My Coinbase account was accessed, money was deposited through my linked bank account, and the ETH was then sent to unfamiliar wallet addresses. I also received two-factor authentication codes for SoFi and several other accounts. I froze the bank account and checked the activity logs, which show the activity coming from my IP address even though I was in a work meeting at the time.
My browser history also shows visits to account login pages and attempted sign-ins, with the device identified as my personal PC. I'm not aware of anyone else who knows my credentials. Should I only change my passwords, or should I disconnect the computer and perform a complete reinstall?
4 Answers
Changing passwords is important, but do it from another device. Change unique passwords for your email, banking, exchange, and password-manager accounts, and sign out of all other sessions. Also check email forwarding rules, recovery addresses and phone numbers, exchange withdrawal addresses, bank transfers, and any newly created API keys. Preserve screenshots and transaction details for the bank, exchange, and law-enforcement reports before wiping the PC.
Event ID 4624 entries and elevated privileges are not automatically evidence of an intrusion; Windows generates many normal logon and service events. Their meaning depends on the account, logon type, source address, timing, and surrounding events. Don’t spend too long interpreting logs while accounts are actively at risk—secure them from a clean device first, then collect the PC for analysis or have a qualified technician examine it before reinstalling.
Treat the computer as compromised. Disconnect it from the internet and don’t use it to change passwords, since malware such as an infostealer or keylogger could capture the new credentials. From a known-clean phone or computer, contact your bank and the cryptocurrency exchange, secure or close affected accounts, revoke active sessions and API keys, replace the email password first, and enable strong app-based or hardware-key 2FA. Then reinstall Windows using official installation media and delete the existing system partitions before restoring files.
The matching IP address doesn’t prove the activity came directly from the computer. An attacker could have used an existing session, stolen browser cookies, malware, or access to the network. The browser’s device label can also be misleading. The priority is account containment and professional incident response, not trying to identify the attacker from those logs alone.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures