Independent educational website - not an official exchange service

Reviewed guide | 2026-09-30

Running a Calm Account Lockdown Drill Before Anything Goes Wrong

Learn a step-by-step lockdown drill for your crypto exchange account: freeze access, revoke sessions, and notify support calmly when you suspect a compromise. Practice now so you can act fast later.

bangladeshcryptohub.com

Multiple exchanges | Bangladesh | BDT | fees, access and account safety

A sudden warning that someone else may be inside your exchange account is one of the worst moments to improvise. In that moment, panic pushes people to click the first link they see, hand over codes to a stranger, or delete the only evidence that would have helped support understand what happened. A lockdown drill flips that around. You rehearse the exact sequence of freeze, revoke, and report while everything is calm, so the steps are already in your hands when the pressure is real. This guide is for readers in Bangladesh who want a practical, repeatable routine they can run on any exchange they use. It does not replace the exchange's own security tools; it trains you to use them in the right order. You will build a one-page plan, walk through it once per quarter, and keep a small log of what you changed and when. The goal is not to become a security engineer. The goal is to remove hesitation from the first five minutes of a suspected compromise, because that is when small correct actions matter most.

Why a drill beats a panic response

When you suspect an active compromise, your first instinct is usually to do something, anything, immediately. That instinct is useful only if it is pointed at the right actions. A drill gives you a fixed order: secure the entry points first, then cut the sessions, then preserve what you can see, and only then contact support. Practising that order while nothing is wrong turns it into muscle memory. You stop debating whether to change the password before or after checking devices, because you already decided in advance.

A drill also exposes the gaps you cannot see from memory. You may discover that your authenticator backup codes are stored somewhere you cannot reach from your phone, that you do not know how to find the active sessions list, or that your recovery email is an old address you no longer control. Each of those is a small fix today and a serious problem during a real incident. Write down what you find, fix one item at a time, and run the drill again next quarter to confirm the fix held.

Keep the drill short. A full rehearsal should take fifteen to thirty minutes, not an afternoon. If it becomes a big project, you will postpone it. The value comes from repetition, not from a single perfect run.

Step one: secure the entry points

Start with the credentials that let someone back in. Change the account password from a device you trust, and make the new password unique to this exchange. If you reuse a password anywhere else, change it there too, because a breach on another site can become a breach here. Then review your two-factor authentication. If you use SMS codes, consider moving to an authenticator app or a hardware security key where the exchange supports it. If you already use an app, confirm the codes still generate correctly and that you can restore them on a second device.

Next, check the recovery paths. Look at the email address and phone number attached to the account. If either is old, update it now while you have full access, because support will often need to verify you through those channels. Record the date you made each change. Do not send codes, passwords, or seed phrases to anyone who contacts you first, even if they claim to be from the exchange. Official support will not ask for your password or your authenticator codes.

If you keep a written recovery kit, open it once during the drill and confirm every item is still readable and current. A backup code that has been used, a seed phrase written in fading ink, or a note stored on a device you no longer own is not a backup. Replace it during the drill, not during the emergency.

Step two: revoke sessions and tighten device access

Find the security or device management page in your account settings. Most exchanges list active sessions with a device name, approximate location, and last activity time. Read the list slowly. Anything you do not recognise, and anything you recognise but no longer use, should be logged out. Change your password again after revoking sessions if the interface gives you that option, so any stolen token is invalidated. Then check connected applications and API keys. If you created API keys for a trading tool and no longer use it, delete the key. If you still need it, restrict it to the minimum permissions and, where the exchange allows it, to specific IP addresses.

Look at withdrawal address lists and any trusted-device or whitelist settings. Remove addresses you do not recognise. If the exchange supports a withdrawal lock or a cooling-off period after adding a new address, note where that setting lives and whether it is switched on. These controls are exactly what slow down an attacker who already has partial access. During the drill, write down the exact menu path you used, because menus change and you do not want to be searching during an incident.

Finish by checking email and phone security. If your email account is compromised, every exchange reset link is compromised too. Turn on two-factor authentication for the email account, review its active sessions, and confirm its recovery options are current. This step is easy to skip because it is not inside the exchange, but it is often the weakest link.

Step three: preserve evidence and contact support

Before you delete anything, capture what you can see. Take screenshots of the active sessions list, unfamiliar withdrawal addresses, recent login alerts, and any strange emails or messages. Save them in a folder with the date in the name. Do not edit the images. Support teams can act faster when you can show them a timeline instead of describing it from memory. If you received a suspicious message, keep the original, including the sender address and any headers your mail client can show.

Then open the official help centre for your exchange and use the contact or chat option listed there. Do not use a link from an email, a social media message, or a search result you have not verified. In your first message, state plainly that you suspect unauthorised access, list the actions you have already taken, and attach the screenshots. Ask what additional verification they need. Expect that they may freeze withdrawals or place a hold while they review; that is a normal protective step, not a punishment. Record the ticket number, the date, and the name or channel of the person who replied.

While you wait, do not open new accounts elsewhere to move funds in a hurry, and do not accept help from anyone who approaches you offering to recover the account for a fee. Recovery scams target people precisely in this window. Keep all communication inside the official support channel, and keep your own notes updated after each reply.

Risk boundary: Bangladesh Crypto Guide

Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat. A referral link only records attribution; it does not guarantee access, pricing, rewards, approval or investment results. Availability can differ by residence, legal entity and product, so no regional access is assumed from language or branding alone.

Scenario checkpoint

  • Write a one-page lockdown plan with the exact menu paths for password change, two-factor settings, active sessions, API keys, and withdrawal address lists.
  • Confirm your recovery email and phone number are current and that you can access both from a device you trust.
  • Store backup codes and recovery information somewhere you can reach without your primary phone, and verify they are readable.
  • Practise finding the official help centre contact option without using a link from an email or message.
  • Create a dated incident folder for screenshots and support replies, and note the ticket number after each contact.
  • Schedule the next drill in your calendar and list the one fix you will complete before then.
Risk boundary

Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat.