As we have explained to this user over email, his account had the email changed by using our "change email" feature that requires the user to have access to the previous email to complete the process.
We also offer 2FA but the user did not had it enabled in his account.
We are not responsible and cannot prevent an attacker if the account is not properly secured and the attacker has access to the users email, if you want extra security please enable 2FA.
Well, always same reply template to all similar issue right? that is your one sided claim and always put blame on your user without helping them to solve the problem, i frequently asked your help to provide me with some information that support your claim that my email was the source of the problem so i can make action if that is true, considering that you openly lie about 2FA in my account, make me think something is wrong in your internal management, either you don't get the right information before replying or you covering something, because i believe you can always check the timing when i activated 2FA for first time or when it was deactivated.
Even when i actively try to find solution and communicate and tracking my investor, your support only trying to mislead the case, not answering simple direct question, claiming false action. for example, i'm the first to notify there was suspicious email change and comment to inform my investors, yet your support said they suspend my account after that but unauthorized withdraw still happened in that same day, so either your support lie about the timing of account suspend or it was done deliberately, and there are also few other suspicious action/claim from your support that was not correct if it compared with the timing stamp of every action, and by avoiding to answer simple direct question make whole communication process difficult.
From this case obviously we can assume that your "change email" feature did not protect your users and since unauthorized user can change registered email several times like your own support said and without your support asking for identification for repeated attempt of using/abusing that feature.