SIM Swap or Exchange Account Takeover: Emergency Self-Freeze vs Issuer Blacklist
When an exchange account is SIM-swapped, hit the venue self-freeze first. Issuer blacklists help only after funds are already on-chain.

A SIM-swapped or session-hijacked exchange account is a custodial emergency: attackers trade and withdraw as you while your phone number or cookies are theirs. The first control is the venue’s self-freeze / disable account flow - not an issuer blacklist on a random chain address. Issuer freezes matter later if stolen balances already swept on-chain to EOAs or other deposits. This playbook separates minute-zero venue self-freeze from the stolen USDT VASP/issuer packet and from the KYC/AML/LE account taxonomy.
Educational only. Not legal advice. FreezeRadar cannot freeze your CEX account remotely.

Check a wallet before you act
Run a FreezeRadar scan for issuer-freeze signals, sanctions exposure, counterparty risk, and freezeable asset sensitivity before moving funds.
Direct answer
If your exchange account is stolen (SIM swap, malware session, phished 2FA), use the venue’s published emergency disable / freeze account path immediately - often available even from the login screen’s security links - then secure the phone number with the carrier, rotate email passwords, and open an official support ticket. Parallel issuer blacklisting only helps for funds that already left to on-chain addresses still holding freezeable USDT/USDC. Plane separation: exchange hold vs issuer blacklist. Contact map: contact issuer / exchange / LE.
Minute-zero order of operations
- Venue self-freeze - disable withdrawals/login per official help center (Binance and peers publish compromised-account / lost-device guidance; UI labels change - search the venue’s own “disable account” / “security anomaly” articles).
- Carrier - report SIM swap; place port freeze; new SIM under stronger auth.
- Email & password managers - rotate credentials that gated 2FA resets.
- Official support ticket - from a clean device; include approximate compromise time, unrecognized IPs/devices, withdrawal TxIDs if any.
- LE report - especially if fiat rails or large notionals involved.
- On-chain fork - if withdrawals already hit TRON/ETH addresses, start the evidence packet and VASP-outbound tickets on destination venues (exchange freeze request when stolen funds land).
- Refuse recovery DMs offering “priority unfreeze.”
Do not wait for an issuer to “pause” a CEX internal ledger balance - you need the venue.
Self-freeze vs issuer blacklist
| Question | Venue self-freeze | Issuer blacklist |
|---|---|---|
| What is frozen? | Your custodial account / withdrawals | Specific on-chain addresses for a token contract |
| Who triggers? | You or venue security | Issuer under policy / lawful process |
| SIM-swap mid-login | Primary control | Irrelevant until funds are on-chain |
| Funds already withdrawn to EOA | Too late for that balance | Possible LE+issuer path on thief addresses |
| KYC docs | May be required to reopen | Different packet |
Mixing these planes wastes the first hour.
After the bleeding stops
- Expect AML/KYC review when reopening (taxonomy).
- Review API keys, withdraw allowlists, device management, anti-phishing codes.
- Move residual self-custody funds if the same email/phone threatened those wallets.
- Document carrier reference numbers for insurance / LE.
Worked composite
Trader loses SMS 2FA overnight (SIM swap). Attacker drains USDT to an external TRC-20 address, then toward a second exchange deposit. Victim still has email access on a laptop. Actions: emergency disable on the source venue; carrier port freeze; support tickets on source and destination venues with TxIDs; LE filing; issuer path only for residual EOA balances under counsel; new phone number + hardware 2FA after recovery. Wrong path: arguing with SMS while open orders still withdrawable; or only emailing Tether while the CEX account remains unlocked.
Prevention controls (principle-level)
- Prefer app-based or hardware 2FA over SMS where the venue allows
- Withdrawal allowlists with cool-down
- Anti-phishing codes on email
- Carrier PIN / port freeze
- Separate email for exchange login vs social
UI steps go stale; principles age better.
Limitations
Each venue’s emergency button location changes. This article stays principle-level on purpose. FreezeRadar does not observe your CEX session. Successful self-freeze does not reverse completed withdrawals.
Key takeaway
SIM-swap theft is a venue self-freeze first problem. Issuer blacklists are a downstream tool for on-chain remnants. Secure phone and email in parallel, file LE, and hand destination hops to the stolen-funds VASP playbook.
Next: exchange hold vs issuer, evidence packet, contact guide, KYC/AML/LE taxonomy, outbound VASP freeze request.
Clean-device checklist
- New or verified-clean laptop/phone
- No browser extensions until baseline restored
- Official venue URL typed manually
- Hardware 2FA preferred when re-enabling
- Withdraw allowlist re-confirmed before unlocking large limits
Family / shared-number risk
SIM swaps sometimes hit family plans. Inventory which exchanges still use the compromised MSISDN. Update every venue, bank, and email recovery path - not only the one that was drained.
Coordination with outbound VASP freezes
Once withdrawals hit another exchange, you are both victim-of-venue-A and reporter-to-venue-B. Use the landing-funds article’s channel map for B while A’s self-freeze ticket remains open. Do not assume A’s support notifies B automatically.
Additional operator notes (sim)
Keep this section practical. Re-read the direct answer before customer calls. Prefer primary issuer and venue URLs over screenshots from group chats. Log every contact attempt with UTC timestamps. If a step requires counsel, stop and wait - do not invent process. Cross-check related FreezeRadar guides linked above so you do not paste contradictory advice into the same ticket thread. When in doubt, halt movement of funds and escalate internally before escalating externally.
Signal list that should trigger self-freeze drills
- Carrier SMS about SIM change you did not request
- Exchange login alerts from unfamiliar geolocations
- Sudden 2FA reset emails
- Withdrawals you did not place
- API keys created without change tickets
Any one signal is enough to start the minute-zero list. Waiting for three signals is how drains complete.
Reopening without re-exposing
When the venue clears you to reopen:
- New 2FA device enrolled on clean hardware
- All sessions terminated
- API keys rotated
- Withdraw allowlist confirmed
- Small test withdrawal before full limits
- Taxonomy docs ready if compliance still reviewing (KYC/AML/LE)
Cross-link reminder
Self-freeze ≠ proof your deposit addresses on other venues are safe. Screen and ticket destinations separately using the stolen-funds landing playbook when on-chain hops exist.
Staff drill note
Run a 20-minute tabletop on this failure mode each quarter. Capture gaps in the runbook. Do not grade people on memorizing UI paths that change - grade them on plane separation and halt discipline.
Closing operational reminder
Halt first when unsure. Prefer primary sources. Document UTC times. Escalate to counsel for legal process. Refuse seed/unlock-fee solicitors. Re-read the direct answer section before external emails.
Timeline example (composite)
- 02:10 local - SMS outage; carrier silently ported number
- 02:25 - exchange SMS 2FA intercepted; password reset via email if email also weak, or session cookie theft concurrent
- 02:40 - withdrawals to external TRC-20
- 03:05 - victim notices email alerts on laptop
- 03:10 - emergency disable succeeds; further withdrawals blocked
- 03:30 - carrier port freeze; LE report number obtained
- 04:00 - destination exchange ticket + hash list
- Next business day - counsel reviews issuer path for residual EOA balances
Hours matter. The self-freeze at 03:10 is the difference between partial and total loss.
Insurance / corporate notes
Corporate accounts should pre-stage:
- Break-glass admin users with hardware 2FA stored offline
- Documented emergency disable owners
- Carrier contacts on file
- Retainer counsel familiar with VASP freezes
Personal accounts should still rehearse the disable path once so panic is not the first visit to that screen.
Final plane check
Ask aloud: “Is the money still on the exchange ledger, or already on-chain?” Ledger → venue self-freeze + support. On-chain → evidence packet + destination VASPs + possible issuer. Both → do both. Neither issuer blogs nor FreezeRadar scans replace the disable button.
One-sentence staff mantra
Self-freeze the venue account first; call the carrier second; open lawful tickets third; chase issuer blacklists only for coins that already left for chain addresses that still hold freezeable balances.
Related reading order
- This self-freeze playbook (minute zero).
- KYC/AML/LE taxonomy when the venue keeps the account locked for review.
- Outbound VASP freeze request for destination hops.
- Evidence packet for on-chain remnants.
References
- Binance Square / Blog - What to do if your account has been compromised - https://www.binance.com/en/square/post/745318
- Binance Support - How to secure my Binance account (security hub) - https://www.binance.com/en/support/faq/list/7-27
- FBI IC3 - https://www.ic3.gov/
- FreezeRadar - Exchange hold vs issuer USDT blacklist - https://freezeradar.com/blog/exchange-hold-vs-issuer-usdt-blacklist
- FreezeRadar - Stolen USDT freeze-request evidence packet - https://freezeradar.com/blog/stolen-usdt-freeze-request-evidence-packet
Sources (5)
Binance Square — Compromised account guidance
Binance
Official compromised-account advice.
Binance Support — Security FAQ hub
Binance
Account security articles.
FBI IC3
FBI IC3
Cybercrime reporting.
FreezeRadar — Exchange hold vs issuer blacklist
FreezeRadar
Plane separation.
FreezeRadar — Stolen USDT evidence packet
FreezeRadar
On-chain remnant packet.
Related reading
Continue exploring FreezeRadar knowledge content.
On this page
Get posts like this by email
A daily or weekly digest of FreezeRadar freeze activity.
By FreezeRadar Team
Wallet risk intelligence and stablecoin compliance analysis from FreezeRadar.


