You change your password and the withdraw button stops working. Or a coin you hold goes into maintenance, deposits and withdrawals both refuse, and its order book keeps trading as though nothing happened. These read like one failure and they are two: one suspension is attached to your account, the other to the asset, and which one you are in decides what ends it.
What a suspension is holding still
A suspension is a deliberate stop on the movement of value while something else is settled. Its length is the least informative thing about it. What it is holding still gives you the trigger and the release.
Two scopes cover the cases here. An account-scoped hold is attached to you: your security settings changed, so your withdrawals pause while every other customer keeps withdrawing. An asset-scoped suspension is attached to a coin: its contract or its chain is being replaced, so no holder can move it in either direction until the replacement is finished. You read the scope off the notice: one names your account, the other a ticker.
Why a credential change freezes withdrawals
Consider what someone who has just taken over an account does next. A stolen password is not enough while a second factor stands in the way, so they change or remove the second factor. They cannot send to their own wallet while a withdrawal whitelist restricts destinations, so they add an address of their own. Then they withdraw. That is also the sequence a legitimate owner performs after losing a phone.
At the moment the change is submitted the platform cannot tell the two apart: both parties arrive holding valid credentials, and valid credentials are precisely what was stolen. A system that tried to decide which one it was would be deciding on nothing.
A withdrawal hold declines the decision and delays the consequence instead. It postpones the one step in the sequence that cannot be taken back, and raises an alert while the delay runs. Everything else is reversible: a password can be changed again, two-factor authentication can be re-enrolled, an address can be removed from a list. A confirmed on-chain withdrawal cannot be recalled by anyone.
Kraken documents both halves of that design. Its support page on withdrawal holds records that a recent password change places a 24 hour hold on withdrawals to new withdrawal addresses. Its Global Settings Lock, which Kraken describes as the last line of defense if your sign-in password and sign-in 2FA are compromised, covers exactly the settings named above: adding a withdrawal address, changing your password while logged in, and adding or changing any 2FA. Unlocking it without a Master Key takes a minimum of 24 hours and can be set as long as 30 days.
Which changes start the clock, and what does not stop it
The trigger is not the word password. It is any change to a control that would otherwise stand between a stolen login and a withdrawal: replacing a second factor, adding a destination address, changing the email that receives the alerts, creating an API key with withdrawal permission. Each removes a barrier, and removing a barrier starts a clock.
Direction matters more than which setting was touched. Switching a protection on can be applied at once, because that is not a move a thief opens with. Switching one off, or pointing it somewhere new, is what needs a delay in front of it. Kraken's lock is built around that asymmetry, with the documented waiting period attached to the unlock.
The same logic explains why the obvious remedies fail. Passing the second factor again, or setting the changed value back, shows only that whoever is doing it has the access that started the hold. A release available from inside the account would be available to the party inside the account. So rotate credentials on a day you picked, not on the afternoon you plan to withdraw.
Why a token migration closes deposits
A token migration replaces one token contract with another. The project deploys the new contract, retires the old one, and holders exchange old units for new, sometimes at one for one and sometimes onto another chain. Kraken's Nillion notice records that shape: balances were migrated automatically to a new Ethereum-based token at a 1:1 rate, and the version on the old chain is no longer supported once the migration completes.
A deposit system is not watching an asset. It watches an address on a specific chain for transfers of a specific contract, and credits your account when it sees one. During a migration two contracts are live for what a customer thinks of as one coin, and leaving deposits open would force the crediting rule to decide, transfer by transfer, which of the two arrived and what it will be worth after the swap.
Suspending deposits removes that decision rather than answering it, so that everything credited inside the window is something the platform can still pay out. The failure being avoided is the one familiar from deposits over an unsupported network: the transfer is valid on chain and the system that credits accounts is not watching for it. Kraken's Kyber notice states that deposits of the legacy token after the reopening time will be lost.
Why the same migration closes withdrawals
The withdrawal side stops for a different reason, and it is custody rather than bookkeeping. Customer balances sit pooled in the platform's own wallets, and the swap is performed once, for every holder, out of that pool. While the pool is in motion there is nothing to send.
The hot-wallet float that ordinarily pays withdrawals out is the same balance handed to the migration contract. A second reason outlasts the first: where a migration settles against a balance recorded at a defined moment, the platform has to state exactly what each account held then, and anything still in flight is a figure that is not final. Suspending both directions makes the ledger stand still long enough to be counted.
Notice what is not suspended. Kraken's notice for the Stargate migration records that deposits and withdrawals of the token were stopped while spot trading was not affected. An internal trade moves a balance between two accounts on the same platform and never touches a chain, so it leaves the pooled position unchanged. A funding suspension and a suspended trading pair are separate events, and either can happen without the other.
The two suspensions side by side
| Account-scoped hold | Asset-scoped suspension | |
|---|---|---|
| Trigger | A change to your security settings | A change to the token's contract or chain |
| Covers | Your account | Every holder of that asset |
| Stops | Withdrawals | Deposits and withdrawals of one asset |
| Leaves working | Deposits, trading, your other assets | Trading of that asset and all others |
| Ends when | The waiting period elapses | The migration completes |
Reading the notice you were sent
Two features carry the information: what the notice names, and whether it names an end. Naming an asset makes it asset-scoped; naming a return time makes it a pause. A notice that names an asset and no return is not a pause at all, which is the shape of a delisting, and it asks you to act inside a deadline rather than wait one out.
The last row below belongs with none of the others. Nothing here accounts for a stop that covers every asset, states no reason and names no end; the missing explanation is itself the finding.
| What the notice names | What it is | What ends it |
|---|---|---|
| Your account, withdrawals only | A security hold behind a settings change | The waiting period elapsing |
| One asset, both directions, a return time | A migration or a chain upgrade | The window closing on schedule |
| One asset, both directions, no return time | Support for that asset ending | A deadline you have to act inside |
| Every asset, no reason, no end | No mechanism above | Not stated, which is the thing to notice |
The bottom line
A hold on your withdrawals after a change to a password, a second factor or a whitelist exists because the platform cannot distinguish you from someone using your credentials. It delays the one step that cannot be undone and warns you while the delay runs. It ends by elapsing, and nothing done from inside the account shortens it.
A suspension of deposits and withdrawals in a single asset exists because the asset is being replaced. Deposits close so that nothing is credited which cannot later be paid out; withdrawals close because the pooled balance is inside the swap and the ledger has to stand still to be counted. Trading in that same asset can continue throughout, which is the clearest sign that a funding suspension is not a trading suspension. Work out which of the two you are reading, then either wait out a timer or act inside a deadline. To keep learning the fundamentals, follow more from Bitbase Academy.
Related reading
Other Bitbase articles on this topic:
- Corporate Crypto Account Verification: KYC Requirements for a Business
- Crypto Dust Conversion and the Records It Leaves
- Missed the Withdrawal Deadline on a Delisted Token
- Small Balance Conversion After a Token Delisting
- Cryptocurrency versus Digital Asset
Disclaimer: This article is educational content from Bitbase Academy, provided for information only. It does not constitute investment, trading, tax, or financial advice. Crypto assets are volatile; assess your own risk. Written as of September 2026; refer to the latest official information.
References
[1] Kraken Support, Why is there a withdrawal hold on my account? support.kraken.com
[2] Kraken Support, What is the Global Settings Lock (GSL)? support.kraken.com
[3] Kraken Support, Nillion (NIL) Token Migration to Ethereum support.kraken.com
[4] Kraken Support, Kyber KNC token migration support.kraken.com
[5] Kraken Support, Notice regarding the Stargate Finance (STG) token migration support.kraken.com






