Getting in / Pair 10 of 41
A door you shut yourself against a lock somebody changed
The login page gives the same answer either way. Your password does not work, and nothing on the screen says whether that is your doing or somebody else's.
Two doors that refuse you identically
From the outside a lockout and a takeover are one event. The credential you have goes in and comes back rejected. There is no line on the page that reads this account is now being used by somebody who is not you, and there would be no sense in printing one if there were.
What makes this pair worse than the others in this section is the delay. A limiter announces itself within minutes. A takeover can sit quietly for a while, and the first thing you notice may be an ordinary looking refusal on an ordinary evening.
The account is still yours and the key is not working
A counter has closed the door for a while, a second factor lives on a phone that no longer exists, or the value you are typing drifted out of date. Everything inside is untouched. What has failed is your ability to prove who you are, which is a smaller problem than it feels.
Somebody else proved they were you
The credential left your hands at some point and was used. The password has been changed, and usually so has anything that would let you change it back. What is inside is now being spent or read by a person you cannot contact.
Where the refusal is decided in each case
A lockout is decided by rules. A number was exceeded, a device was lost, a value expired. Rules are patient and they are reversible, and the market that wrote them is the same market that can undo them.
A takeover is decided by a person, and it needed something to happen first. Passwords do not walk off on their own. On this kind of site they leave in one of a small number of ways, and by far the most common is that they were typed into a page that looked right and was not.
The signal that tells them apart
Retrace the last few entrances
Work backwards through the last few times you logged in and name where each address came from. A credential that has only ever been typed into an address out of your own record has had no opportunity to leave. One that was typed into an address you found on the day has had every opportunity.
- List the last three or four sessions you can remember, roughly.
- For each, say where the address you used came from. Something you had written down beforehand, or something you picked up at the time.
- If any of them came from a search result, a chat message or a post you followed on the day, treat the credential as having left your hands.
- If every one came from your own record, a lockout is by far the more likely reading.
That test is not perfect and it does not need to be. It is the only one available that does not depend on getting inside the account first, which is precisely the thing you cannot do. It also has the useful property of being answerable while annoyed.
The cheap misread and the costly one
- If you treat a takeover as a lockout
- You wait politely for a door that somebody else now controls. While you wait, the balance goes and the message history gets read. This is the expensive direction and it is expensive in a way that does not come back.
- If you treat a lockout as a takeover
- You write off an account that was never gone, abandon the standing and history you built up, and start again from nothing. That hurts, but it hurts in a currency you can rebuild, and the mistake is reversible for as long as the account exists.
Since the two are not symmetric, the safe default when you genuinely cannot tell is to act as though it was taken. That means moving on the things that are still in your hands rather than waiting on the thing that is not. The same reasoning applied to money rather than access sits under money.
What each situation asks of you
- If you are locked out
- Stop attempting, since attempts are what most lockouts are built on. Note what changed on your side, then use the recovery route the market itself publishes, reached from the address you already had.
- If it was taken
- Assume everything held inside is gone, the balance first. Stop using that password anywhere else you used it. Approach the market through its own support and expect the process to be slow and unsatisfying.
One more thing worth separating out. A takeover is an argument about how the credential travelled, not about how strong it was, so lengthening the password afterwards fixes nothing on its own. The neighbouring pairs in this section deal with the smaller refusals that get mistaken for this one, and a session that expired against one that was ended for you is the one people confuse with it most.
Questions readers send about this pair
How do I know if someone else is using my account?
From outside, you generally cannot, which is the whole difficulty. The evidence that survives a lockout is not inside the account at all. It is in your own record of where you have been typing the password.
Can the market give me the account back?
Sometimes, and only the market can. It will depend on what you can show them that a stranger could not, and it will not be fast. No third party has any ability to help with this, whatever they claim.