Is Passing a Liveness Check Enough to Prove It’s You?

BeginnerLast Updated July 17, 2026
Is Passing a Liveness Check Enough to Prove It’s You?

Facial liveness verification is commonly used during identity checks, account recovery, and security setting changes. It can help determine whether the camera is capturing a live person rather than a photo or prerecorded video.

 

But what if an attacker already has your identity documents, transaction records, payment information, or access to your email or device? As AI-generated faces and videos become more realistic, passing one liveness check may not be enough to prove that the person controlling the account is its legitimate owner.

Why Liveness Verification Is Not Enough on Its Own

Liveness verification can stop many simple attacks, such as using a printed photograph or replaying a basic video in front of the camera.
 
However, AI-generated images and videos are becoming increasingly realistic. Attackers may be able to create synthetic faces that blink, turn, speak, or respond to instructions.
 
They may also attempt to manipulate the video sent to the verification system rather than simply placing a fake image in front of the camera.
 
This does not mean facial verification is useless. It remains an important security measure. But it is only one part of a broader security process.
 
A successful liveness check cannot independently confirm that:
  • the user’s device and camera feed are secure
  • the user’s personal and account information has not been stolen
  • the request was made by the legitimate account owner

The Bigger Risk: AI Combined With Stolen Personal Information

A convincing account takeover usually requires more than a fake face.
 
Attackers may also collect:
  • identity documents or KYC materials;
  • email addresses and phone numbers;
  • account and transaction records;
  • banking or payment screenshots;
  • passwords, verification codes, or active login sessions.
This information may be obtained through phishing, fake customer support, malware, screen-sharing scams, compromised email accounts, or previous data leaks.
 
AI can imitate your face. Stolen personal information can help attackers imitate your identity.
When combined, they can make an account takeover attempt far more convincing.
 
For this reason, users should protect identity documents, payment records, transaction details, and verification videos with the same care as passwords and verification codes.

How to Protect Your KuCoin Account

✅ Use a passkey and secure your email

Enable a passkey for your KuCoin account on a trusted personal device.
 
Although a passkey may use Face ID or a fingerprint, it works differently from remote facial verification. Your biometric information stays on your device and is used locally to unlock a secure login credential.
 
You should also protect your email account with a passkey, authenticator app, or hardware security key whenever available.

✅ Protect your personal and account information

Never send identity documents, KYC videos, payment recordings, complete transaction histories, passwords, or verification codes to an unverified person.
 
Be cautious even when someone claims to represent customer support, law enforcement, a lawyer, or another trusted organization. Always verify the request through an official channel.
 

✅ Keep your devices secure

Only use the official KuCoin website and application.
 
Do not install unknown applications, suspicious browser extensions, unofficial exchange software, or remote-control tools at someone else’s request.
 
Do not allow strangers to access your screen, camera, messages, or device settings.

✅ Review your account security regularly

Check your account for:
  • unfamiliar devices or login activity
  • unknown passkeys
  • unexpected changes to your email or phone number
  • unrecognized API keys
  • withdrawals or security actions you did not initiate
Remove any device or credential you no longer recognize or use.

⚠️ Never Ignore an Unexpected Security Notification

Security notifications are not just routine messages. They may be your final opportunity to stop an account takeover before assets can be withdrawn.
 
Take immediate action if you receive a notification about:
  • a password or 2FA reset
  • a new device login
  • an email or phone number change
  • a new passkey
  • an account recovery request
  • a new API key
  • a withdrawal you did not initiate
Do not click links in suspicious messages. Open the official KuCoin application or manually enter the official website address.

If you suspect that your account has been compromised:

  1. Contact KuCoin Support through an official channel.
  2. Change your email password from a trusted device.
  3. Remove unfamiliar devices, sessions, passkeys, and API keys.
  4. Save relevant emails, messages, login records, and transaction information.

Final Reminder

Facial liveness verification remains useful, but it is not absolute proof of account ownership.
The strongest protection comes from multiple security layers working together: trusted devices, passkeys, protected personal information, account monitoring, and rapid action.

Disclaimer: The information on this page may come from third parties and does not necessarily reflect KuCoin’s views. It is provided for general reference only and should not be interpreted as financial or investment advice.

Virtual asset investments may involve risk. Please carefully assess the product risks and your own risk tolerance. For more information, please refer to our Terms of Use and Risk Disclosure.