Unknown Sub-Account on Your Exchange: How to Isolate Main Account Assets

 / 
4

If you see an unfamiliar sub-account in your list, it means someone else has gained the ability to create sub-accounts on your account. Main and sub-accounts are separate—their funds and permissions are not shared. As long as you cut off the intruder's access right away, your main account assets cannot be moved out directly.

Step 1: Freeze the sub-account's fund transfer permission

The attacker's next step will be to transfer funds from your main account to that sub-account. Go to the exchange's "Sub-account management" page, find the unknown sub-account, and check whether "Fund transfer" is enabled. Turn it off immediately.

Success check: The sub-account's fund transfer feature is disabled, so no assets can be sent from your main account to that sub-account.

According to OKX, the main account holder can view and edit all security settings for sub-accounts, including fund transfer permissions, and only the main account can do so. Bybit also stresses that sub-accounts are completely isolated from the main account and other sub-accounts. The real risk is not that a sub-account can directly touch the main account's money, but that the attacker, using your main account identity, can move money into the sub-account. Focus on shutting down that path.

Step 2: End all active sessions and reset login credentials

A mysterious sub-account means your login password or session token has already been leaked. Go to your "Security settings" or "Device management" page, choose "End all sessions" or "Log out everywhere," and force every device to sign out. Then change your password immediately, and switch to an authenticator app (such as Google Authenticator) if you're using SMS two‑factor authentication.

Success check: Every device—including the intruder's—is logged out. Your password and 2FA are completely new.

Bitfinex explains that sub-accounts are created by logging into the main account. An unknown sub-account means the attacker was able to log in as you.

Step 3: Check and clean API keys

The attacker might have used an API key to create sub-accounts or move funds. Go to the API management page, remove any API keys you did not create yourself recently. Check every key's permissions, especially "withdraw" or "transfer" rights.

Success check: The API list is empty, or it contains only keys you know are safe.

OKX's API documentation notes that an API key can be linked to the main account or a specific sub-account. A compromised high‑permission key can control sub‑accounts directly through the API.

Step 4: Delete the unknown sub-account

Only after cleaning up the above should you delete the sub-account itself. Go back to sub-account management and choose to delete or remove the unknown entry. Some platforms (like OKX) may require you to do this on a web browser instead of the mobile app.

Success check: The unfamiliar sub-account disappears from your list and is no longer linked to your main account.

Common Mistake

Many people's first instinct is to delete the sub-account right away, skipping the steps that cut off transfer permissions and live sessions. If you delete before changing your password, clearing sessions, and removing API keys, the attacker can simply create a new sub-account again—making all your work pointless.

How to Verify Everything is Secure

After all steps, log back into your main account, open the sub-account management page, and confirm no unknown accounts remain. Make a small fund transfer to test that the function works and only you can use it. Finally, check your account security log or login history for any logins from strange IP addresses.