In that scenario we simply demand the signed message from user and if not get that we will send back the coins to the address from where the coin is transferred :-)
Nice to see that paul is like ... :-)
Genius idea, you'd send the coins to a non-related cold address in the case of zencloud. I guess there are other wallets that work like this too.
also, what about blockchain? there could be 10 or more tx from one wallet?
As i already stated we will add this to faq so that user can be aware of it. And if one or two transactions of these type comes we will try to verify by asking for copy of withdrawal confirmation mail received from the exchange they transferred the coin.