The pragmatic checklist I’d run: log out all devices, rotate password and 2FA, switch to a hardware key/WebAuthn, audit browser extensions (disable anything non‑essential), scan the box, and revoke any third‑party app access tied to Reddit. On the policy side, keep a clear timeline of IPs and actions; in my experience, a concise paper trail sometimes gets a human review even when the first appeal doesn’t. Glad the account is back—hopefully it sticks.