Got hacked on a small CEX. Someone from Zhejiang logged into my account and changed my Google Authenticator.

Tried resetting password multiple times - kept getting "invalid 2FA code" errors. Luckily only had 20 USDT in there and nothing got drained.

I know I fucked up:
- No KYC done
- Only had email + 2FA (clearly not enough)
- Been clicking sketchy links like an idiot

Still don't know which part of my setup got compromised. Probably phishing or clipboard malware.

Lesson: Even small accounts need proper security. One wrong click and your 2FA gets hijacked. Stay paranoid out there.