Your email has been hacked. Your first instinct is to change the exchange password, and that's the right move. But if you've ever generated API keys, just changing the password may not be enough—depending on which exchange you use. Some platforms automatically invalidate old API keys when you change your password, while others don't, forcing you to manually delete them.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
Forget about your email for now. Log directly into your exchange and follow these steps.
Step 1: Log into the Exchange Immediately and Lock Withdrawal Rights
Before checking API keys, make sure your money can't leave.
What to do: Log into the exchange, go to the withdrawal page. If the platform supports "pause withdrawals" or "freeze withdrawals", activate it right away. If not, contact customer support to temporarily freeze withdrawals.
Completion standard: The withdrawal page shows "withdrawals paused" or a similar message.
Risk reminder: After your email is hacked, an attacker can not only try "forgot password" to take over your exchange account, but may also have already grabbed your API key information from old emails in your inbox. According to Binance's security advisory, once an attacker controls your primary email, they can use "forgot password" to reset all linked financial accounts.
Step 2: Check and Clean Up API Keys – Core Action
This step determines whether your account still has a backdoor.
What to do: Go to the exchange's API management page and view all generated API keys. Delete any key that wasn't recently created by you yourself, especially those with "withdrawal" permissions.
Completion standard: The API list is empty, or only keeps keys you know about and haven't leaked.
According to Binance's security guide, hackers may create API keys after compromising an account to automate withdrawals, so you must check and remove suspicious keys. Kraken also clearly states that API keys are equivalent to your username and password; whoever holds them can perform sensitive operations on your account, including placing orders and checking balances.
Case A: The Platform Automatically Invalidates Old APIs When You Change Your Password (e.g., Kraken)
Some platforms are stricter about this. When you change your password, old API keys are automatically revoked.
According to Kraken's official announcement, if a user changes their email or password, Kraken will log out the user's API Viewer and invalidate all outstanding refresh tokens. This means API users must re-authenticate to continue using the API.
What to do: Even if the platform has an auto-invalidation feature, you should still manually check the API list to confirm all keys are cleared or unusable.
Completion standard: API list is empty, or status shows "expired/disabled".
Case B: The Platform Does Not Automatically Invalidate Old APIs (Most Cases)
If your exchange doesn't have a similar mechanism, old API keys remain valid after a password change. This is the most dangerous scenario—attackers don't need to log in; they can just use the API key to withdraw your funds.
What to do: Do not rely on the "change password invalidates API" function. Go manually into the API management page and delete all API keys. If necessary, generate new keys and store them securely.
Completion standard: API key list is empty.
Step 3: Check and Remove Other Backdoors – Active Sessions and Third-Party Authorizations
API keys aren't the only entry point. You also need to check other channels that attackers might exploit.
What to do:
- Go to the "device management" or "active sessions" page and end all sessions that weren't initiated by you.
- Check third-party login authorizations linked to your account (such as Google, Telegram), and remove any suspicious ones.
- Check withdrawal whitelist addresses to make sure none have been replaced with unknown addresses.
Completion standard: All active sessions are from your own devices, and the third-party authorization list contains only accounts you intentionally linked.
Common Failure Reasons
Many people only change their exchange password after their email gets hacked and think they're safe. But the attacker may have already copied your API keys when they first broke into your email. API key permissions are independent of your login password. Changing the password doesn't necessarily invalidate the API keys. If you don't clean them manually, you're leaving a backdoor wide open for attackers.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
Verification After Completing the Steps
After finishing the above steps, go to the exchange's API management page and confirm that no unfamiliar keys appear in the list. If the platform offers API call history, check recent logs for any suspicious requests. Finally, open your email security settings, enable 2FA, and check "forwarding rules" and "auto-reply" in your email—attackers sometimes set up email forwarding to discreetly send all emails containing words like "exchange" or "withdrawal" to their own inbox.


