Since account security features vary between platforms and are not always documented, the user might not know what to expect nor how to configure their account best for their personal threat model. ATO is another common type of fraud that happens due to security failures, even though financial institutions like CEXes that serve US customers must protect their users’ information from (among other harms) unauthorized access. If the user sends their MFA codes to their email account, the attacker could then compromise the email account to secondarily gain CEX account access.