How trading accounts actually get drained
- Severity
- High
- Status
- Published
- Affected area
- Threats
- Published
- Last reviewed

When a trading account is emptied, the story people imagine is dramatic: an elite intruder breaking exotic cryptography in the small hours. The reality is almost always duller and more preventable. Accounts are drained through a chain of small, ordinary failures that line up, a reused password here, an over-permissioned key there, a withdrawal control that was never switched on. Understanding the real path is the first defence, because it is a path made of steps you can each block.
§01It starts with a credential, not a genius
The overwhelming majority of account compromises begin with a credential the attacker did not have to break: one leaked in an unrelated breach and reused, one phished through a convincing lookalike page, or an API key committed to a public repository and harvested by a bot within minutes. None of this requires sophistication. It requires only that somewhere in the chain a secret was weaker, or more exposed, than the balance it protected.
§02The quiet middle: reconnaissance
Once inside, a patient attacker rarely acts immediately. They watch. They learn the account’s normal rhythm, note when a human is likely to be looking, and check what the credential can actually do, trade only, or trade and withdraw. This dwell time is a gift to the defender: it is precisely the window in which anomalous-access alerts, a login from an unfamiliar address, or a second factor prompt on a sensitive action can turn a silent compromise into a caught one.
§03The drain itself
The money leaves in one of two ways. The blunt way is a direct withdrawal to an attacker-controlled address, trivially preventable if the key could not withdraw at all, or if payouts were restricted to a pre-approved whitelist. The subtle way is a manufactured loss: the attacker trades the account into a position on an illiquid instrument against their own account elsewhere, transferring value through the market itself. The second method sidesteps withdrawal controls entirely, which is why order-side risk limits matter as much as custody controls.
§04Every step was optional
The uncomfortable, and ultimately reassuring, truth is that a drained account is a story of controls that were each individually easy and each individually skipped. Unique credentials, scoped keys, a real second factor, withdrawal whitelisting, and order-rate limits, no single one is heroic, but together they turn a chain of dominoes into a wall. This advisory is educational and illustrative and is not security or investment advice for any specific account or situation.