My Coinbase account was compromised today. Money was deposited through my linked bank account and then converted to ETH and sent to unfamiliar wallet addresses. I also received two-factor authentication codes for SoFi and several other accounts. I froze my bank account and checked the activity logs, which showed my own IP address, even though I was in a work meeting at those times.
My browser history also showed visits to account-login pages and attempted sign-ins, with Google identifying the device as my personal PC. I'm worried that the computer may have an infostealer, keylogger, or another form of remote access. Should I simply change my passwords, or should I disconnect the computer and perform a complete wipe and fresh Windows installation?
4 Answers
This sounds consistent with an infostealer or keylogger, especially if several unrelated accounts were accessed around the same time. Don’t enter new passwords on the suspect PC. A reputable password manager and unique passwords for every account will help afterward, but the first priority is securing the accounts from a clean device and enabling app-based or hardware-key two-factor authentication where possible.
The IP address and device label don’t prove that you personally performed the logins. If malware controlled your computer, the activity could appear to come from your normal browser, device, and home connection. Also, browser history and Event Viewer entries can be misleading or generated by normal Windows activity, so Event ID 4624 by itself isn’t evidence of an attacker. Focus on containment and account recovery rather than trying to interpret every log first.
That still doesn’t rule out malware. Secure the accounts from another device, preserve relevant evidence if the financial institutions request it, and then wipe and reinstall the PC. Avoid blaming yourself or assuming the activity was caused by any particular website or download without evidence.
Lock down the financial accounts first: call the bank’s fraud department, freeze or replace compromised cards and account credentials, report the unauthorized Coinbase transactions, and document dates, wallet addresses, and alerts. Then reset your email account before the others, because access to email can let an attacker reset everything. Change the router’s administrator password and update its firmware, but a dynamic IP address alone is not a reason to reset the router.
Treat the computer as compromised. Disconnect it from the network, then use a different trusted device—ideally your phone or a freshly reset computer—to change your email, banking, exchange, and other important passwords. Revoke active sessions, replace recovery methods, rotate API keys, and contact the banks and Coinbase immediately. After preserving anything you may need for an investigation, wipe the system drive and perform a clean Windows installation rather than relying on a reset that keeps personal files.

I was actively using the computer during the suspicious timestamps, which is why this is so confusing. I also don’t recognize the login attempts and nobody else has my account details.