A SIM-swapped or session-hijacked exchange account is a custodial emergency: attackers trade and withdraw as you while your phone number or cookies are theirs. The first control is the venue’s self-freeze / disable account flow - not an issuer blacklist on a random chain address. Issuer freezes matter later if stolen balances already swept on-chain to EOAs or other deposits. This playbook separates minute-zero venue self-freeze from the stolen USDT VASP/issuer packet and from the KYC/AML/LE account taxonomy.

Educational only. Not legal advice. FreezeRadar cannot freeze your CEX account remotely.

Smartphone / mobile security metaphor for SIM-swap exchange self-freeze vs issuer blacklist.

Check a wallet before you act

Run a FreezeRadar scan for issuer-freeze signals, sanctions exposure, counterparty risk, and freezeable asset sensitivity before moving funds.

Scan a wallet

Direct answer

If your exchange account is stolen (SIM swap, malware session, phished 2FA), use the venue’s published emergency disable / freeze account path immediately - often available even from the login screen’s security links - then secure the phone number with the carrier, rotate email passwords, and open an official support ticket. Parallel issuer blacklisting only helps for funds that already left to on-chain addresses still holding freezeable USDT/USDC. Plane separation: exchange hold vs issuer blacklist. Contact map: contact issuer / exchange / LE.

Minute-zero order of operations

  1. Venue self-freeze - disable withdrawals/login per official help center (Binance and peers publish compromised-account / lost-device guidance; UI labels change - search the venue’s own “disable account” / “security anomaly” articles).
  2. Carrier - report SIM swap; place port freeze; new SIM under stronger auth.
  3. Email & password managers - rotate credentials that gated 2FA resets.
  4. Official support ticket - from a clean device; include approximate compromise time, unrecognized IPs/devices, withdrawal TxIDs if any.
  5. LE report - especially if fiat rails or large notionals involved.
  6. On-chain fork - if withdrawals already hit TRON/ETH addresses, start the evidence packet and VASP-outbound tickets on destination venues (exchange freeze request when stolen funds land).
  7. Refuse recovery DMs offering “priority unfreeze.”

Do not wait for an issuer to “pause” a CEX internal ledger balance - you need the venue.

Self-freeze vs issuer blacklist

QuestionVenue self-freezeIssuer blacklist
What is frozen?Your custodial account / withdrawalsSpecific on-chain addresses for a token contract
Who triggers?You or venue securityIssuer under policy / lawful process
SIM-swap mid-loginPrimary controlIrrelevant until funds are on-chain
Funds already withdrawn to EOAToo late for that balancePossible LE+issuer path on thief addresses
KYC docsMay be required to reopenDifferent packet

Mixing these planes wastes the first hour.

After the bleeding stops

  • Expect AML/KYC review when reopening (taxonomy).
  • Review API keys, withdraw allowlists, device management, anti-phishing codes.
  • Move residual self-custody funds if the same email/phone threatened those wallets.
  • Document carrier reference numbers for insurance / LE.

Worked composite

Trader loses SMS 2FA overnight (SIM swap). Attacker drains USDT to an external TRC-20 address, then toward a second exchange deposit. Victim still has email access on a laptop. Actions: emergency disable on the source venue; carrier port freeze; support tickets on source and destination venues with TxIDs; LE filing; issuer path only for residual EOA balances under counsel; new phone number + hardware 2FA after recovery. Wrong path: arguing with SMS while open orders still withdrawable; or only emailing Tether while the CEX account remains unlocked.

Prevention controls (principle-level)

  • Prefer app-based or hardware 2FA over SMS where the venue allows
  • Withdrawal allowlists with cool-down
  • Anti-phishing codes on email
  • Carrier PIN / port freeze
  • Separate email for exchange login vs social

UI steps go stale; principles age better.

Limitations

Each venue’s emergency button location changes. This article stays principle-level on purpose. FreezeRadar does not observe your CEX session. Successful self-freeze does not reverse completed withdrawals.

Key takeaway

SIM-swap theft is a venue self-freeze first problem. Issuer blacklists are a downstream tool for on-chain remnants. Secure phone and email in parallel, file LE, and hand destination hops to the stolen-funds VASP playbook.

Next: exchange hold vs issuer, evidence packet, contact guide, KYC/AML/LE taxonomy, outbound VASP freeze request.

Clean-device checklist

  • New or verified-clean laptop/phone
  • No browser extensions until baseline restored
  • Official venue URL typed manually
  • Hardware 2FA preferred when re-enabling
  • Withdraw allowlist re-confirmed before unlocking large limits

Family / shared-number risk

SIM swaps sometimes hit family plans. Inventory which exchanges still use the compromised MSISDN. Update every venue, bank, and email recovery path - not only the one that was drained.

Coordination with outbound VASP freezes

Once withdrawals hit another exchange, you are both victim-of-venue-A and reporter-to-venue-B. Use the landing-funds article’s channel map for B while A’s self-freeze ticket remains open. Do not assume A’s support notifies B automatically.

Additional operator notes (sim)

Keep this section practical. Re-read the direct answer before customer calls. Prefer primary issuer and venue URLs over screenshots from group chats. Log every contact attempt with UTC timestamps. If a step requires counsel, stop and wait - do not invent process. Cross-check related FreezeRadar guides linked above so you do not paste contradictory advice into the same ticket thread. When in doubt, halt movement of funds and escalate internally before escalating externally.

Signal list that should trigger self-freeze drills

  • Carrier SMS about SIM change you did not request
  • Exchange login alerts from unfamiliar geolocations
  • Sudden 2FA reset emails
  • Withdrawals you did not place
  • API keys created without change tickets

Any one signal is enough to start the minute-zero list. Waiting for three signals is how drains complete.

Reopening without re-exposing

When the venue clears you to reopen:

  1. New 2FA device enrolled on clean hardware
  2. All sessions terminated
  3. API keys rotated
  4. Withdraw allowlist confirmed
  5. Small test withdrawal before full limits
  6. Taxonomy docs ready if compliance still reviewing (KYC/AML/LE)

Self-freeze ≠ proof your deposit addresses on other venues are safe. Screen and ticket destinations separately using the stolen-funds landing playbook when on-chain hops exist.

Staff drill note

Run a 20-minute tabletop on this failure mode each quarter. Capture gaps in the runbook. Do not grade people on memorizing UI paths that change - grade them on plane separation and halt discipline.

Closing operational reminder

Halt first when unsure. Prefer primary sources. Document UTC times. Escalate to counsel for legal process. Refuse seed/unlock-fee solicitors. Re-read the direct answer section before external emails.

Timeline example (composite)

  • 02:10 local - SMS outage; carrier silently ported number
  • 02:25 - exchange SMS 2FA intercepted; password reset via email if email also weak, or session cookie theft concurrent
  • 02:40 - withdrawals to external TRC-20
  • 03:05 - victim notices email alerts on laptop
  • 03:10 - emergency disable succeeds; further withdrawals blocked
  • 03:30 - carrier port freeze; LE report number obtained
  • 04:00 - destination exchange ticket + hash list
  • Next business day - counsel reviews issuer path for residual EOA balances

Hours matter. The self-freeze at 03:10 is the difference between partial and total loss.

Insurance / corporate notes

Corporate accounts should pre-stage:

  • Break-glass admin users with hardware 2FA stored offline
  • Documented emergency disable owners
  • Carrier contacts on file
  • Retainer counsel familiar with VASP freezes

Personal accounts should still rehearse the disable path once so panic is not the first visit to that screen.

Final plane check

Ask aloud: “Is the money still on the exchange ledger, or already on-chain?” Ledger → venue self-freeze + support. On-chain → evidence packet + destination VASPs + possible issuer. Both → do both. Neither issuer blogs nor FreezeRadar scans replace the disable button.

One-sentence staff mantra

Self-freeze the venue account first; call the carrier second; open lawful tickets third; chase issuer blacklists only for coins that already left for chain addresses that still hold freezeable balances.

  1. This self-freeze playbook (minute zero).
  2. KYC/AML/LE taxonomy when the venue keeps the account locked for review.
  3. Outbound VASP freeze request for destination hops.
  4. Evidence packet for on-chain remnants.

References

  1. Binance Square / Blog - What to do if your account has been compromised - https://www.binance.com/en/square/post/745318
  2. Binance Support - How to secure my Binance account (security hub) - https://www.binance.com/en/support/faq/list/7-27
  3. FBI IC3 - https://www.ic3.gov/
  4. FreezeRadar - Exchange hold vs issuer USDT blacklist - https://freezeradar.com/blog/exchange-hold-vs-issuer-usdt-blacklist
  5. FreezeRadar - Stolen USDT freeze-request evidence packet - https://freezeradar.com/blog/stolen-usdt-freeze-request-evidence-packet
Sources (5)

Continue exploring FreezeRadar knowledge content.