Sentry Labs Advisories← Advisories
SL-2025-011 High Threats

How trading accounts actually get drained

PUBLISHED 22 AUG 20257 MIN READ
Advisory Record SL-2025-011·r2
Severity
High
Status
Published
Affected area
Threats
Published
Last reviewed

When a trading account is emptied, the story people imagine is dramatic: an elite intruder breaking exotic cryptography in the small hours. The reality is almost always duller and more preventable. Accounts are drained through a chain of small, ordinary failures that line up, a reused password here, an over-permissioned key there, a withdrawal control that was never switched on. Understanding the real path is the first defence, because it is a path made of steps you can each block.

§01It starts with a credential, not a genius

The overwhelming majority of account compromises begin with a credential the attacker did not have to break: one leaked in an unrelated breach and reused, one phished through a convincing lookalike page, or an API key committed to a public repository and harvested by a bot within minutes. None of this requires sophistication. It requires only that somewhere in the chain a secret was weaker, or more exposed, than the balance it protected.

§02The quiet middle: reconnaissance

Once inside, a patient attacker rarely acts immediately. They watch. They learn the account’s normal rhythm, note when a human is likely to be looking, and check what the credential can actually do, trade only, or trade and withdraw. This dwell time is a gift to the defender: it is precisely the window in which anomalous-access alerts, a login from an unfamiliar address, or a second factor prompt on a sensitive action can turn a silent compromise into a caught one.

§03The drain itself

The money leaves in one of two ways. The blunt way is a direct withdrawal to an attacker-controlled address, trivially preventable if the key could not withdraw at all, or if payouts were restricted to a pre-approved whitelist. The subtle way is a manufactured loss: the attacker trades the account into a position on an illiquid instrument against their own account elsewhere, transferring value through the market itself. The second method sidesteps withdrawal controls entirely, which is why order-side risk limits matter as much as custody controls.

§04Every step was optional

The uncomfortable, and ultimately reassuring, truth is that a drained account is a story of controls that were each individually easy and each individually skipped. Unique credentials, scoped keys, a real second factor, withdrawal whitelisting, and order-rate limits, no single one is heroic, but together they turn a chain of dominoes into a wall. This advisory is educational and illustrative and is not security or investment advice for any specific account or situation.

Institutional execution, engineered.

Institutional-grade algorithmic and high-frequency trading infrastructure.

Request access →

Educational content only. Algorithmic and high-frequency trading carries substantial risk of loss. All figures are illustrative / simulated, are not indicative of future results, and nothing here is financial, security, or risk-management advice.