The password you reused years ago could give someone a route into your crypto account today.
Singapore police warned on September 12 that they have seen an increase in unauthorised access to cryptocurrency accounts through compromised email since mid-August, according to CNA. Investigators found that several affected email accounts had appeared in earlier data breaches on other platforms. Police said exposed credentials and password reuse may have helped attackers gain access. The warning concerns account takeovers, and does not establish that an exchange’s own systems were breached.
Once inside an inbox, attackers may be able to work out which crypto services its owner uses. Police described the possibility of password-reset requests followed by interception of reset links, verification messages or one-time passwords delivered by email. They also warned that intruders may alter inbox rules to hide exchange messages by forwarding, archiving or deleting them. That makes a quiet inbox a poor substitute for checking the account itself. A notification cannot warn you if someone has arranged for you never to see it.
The inbox deserves the same attention as the exchange
The practical issue is how much authority your email account has over your other accounts. If it receives recovery links, access to that mailbox can become part of the route to changing a login. Reusing a password creates another connection between services that might otherwise have little to do with each other. An old breach at one website can therefore remain relevant long after you stopped using that website. The police’s wording leaves room for differences between individual cases, so this should not be read as a claim that every exchange can be unlocked with email alone.
The warning follows a separate August 21 police advisory about criminals allegedly impersonating Apple support to steal cryptocurrency. In that scheme, police said victims were directed to fraudulent websites and asked for login details and one-time passwords. The reported sequence included unexpected device prompts and unsolicited calls claiming that an account was compromised. Police recorded at least five cases after August 7 in that earlier warning. Those were separate incidents, but they illustrate why an urgent offer to secure an account also needs checking through the provider’s official channels.
Check the settings that can hide a takeover
For the latest warning, police recommended unique passwords and multi-factor authentication, with an authenticator app preferred over SMS where available. Their advice also included reviewing email forwarding rules and suspicious login activity. Crypto users were urged to inspect transaction history and enable activity alerts where supported. That review needs to include the mailbox receiving those alerts. Security settings on the exchange are only part of the picture when account recovery depends on another service.
Anyone who suspects a compromise should contact both the email provider and the crypto exchange promptly, police said, asking them to secure or freeze affected accounts where possible. Password changes should cover the affected accounts and other services where the same password was used. A suspicious login or unexplained forwarding rule deserves attention even before you spot an unfamiliar withdrawal. The useful response to this warning is to check your recovery route while you still control it. Start with the inbox that receives your exchange emails.
—————
Author: Ren Nakamura
Asia Newsroom
Breaking Crypto News





Be the first to comment