo, label, and status.
  2. Creation or modification time, displayed time zone, activation delay, and any confirmation method.
  3. Email, SMS, push, or in-app alerts, including full sender and message metadata.
  4. Pending, canceled, failed, and completed withdrawal records and their transaction IDs.
  5. Session/device entries, IP/location clues, API-key activity, connected apps, and security-setting changes.
  6. Support case numbers, account-lock confirmation, and the exact controls you used.

Keep complete addresses in a private incident record. When speaking in a public forum, shorten them carefully so you do not expose account history or invite impersonation. Never rely on the first and last characters alone to prove two long addresses match; compare the full value with a trusted source.

Do not remove the suspicious entry before preserving it unless deletion is the only available way to stop an imminent transfer. If the platform offers an emergency lock that pauses transfers, use it first and capture evidence afterward.

How do you contain an unauthorized withdrawal address?

Move in this order:

  1. Lock or restrict the exchange account. Use the official compromised-account or transfer-control feature. Coinbase documents a security lock that signs devices out and pauses transfers and account changes while retaining review and support access.[3] Other exchanges may provide different effects.
  2. Secure the primary email. Change to a unique password, end unknown email sessions, remove suspicious forwarding and recovery changes, and enable strong MFA.
  3. Change the exchange password. Do this on a trusted device and do not reuse the email password.
  4. Replace exposed MFA and recovery material. Remove unknown authenticators, passkeys, security keys, phone numbers, and recovery methods.
  5. Revoke web sessions and authorized devices. Record suspicious entries before removal.
  6. Revoke API keys and connected applications. Pay special attention to address-management, withdrawal, trading, and account-modification permissions.
  7. Review every money-moving setting. Check allowlists, newly added addresses, fiat beneficiaries, bank accounts, card funding, internal transfers, and pending withdrawals.
  8. Contact official support. Give the evidence package and ask for server-side records or holds available under the provider's policy.

Do not send funds to the changed address to discover who controls it. Do not move assets to an address supplied by a caller, chat agent, recovery company, or social-media account. A genuine provider does not need your wallet seed phrase or private key to secure a custodial exchange account.

If a withdrawal is pending, use the provider's cancel or freeze option if available, but do not assume cancellation is possible. If it has been broadcast, record the transaction hash, asset, network, amount, destination, and time. Blockchain settlement may be irreversible even when the account compromise can still be contained.

How do you investigate the access path?

An address change is the outcome, not necessarily the entry point. Build a timeline that includes email access, device authorization, password resets, MFA changes, sessions, API keys, and connected applications.

Investigate these paths:

  • Stolen login: an attacker used the password and possibly a verification code, then changed the destination through the account UI.
  • Compromised email: the attacker approved a new device, intercepted alerts, or reset exchange credentials.
  • API credential: a key with address-management permission added or removed destinations programmatically.[1]
  • Malicious endpoint: malware, a remote-access tool, or a browser extension captured credentials or replaced copied addresses.
  • Third-party service: a trading bot, portfolio tool, or tax application stored an over-privileged key.
  • Authorized household or business user: another legitimate operator made the change without a shared change-control record.

If an API key may be involved, follow the separate exchange API-key leak response. Revoking a browser session is not enough. Conversely, an address-book problem does not prove that a private wallet's seed phrase is compromised; keep custody boundaries clear.

What should you verify before restoring withdrawals?

Do not unlock money movement merely because the suspicious address disappeared. Verify the account as a system:

  • Primary email sessions, forwarding, recovery methods, password, and MFA are known.
  • Exchange password, MFA, passkeys, recovery codes, devices, and sessions are controlled.
  • Every API key and connected app has an owner, purpose, minimum permissions, and recent-use record.
  • Address books and allowlists contain only independently verified destinations.
  • Pending and completed withdrawals reconcile with your own records.
  • No unexpected trade, conversion, beneficiary, profile, phone, or identity change remains.
  • The device used for recovery has no credible sign of remote control, malicious extension, or credential theft.
  • Official support has logged the incident and explained any unresolved record or hold.

When rebuilding an allowlist, source the destination from a channel you already trust and compare the complete network-specific address. The withdrawal-address whitelist guide explains activation and lock behavior; a disabled control is covered separately in exchange withdrawals disabled.

Summary

  • Identify whether the change affected an address book, allowlist, transaction, or API-managed destination.
  • Preserve complete address and timeline evidence before cleanup when containment allows it.
  • Restrict the account, secure email and authentication, and revoke sessions, devices, keys, and apps.
  • Trace pending and completed money movement without sending a test or rescue transfer.
  • Restore withdrawals only after the full access and destination inventory is reconciled.

Frequently Asked Questions

Should I send a small test to the changed address?

No. A test can create another irreversible loss and does not establish who controls the address. Preserve it as evidence and use official account controls.

Is changing the address label as serious as changing the address?

The full value determines the destination, but an unauthorized label change is still evidence of account access. Preserve both and review other settings and activity.

Can an API key change withdrawal addresses?

Some exchanges expose that permission. Review every key's permissions and recent use and revoke any key you cannot verify.

Should I delete the address immediately?

First use an emergency lock or transfer restriction when available and preserve the record. Delete or disable the address after evidence capture unless removal is the only way to stop imminent use.

What if a withdrawal already reached the blockchain?

Save the transaction hash and complete details, keep the account restricted, and contact official support. Do not trust anyone who guarantees recovery in exchange for an upfront transfer or secret.

Does an address change mean my self-custody wallet is compromised?

Not by itself. A custodial exchange address book, an exchange API key, a copied address, and a wallet seed phrase are separate trust boundaries and need separate evidence.

How can I verify a restored address safely?

Use the recipient's authoritative channel, verify the exact asset and network, compare the complete address, and follow the provider's allowlist process. Do not rely only on a familiar label.

What information should I give support?

Provide timestamps, the full address through the provider's private case system, asset/network, transaction IDs, alerts, session/API evidence, and actions taken. Never provide passwords, private keys, seed phrases, or one-time codes.

Disclaimer: This article provides general security information, not financial, investment, legal, or professional incident-response advice. Exchange controls and recovery options vary, and blockchain transfers may be irreversible.

Sources:

  1. Kraken — Add Withdrawal Addresses API Permission — https://support.kraken.com/gb/articles/withdrawal-addresses-api-permission
  2. Coinbase — Address book and crypto withdrawal address whitelisting — https://help.coinbase.com/en/exchange/managing-my-account/address-book-and-crypto-withdrawal-address-whitelisting
  3. Coinbase — Lock or unlock your compromised account — https://help.coinbase.com/en/coinbase/privacy-and-security/account-compromised/my-account-was-compromised

Sources checked 12 September 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

Crypto Withdrawal Address Was Changed: What to Do | AethoVPN