The photo looks fine to you. You are in the frame, the light is on, the document is the same one you have used everywhere else, and the app still says the check did not pass. The refusal rarely says which half of the check failed, and the two halves fail for unrelated reasons. Working out which one you are standing in front of decides whether the fix is a better photograph or a different document.
What the selfie step is actually testing
The selfie is not a photograph being filed. It is the input to two tests that run in sequence, and clearing one does not carry you through the other.
The first is a comparison. The face in front of the camera is scored against the face printed on the document you uploaded, and a threshold is applied to that score. The second asks whether there is a live person in front of the lens at all, rather than a screen, a printout, a video replay or a mask. That second question has a name in the standards world, presentation attack detection, and the National Institute of Standards and Technology runs a public evaluation of software-based implementations of it.
Both sit inside the wider account verification flow a regulated platform runs before it lets you trade or withdraw freely. Either can refuse while the other would have passed, which is why advice about lighting is sometimes exactly right and sometimes beside the point.
Why a live face gets read as a replay
A liveness check is a classifier, and a classifier has two ways to be wrong. It can accept an attack, and it can refuse a genuine person. The second kind of error is not a malfunction. It is the price of the first kind being rare.
Suppose a check clears 19 of every 20 genuine attempts. That is a 95% pass rate per attempt, and the 5% that are refused are not fraud. They are the tail of a distribution, and on any given evening you can be in it. Tightening the threshold to catch more attacks moves people from the first group into the second, so a platform reacting to a wave of fraud refuses more real customers, not fewer.
What pushes a genuine capture into that tail is anything that makes a real face resemble a reproduction of one: a screen behind you, a reflection on glasses, a face lit flatly from one side, heavy compression, motion blur from a hand that moved. None of these is a rule you broke. Each removes the texture, depth cue or micro-movement the classifier was reading.
The capture conditions that decide the result
Clearing a liveness refusal is a matter of changing the physical setup rather than the attempt count. Retrying the same capture in the same room reproduces the same input.
| What is in the frame | Why it costs you the check | What to change |
|---|---|---|
| A window or lamp behind you | The camera exposes for the bright area and the face loses detail | Put the light in front of you |
| Glasses, a visor, a screen reflection | Reflections read as a flat surface rather than a face | Remove eyewear for the capture |
| A hat, hood, mask or heavy fringe | Measured features sit outside the visible area | Uncover forehead, ears and jawline |
| A second person or a poster with a face | Two faces in one frame make the match ambiguous | Use a plain wall |
| A weak connection | Compression destroys the detail the classifier reads | Capture on a stable network |
Hold the device still, at arm's length, with your face filling the frame. Follow the on-screen instruction exactly where there is one: a check that asks you to turn your head is measuring that movement, and doing something else is a refusal by definition rather than a false one.
Capture inside the platform's own app or website. A screenshot of a selfie, a photograph of a photograph, and a picture taken through a video call are, from the classifier's point of view, precisely the attacks it exists to detect.
When the document is the half that failed
A refusal delivered as a failed selfie can be the document side coming back short, because the comparison needs a usable face at both ends of it.
A document image fails when glare from a laminate covers the portrait, when a corner falls outside the frame, when what you uploaded is a scan of a photocopy rather than the object itself, or when the machine-readable zone along the bottom is cut off. The face on a document is also older than the one at the camera, and a portrait predating a decade of change, a beard, or a large change in weight lowers the score against a face that is unmistakably yours.
Photograph the document flat on a dark, non-reflective surface, in indirect light, with all four corners inside the frame. Where a platform accepts more than one document type, an unexpired passport carries a full-page portrait and a standard machine-readable zone, which gives the reader more than a card with a small photograph on a patterned background.
What the refusal maps to
| What you see | What it points at | The move that changes it |
|---|---|---|
| Face does not match the document | Similarity below threshold | Recapture in even light, or submit a newer document |
| Could not detect a live person | Presentation attack detection | Change the lighting and background, remove eyewear |
| Document unreadable or unsupported | The document side | Reshoot flat, or use a different accepted document |
| Details do not match your account | Registration data, not the image | Correct the name or date of birth on the account |
| Too many attempts | An attempt cap | Wait for the window to reset, then change conditions |
| Under manual review | A human queue | Wait; a further submission restarts the queue |
Read the message for the side it names before you retake anything. A refusal about the document is not answered by a better selfie, and the reverse holds just as firmly.
The mismatches that no retake can reach
Some refusals are about the account record rather than the camera. Where the name on your profile is a shortened form, a married name, or transliterated differently from the document, the comparison fails however good the photograph is. The same applies to a date of birth entered in the wrong order, an expired document, and a document issued by a country the platform does not support.
Duplicate identity is the other case. Where an identity is already attached to another account on the same platform, a second application can be refused with no statement about why, since telling an applicant that an identity is already registered is itself a disclosure. If you opened an account years ago and forgot it, the route runs through recovery on the original profile rather than a new verification attempt.
A refusal here carries a consequence you feel later. Verification tiers set your withdrawal limit, so an unresolved check is not only a blocked signup. It is a cap that stays where it is.
What happens after the last attempt
Attempt caps exist because unlimited retries are how an attacker tunes an image until it passes. At the cap, the case moves to a queue where a person reads the file, and European data protection law shapes what you can ask for there: where a decision produces legal or similarly significant effects and was taken by automated processing alone, the person affected has the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.
Note what that gives you and what it does not. It gives you a human reader and the right to state your case. It does not promise the outcome you want, and it does not shorten the queue. Sending the same capture again while a review is open restarts it.
Handle the documents with the care their legal status implies. Biometric data processed for the purpose of uniquely identifying a natural person sits in the special category that Article 9 of the General Data Protection Regulation prohibits processing outright, subject to the exceptions listed there. That is why a platform collects the capture inside its own app instead of over a chat window.
A stuck check is what impersonation attaches itself to, because an account that cannot pass verification belongs to someone actively looking for help. A message offering to push it through, an agent asking for the document by email, or a paid service promising an approved KYC file is collecting the exact set of documents needed to open accounts in your name. An email carrying your anti-phishing code is one the platform actually sent; one without it proves nothing except that it arrived. Bitbase customer service does not ask for your documents outside the platform, and no fee moves a review.
The bottom line
A failing selfie check is two tests wearing one error message. One compares your face to the document, and it degrades with uneven light, an old portrait or a poor scan. The other decides whether a live person is present, and it refuses genuine people at a rate that is the direct cost of refusing attacks.
Read the message for the side it names, then change the physical conditions rather than the attempt count: light in front of you, a plain background, no eyewear, the document flat and complete in frame. Where the block is a name, a date, an expired document or an identity already on file, no retake reaches it, and the route is the account record or a human review. Send documents only inside the official app, and treat any offer to speed the process up as the thing it is. To keep learning the fundamentals, follow more from Bitbase Academy.
Related reading
Other Bitbase articles on this topic:
- How to Appeal a Crypto Exchange Account Restriction
- Small Balance Conversion After a Token Delisting
- Aggregated, Cross-Exchange, and Hidden Liquidity
- Institutional and Permissioned DeFi
- Double Top and Double Bottom Patterns
Disclaimer: This article is educational content from Bitbase Academy, provided for information only. It does not constitute investment, trading, tax, or financial advice. Crypto assets are volatile; assess your own risk. Written as of September 2026; refer to the latest official information.
References
[1] Regulation (EU) 2016/679 (General Data Protection Regulation), Article 9, Processing of special categories of personal data gdpr-info.eu
[2] Regulation (EU) 2016/679 (General Data Protection Regulation), Article 22, Automated individual decision-making, including profiling gdpr-info.eu
[3] National Institute of Standards and Technology, Face Analysis Technology Evaluation (FATE) PAD pages.nist.gov






