When you discover that your whitelist has been replaced by an unknown address, your first reaction shouldn't be to investigate who did it—it should be to freeze the withdrawal function immediately. What you need to freeze isn't your password or your phone number; it's the entire account's withdrawal permission. That's the most effective way to stop further loss.
Don't waste time figuring out whose address that is, and don't try to change your password first. Whoever replaced the address already has control over your account. While you're busy changing your password, they could already be withdrawing your funds.
Step 1: Freeze withdrawals right away (highest priority)
This is the fastest action you can take to block the threat.
What to do: Log into your exchange, go to the withdrawal page. If the platform offers a "pause withdrawals" or "freeze withdrawals" function, turn it on immediately. If not, contact customer support as quickly as possible and request that they temporarily disable withdrawals for your account.
How you'll know it's done: When you try to withdraw, you should see a message like "withdrawal function suspended" or something similar.
Warning: A changed whitelist means the attacker has already bypassed at least one layer of security (this could be session hijacking, a device trojan, or credential stuffing). Before you've completely removed the threat, don't just "change your password and turn off the whitelist" and then re‑enable withdrawals. On some platforms, turning off the whitelist actually allows you to manually enter a new address for a withdrawal—if you disable the whitelist, you may be making things easier for the attacker.
Step 2: Confirm that withdrawal lock is active—check the platform's passive protection
Many exchanges automatically trigger a withdrawal lock when they detect a critical security change. A whitelist replacement falls exactly into that category.
What to do: Check your transaction history or the withdrawal page to see if there's a "withdrawal suspended" notice. You can also try initiating a small withdrawal to test whether you can get through the full verification process.
How you'll know it's done: The system clearly tells you that withdrawals are locked, and you cannot submit a withdrawal request.
Depending on each platform's security mechanism, the act of changing the whitelist address itself may have already locked your withdrawals. Bitfinex, for example, explicitly states that removing an address or changing a whitelisted withdrawal address automatically pauses all crypto withdrawals for 5 days. No withdrawals will be processed during that period. The same logic applies to new address withdrawal locks: if the new address withdrawal lock is enabled, a newly added whitelist address cannot be used for 24 hours. OSL also notes that major exchanges enforce a cooling‑off period of 24 to 72 hours for any new whitelist address that is added.
Step 3: Investigate the attack entry point—figure out how the whitelist was changed
First, block the funds. Then, find the cause. After the withdrawal is frozen, you need to investigate how the attacker got in.
What to do:
- Check active sessions: Go to device management and end all login sessions that aren't yours.
- Check API keys: Delete any API keys you didn't create yourself.
- Check third‑party authorizations: Unlink any suspicious social login connections.
- Check browser extensions: Remove any extensions from unknown sources, especially those that interact with wallets or have auto‑fill functions.
How you'll know it's done: Once you've cleaned up all the entry points listed above, change your login password.
Common mistake: Many people, when they see their whitelist has been changed, immediately go to "fix the whitelist"—delete the unknown address and add their own back. That action alone can trigger a new 24‑hour withdrawal restriction, which will actually put your account in a worse position before the freeze is lifted. The correct order is: first make sure funds can't be withdrawn (passive protection is active), then investigate and clean up, and only after that set up the whitelist again.
How to verify you've finished: After completing all cleanup steps, try making a test withdrawal to your own address for the platform's minimum amount. If the withdrawal succeeds, your withdrawal function is back to normal. If you see a 24‑hour lock message, that means the whitelist change you just made triggered a waiting period—this is normal, just wait until the lock period ends. The final confirmation standard: all your account's security settings (password, 2FA, API, whitelist, sessions) are under your control, and you can complete a full withdrawal successfully.


