Could an exchange account be controlled by another person?¶
Yes. A cryptocurrency exchange account may be controlled or used by someone other than the registered customer.
Avoid the dangerous assumption¶
The dangerous assumption is that account verification and successful login prove the customer personally conducted the activity.
Credentials may be shared, sold, phished or stolen.
An offender may take over an existing session, use remote-access software or persuade the customer to complete actions under instruction.
A family member, employee or associate may also have authorised access. The customer may have allowed access without understanding how the account would later be used.
Relevant evidence may include devices, IP addresses, sessions, login timestamps, authentication events, password resets, contact-detail changes and withdrawal-address creation.
Communications can show recruitment, control, deception or instructions.
Device examination may reveal exchange applications, saved credentials, notifications, copied addresses and remote-access tools.
Compare disputed activity with the customer’s normal devices, locations, trading behaviour and withdrawal destinations.
Do not assume that a new device proves takeover.
It may reflect legitimate replacement, travel or additional access.
Equally, familiar device information does not rule out compromise if an existing session or remotely controlled device was used.
The registered customer may still be involved even where another person directed the account.
Separate technical access, personal actions, knowledge, instruction and benefit.
Preserve provider and device evidence before passwords or sessions are changed where possible.
When reporting, distinguish the account holder, person accessing the account and person directing or benefiting from the transactions.
Operational takeaway¶
Test third-party control through provider access, device, authentication, communication and benefit evidence rather than relying on exchange registration or login success alone.