Bitcoin Forum
September 27, 2026, 11:48:47 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 [4]  All
  Print  
Author Topic: How hackers can use your Email to take over your crypto exchange account  (Read 734 times)
adultcrypto
Hero Member
*****
Offline

Activity: 1190
Merit: 584



View Profile
September 24, 2026, 05:02:17 PM
 #61

Where the user set 2FA, it wil require resetting that before being able to access the exchange account and the process may signal the owner of the account through notification. I don't know if the post detailed how to also boycott this in the hacking process. Protecting the email is very important as a lot can be compromised if the email is accessed.

█████████████████████████
████████
▀▀████▄▀█████████
███████
██████▐█░█████████
████████
███████▐█████████
████████
▌███▐████████████
███████
▀▀███▀▀▀▀▀▀▀██████
█████
▄███▄▄▄▄▄▄▄███▄█████
█████████████████████████
█████████████████████████
█████████████████████████
██████████
▀███▀██████████
█████████
▌█▄▄▄█▐█████████
█████████████████████████
 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
  PLAY NOW  
Hamza2424
Legendary
*
Offline

Activity: 1778
Merit: 1163



View Profile WWW
September 24, 2026, 06:58:47 PM
 #62

If you lose your email you lose everything, because losing your email means losing access to all Google's services like Drive where people are still holding their seed phrases. No matter how many times they read it is not secure, they will still store their seed phrases there, they will still write their portfolio information in spreadsheets because they have to, and that information can be seen by hackers if they have your email. In short, it is the master key so secure it at all costs. Always check and read every policy, make sure every security feature is turned on in your email.

Email forwarding settings are very crucial bro, thanks for mentioning them because it's been a long time since I checked anything like this, but the best practice is to use a completely separate email just for exchanges, and if it is possible to manage multiple emails, then don't use the same email for all the exchanges.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
goldkingcoiner
Legendary
*
Offline

Activity: 2912
Merit: 3129


HoDL


View Profile WWW
September 24, 2026, 07:06:04 PM
 #63

As traders, we usually focus on securing our crypto exchange accounts and making sure they will not be hacked, but sometimes the problem is not there, it's actually the email address we are using.

So I read this warning from Singapore Police where attackers first gain access to their victim's email account, and once inside they can easily search the inbox and find out what crypto exchanges you are using. And because they are smart, they can create email rules to hide security notifications, then request a password reset from the exchange and intercept the reset link or verification email without the user noticing it.

So here's the usual format of the attack:

Your old or reused password gets leaked.

[1] They gain access to your email
[2] They search which crypto exchanges you are using
[3] Hide security emails using inbox rules
[4] Reset your exchange password
[5] If successful, they gain access to the account

So even if the exchange has good security, if our email is not properly secured, there is only so much the exchange can do to protect us. For me, using a different password for your email and exchange is really a must, and if there is 2FA available we should activate it.

Based on the report, we should also check our email forwarding settings, inbox rules and active sessions from time to time because unusual changes there can be a sign that someone already gained access to our email. With this incident it tells us that securing the exchange account alone is not enough, because the email connected to it can also become the easiest way for an attacker to get inside.


As long as you have 2FA authentication on your cryptoexchange account, simply gaining access to their E-Mail will not be enough to withdraw their coins. But then again, anybody who is clumsy enough to get their account info and passwords leaked is probably also clumsy enough to simply not have 2FA authentication set up in the first place. Although many exchanges kind of force it nowadays...

Z_MBFM
Hero Member
*****
Offline

Activity: 1246
Merit: 506



View Profile WWW
September 24, 2026, 07:11:30 PM
 #64

As far as I know, hackers hack emails through browser cookies. There is a lot of data available for purchase in the black market, which many people buy for business purposes, from there they get login access data for various platforms including emails, they are third parties, while actual hackers directly hack people's browser cookies through various phishing links through various means and from there they get access to various things. Exchangers without 2FA should be avoided, and many times accounts are hacked despite 2FA being set, this is because the email that the hackers hack has a 2FA backup in the same email. Google Authenticator now keeps 2FA codes as a backup in Gmail, in that case, if they get access to the email, they are automatically available. If the email of the Exchange account and the email of the 2FA backup are the same. You have to be careful in all aspects if you want to stay safe from hackers.


███████▄▄███▄███▄
███▄▄████████▌████▄
▄██████████████▐███▌
██▄███████████▌████▌
████████▀███████▐▌█
███████████████▌█▌▐
████████▄████████▐▐
██████████████████▌
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

█▄▄▄██████▄▄▄███████▄▄▄
████████████████████████████
████▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
████▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀██████████▌█████████████▄▄████▀
██████████▄█████▀████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀
 
..PLAY NOW..
Crypto Library
Legendary
*
Offline

Activity: 1722
Merit: 1234


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
September 24, 2026, 08:30:04 PM
 #65

As far as I know, hackers hack emails through browser cookies. There is a lot of data available for purchase in the black market, which many people buy for business purposes, from there they get login access data for various platforms including emails, they are third parties, while actual hackers directly hack people's browser cookies through various phishing links through various means and from there they get access to various things. Exchangers without 2FA should be avoided, and many times accounts are hacked despite 2FA being set, this is because the email that the hackers hack has a 2FA backup in the same email. Google Authenticator now keeps 2FA codes as a backup in Gmail, in that case, if they get access to the email, they are automatically available. If the email of the Exchange account and the email of the 2FA backup are the same. You have to be careful in all aspects if you want to stay safe from hackers.
I don't actually know if it is possible to steal email and password by hijacking browser cookies because as far as I know there is a browser session where there is no email or password.

Here I think they try to hack websites and collect the email and password that is signed up on them. And then they try to do the brute force with the same email and the password on the others platform including the exchanges. 

I think the only way to avoid these situations is to use 2-factor authentication and at the same time check various websites where we can see if our email has already been exposed. If it is positive, then we should definitely change the email password.

Like you can see, one of my email was  exposed with the password-

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Dareo
Full Member
***
Offline

Activity: 406
Merit: 186



View Profile
September 25, 2026, 06:54:13 AM
 #66

Where the user set 2FA, it wil require resetting that before being able to access the exchange account and the process may signal the owner of the account through notification. I don't know if the post detailed how to also boycott this in the hacking process. Protecting the email is very important as a lot can be compromised if the email is accessed.
That's why I think offline devices should be used for two factor authentication. The reason for this is that since no internet is required to use the authenticator, if an authenticator is used on an offline device, then there is almost 0% chance of being hacked. But yes, browser cookies can be stolen, as someone already said above. And this is a very important point. Because if you have your exchange account login in your browser and from there, if your session cookie is stolen due to some malware, then your 2FA security will not be of any use. Then he will be able to access your account without any login. And for this reason, I think the most important thing is that the user must be careful before installing any third party software or crack games.

Leahized
Sr. Member
****
Offline

Activity: 868
Merit: 257


Bitz.io Best Bitcoin and Crypto Casino


View Profile
September 25, 2026, 03:50:50 PM
 #67

Where the user set 2FA, it wil require resetting that before being able to access the exchange account and the process may signal the owner of the account through notification. I don't know if the post detailed how to also boycott this in the hacking process. Protecting the email is very important as a lot can be compromised if the email is accessed.

From my experience, I can say that 2FA can be bypassed when logging into an exchange. Once, despite having funds held in Bitget, I accidentally removed 2FA access from the authenticator. This put me in the most difficult moment. I had to change the 2FA to get the exchange access and was able to do so. Because, with the aim of strengthening security, "Email, Number, 2FA were linked". Which can be used interchangeably for login. And the funny thing is, no code was needed to reset the that.

I believe that, by being cautious hackers will not gain access to the email. Any phishing link or suspicious website should be avoided. This will significantly reduce the risk. If unfortunately, hackers gain access to the email, then there is no need to change the exchange password. Because, we save all passwords on Google and  which can be easily seen.

███ 
███████▄▄███▄███▄
███▄▄████████▌████▄
▄██████████████▐███▌
██▄███████████▌████▌
████████▀███████▐▌█
███████████████▌█▌▐
████████▄████████▐▐
██████████████████▌
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀
Bitz.io███ ████████▄████▄▄▄█████▄▄
██████▄████████▀▀██▀▀
█████▀▀█████▀▀▄▄█
███████████▄▀▀███
████████████████▐▌
████████████████▐▌
███▄▄█████▄▄█▄▄█████▄▄
█▄█████████████████████▄
▄███████████████████████▄
██
███████████████████████
▀██
█████████████████████▀
█▀████
█████████████████▀
███▀▀████▀▀██▀▀█████▀▀
98%
RTP
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄███████████████
██████▄
▄███████████████████████▄
█████████████████████████
█████████████████████████
█████████████████████████
████████████████████████▀
▀█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
HIGH
ODDS
 ███
█████████   ██

......PLAY NOW......

██   █████████
███ 
vs2014
Sr. Member
****
Offline

Activity: 1036
Merit: 250


EagleSwap.to | Crypto Exchange


View Profile WWW
Today at 06:46:04 PM
 #68

It's important for a trader to know how to protect assets and secure account alongside trading. There are some traders who mainly focus too much on exchange account but their forget that email account also connected with exchange account. So people have to ensure email security and it's better to use 2FA along with password for both email and exchange account. Besides if we can separate our email then the possiblity of email hacking may reduced while other gets compromised. Sometimes a small mistakes turn into big one, so taking step asap is better instead of dealing with loss later.

        ▄▄████████▄▄ 
    ▄█▀           ▄▄▄ ▀▀███
▄██                 ███▄▄███
██████▄                   ▀███▄
▀  ▄██▀                 ▄███████
  ▄█▀  ▄█   ▄      ██▀        ▀██
▄█▀▄██   ██    ██               ▀
██████  ██   ██       
█▀    ██  ██   ▀█▄     
        ██    ██     ▀█▄▄▄▄█
        ▀██    ▀█▄     ▀▀▀▀ 
            ▀█▄     ██▄         
❰❰ EagleSwap █▀▀▀
█
█
█
█
█
█
█
█
█
█
█▄▄▄
▀▀▀█
█
█
█
█
█
█
█
█
█
█
▄▄▄█
❱❱
⚡FAST & SECURE
✨24/7 SUPPORT
        ▄▄████████▄▄ 
    ▄█▀           ▄▄▄ ▀▀███
▄██                 ███▄▄███
██████▄                   ▀███▄
▀  ▄██▀                 ▄███████
  ▄█▀  ▄█   ▄      ██▀        ▀██
▄█▀▄██   ██    ██               ▀
██████  ██   ██       
█▀    ██  ██   ▀█▄     
        ██    ██     ▀█▄▄▄▄█
        ▀██    ▀█▄     ▀▀▀▀ 
            ▀█▄     ██▄         
Barcode_
Staff
Hero Member
*****
Offline

Activity: 3850
Merit: 592



View Profile WWW
Today at 07:08:32 PM
 #69

It is always good to use a password that is very complex including letters, numbers and symbols if any traders are intending to keep a large amount of their investment including cash and crypto currencies on their trading account.

If a hacker does truly manage to access a victim email and try to execute a 'forget password action' in order to change the password to make it possible for logging into the victim trading account. I think usually all major reputable crypto currencies exchanges websites will have some sort of automated defensive mechanism in their system which will be activated.

The system will detect a change of IP address which differs from the victim usual log in IP address and usually some sort of confirmation will be needed for a 2FA verification which usually requires the victim phone, whether it is a token verification app or a simple 2fa SMS message. Maybe the victim might realize his trading account is in the process of being hack when they receive some notification on their phone app or via the SMS sent to their phone, and they could try to salvage the situation immediately by contacting a customer service agent to freeze all of their assets in their account with the proper authorization.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Joy- maker
Hero Member
*****
Offline

Activity: 602
Merit: 518


For promotion services t.me/ @JoyMakerbtc.


View Profile WWW
Today at 08:43:52 PM
Last edit: Today at 09:04:28 PM by Joy- maker
 #70

It is funny how crypto traders focus only on securing their trading exchanges and then leave the main thing scammers can use to gain access to those trading exchanges unsecured.  If a scammer successfully gain access to your Gmail account their is every chance they can gain control of your trading exchanges by simply doing what OP just stated.  In my country, one method scammers to gain access to your Gmail account is by swapping your phone number onto another SIM card, then proceed to take control of your exchange, simply by resetting your exchange password since they already have access to your email address to receive the OTP.

Pages: « 1 2 3 [4]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!