Bitcoin Forum
September 29, 2026, 07:42:57 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 »  All
  Print  
Author Topic: How hackers can use your Email to take over your crypto exchange account  (Read 808 times)
Queentoshi
Sr. Member
****
Offline

Activity: 1260
Merit: 365


View Profile
September 20, 2026, 05:28:21 PM
 #21

So I read this warning from Singapore Police where attackers first gain access to their victim's email account, and once inside they can easily search the inbox and find out what crypto exchanges you are using. And because they are smart, they can create email rules to hide security notifications, then request a password reset from the exchange and intercept the reset link or verification email without the user noticing it.
A lot of things can be accessed through your emails, this is why you have to ensure that your email is protected from cyber criminals or people with access to it because asides the crypto exchanges that can be verified you make use of through your emails, your banking details and some other importance documents can be found in your email. As a way to ensure that a breach in access to your email does not expose you generally to security attacks on all fronts like your crypto exchanges, your bank account details, casino profile or any other important thing where an access can be requested through your email, You have to try as much as possible to use different emails for different purposes for instance a different email for your crypto exchanges, and a different email for your normal day to day activities.

Using one email for everything is a big risk.
Mrbluntzy
Sr. Member
****
Offline

Activity: 952
Merit: 277



View Profile WWW
September 20, 2026, 05:45:15 PM
 #22

make sure you've got withdrawal address whitelisting/delay set up on your exchange, though not all of them have this option, and this will mean that even if they reset your password, they won't be able to set up a new address to withdraw to and cash out right away. There will be a delay of 24-48hrs, depending on the exchange, for new addresses to become valid. That will give you a chance to secure your account.
A whitelisted withdrawal address can not save you, despite that it will take 24 hours before withdrawal can be allowed after resetting a withdrawal address, that will not even buy you any time to secure your account, except your account was hacked by a dumb hacker. Are you not aware that once a hacker gains access to your funded exchange and successfully change the password, the first thing they do is to set a 2FA and once they have done that, before you can regain back access to that exchange, they must have already bought enough time with that 2FA that they set up on your account and they will move your money before you gain back access.

It's better they don't even gain access to your account at all, do every best to add 2FA before hackers do it for you and just like the first comment said, avoid exchanges that doesn't have the feature to set 2FA on your account. The security of the exchange I am using is to strong that you will have to pass 2 phase 2FA before you can reset password, make withdrawal or do P2P trade.
AmaGold70
Sr. Member
****
Offline

Activity: 910
Merit: 272



View Profile
September 20, 2026, 06:33:11 PM
 #23

Some of these hackers can be very misteriuos in nature as they look for any little information about you to really gain access to somebody's cryptocurrency account, and it is necessary for cryptocurrency investors or traders to be fully aware of this , and ensure every bit of your security details are being hidden from them. For one to be safe, ensure your phone number, email, username are not exposed or saved on any of your cryptocurrency platforms for them to see. We do hear many times how people's account are hacked, and their Bitcoin stolen, but before someone will be able to tamper with your account, the person must gain access to some of these information before they will be able to do that.

Royal Cap
Sr. Member
****
Offline

Activity: 588
Merit: 278



View Profile WWW
September 20, 2026, 07:22:29 PM
 #24

While the others are pointing out about the use of 2FA. The other practice is that you should not use the same passwords for all of your accounts.

The login details of your email should be different from your exchanges. Because you'll never know that even if there's no hacking incident, the person behind the database could have that ill intention of remembering the login details from the exchange account.

It is true that not using the same password everywhere helps a lot. But since the OP is talking about a Google account being hacked, then even if you use a different password on your Exchange account, hackers can still send a recovery link to your email address via the Forgot Password and through that they can hack your Exchange account. So in this case, two factor authentication is definitely necessary. Also, I think that you should never keep all your funds in one exchange. For financial matters, I think that you should spread them out across all the places, so that by any chance, even if an account gets hacked, all your funds are not lost.

ColdLava40
Full Member
***
Offline

Activity: 518
Merit: 188



View Profile WWW
September 20, 2026, 07:33:19 PM
 #25

Based on the report, we should also check our email forwarding settings, inbox rules and active sessions from time to time because unusual changes there can be a sign that someone already gained access to our email. With this incident it tells us that securing the exchange account alone is not enough, because the email connected to it can also become the easiest way for an attacker to get inside.
All crypto exchange I've come to use before all had some security tips that included adding a 2fa verification to your account before you would be able to carry out any transactions.

And for exchange accounts, when you don't store money in there and something like this happens, you have little to nothing to worry about. Except you are the type who keeps money in their exchange accounts.

I still remember that when an exchange account is logged in on a new device, the old login usually logs you out from your account. So if the attackers had access to it, you would lose your access too.

To avoid these kind of issues just avoid leaving fund in your exchange accounts.

Findingnemo
Legendary
*
Offline

Activity: 3192
Merit: 1142


Leading Crypto Sports Betting & Casino Platform


View Profile
September 20, 2026, 07:36:41 PM
 #26

That is why exchanges offers multiple security layers to avoid unauthorized access even when your email is hacked and some exchanges don't even allow withdrawal after a password change for the same reason too.

Make sure you have 2FA via an authenticator apps and also keep the backup codes offline not in the same cloud storage or the email inbox itself. Also, exchanges might request more details to reset the password when 2FA is enabled. So it is not an easy taks for the hacked to steal the crypto after gaining access to your mail but still being cautious is a good thing.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
The Cryptovator
Legendary
*
Offline

Activity: 3024
Merit: 2621


Protect your privacy 🔏 it's very important


View Profile WWW
September 20, 2026, 07:48:19 PM
 #27

So I read this warning from Singapore Police where attackers first gain access to their victim's email account, and once inside they can easily search the inbox and find out what crypto exchanges you are using. And because they are smart, they can create email rules to hide security notifications, then request a password reset from the exchange and intercept the reset link or verification email without the user noticing it.
This is the biggest issue so far for the crypto user. Those who have been using various crypto platforms like exchanges and other platforms must secure their email address. This is the most important for us to secure our funds. We know hackers always target accessing our email first, and then they follow the procedure you wrote above.

Hiding the security notice is more dangerous than changing the email password. Because once a crypto user lost email access, then he could contact the exchange and make them aware to lock the account. Because most exchanges disable withdrawals at least 24 hours after resetting the exchange's password.

So I agree with you; we have to secure email passwords and don’t use the same password for all the exchanges and crypto platforms.

Freeveto
Full Member
***
Offline

Activity: 472
Merit: 138



View Profile
September 20, 2026, 08:00:34 PM
 #28

So even if the exchange has good security, if our email is not properly secured, there is only so much the exchange can do to protect us. For me, using a different password for your email and exchange is really a must, and if there is 2FA available we should activate it.

The security of our emails should be our responsibility; the exchange cannot do anything about hacked emails, but I am wondering how scammers gain access to emails easily. Do they attempt changing passwords of the mail so that when they gain access to the mail, they go further to check the email inbox and know the exchanges the users are using? If yes, then we need external security to be added to secure our emails, if possible, 2FA for the emails because some of us save some sensitive information in the email.
If we can add extra security to our emails, our exchange accounts are almost safe even without 2FA, but we should add the 2FA for external security.

Above all, it is not encouraged to save your Bitcoin in an exchange; your 2FA will not save your Bitcoin if the exchange is being hacked. Learn to keep self-custody of your Bitcoin and stop relying on exchanges to help you out.

uchegod-21
Hero Member
*****
Offline

Activity: 1806
Merit: 744


Are we ever seeing $126k again?


View Profile
September 20, 2026, 09:15:42 PM
 #29

and if there is 2FA available we should activate it.
Any exchange that does not have 2FA should be avoided. All exchanges that know the importance of 2FA make it available for their customers that are using their exchange. Even some exchanges make it mandatory to set before new customers will continue using the exchange.

2FA can also be set on email. A good email service provider will let you know when anyone want to compromise your email account, it will give you options in a way the person will not be able to.

Some email service providers also give options for 2FA which will be required if you want to login in from a new device.
I know that hackers are getting more sophisticated with their skills, but from my email, I get notified immediately whenever I log in to my email from another device. This is why I am wondering how it would be possible for one's email to be accessed or hacked by a third party without any notification at all from the device to alert the owner of the email account of unusual activity going on on the account.

We cannot hide our emails from the public. The constant KYC verifications and others expose our emails to the public. What we can do for ourselves is make sure that these emails remain inaccessible to unauthorized persons. This can be achieved by making sure to use very strong passwords for email accounts and every other account requiring password usage.

Next will be using only security-conscious exchanges, i.e., exchanges that use 2FA. Security is such a great deal that should never be neglected.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
█████████░█████░█████████
████████▀▀░▄▄▄░▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄░▀▀▀░▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
 
  Open − code isolated Crypto Wallet     Sign Up    
boyptc
Hero Member
*****
Offline

Activity: 3864
Merit: 713


www.Crypto.Games: Multiple coins, multiple games


View Profile
September 20, 2026, 09:22:02 PM
 #30

While the others are pointing out about the use of 2FA. The other practice is that you should not use the same passwords for all of your accounts.

The login details of your email should be different from your exchanges. Because you'll never know that even if there's no hacking incident, the person behind the database could have that ill intention of remembering the login details from the exchange account.

It is true that not using the same password everywhere helps a lot. But since the OP is talking about a Google account being hacked, then even if you use a different password on your Exchange account, hackers can still send a recovery link to your email address via the Forgot Password and through that they can hack your Exchange account. So in this case, two factor authentication is definitely necessary. Also, I think that you should never keep all your funds in one exchange. For financial matters, I think that you should spread them out across all the places, so that by any chance, even if an account gets hacked, all your funds are not lost.
You are right but that can also be one of the reasons why your email can be hacked, when you use the same login details for your gmail/yahoo or any other email provider the same as your exchanges account.

You'll only get hacked with your email if you do that or login to a suspicious website. And that's why IMO, it's still a strong way of protecting ourselves from this risk.

So it's a double security matter if you combine it with 2FA and it's the first step before we even use 2FA.

█████████████████████████
███████▄▄▀▀███▀▀▄▄███████
█████▄▀███▄███▄███▀▄█████
█████▄█▄█▀▀███▀▀█▄█▄█████
████▀▀██▀███▀███▀██▀▀████
█████▄█████████████▄█████
████████▀███████▀████████
█████▀█████████████▀█████
████▄▄██▄██▄█▄██▄██▄▄████
█████▀█▀███▀▄████▀█▀█████
█████▀▄███▀███▀███▄▀█████
███████▀▀▄▄███▄▄▀▀███████
█████████████████████████
.
 CRYPTOGAMES 
.
 Catch the winning spirit! 
│█▄░▀███▌░▄
███▄░▀█░▐██▄
▀▀▀▀▀░░░▀▀▀▀▀
████▌░▐█████▀
████░░█████
███▌░▐███▀
███░░███
██▌░▐█▀
PROGRESSIVE
      JACKPOT      
│██░░▄▄
▀▀░░████▄
▄▄▄▄██▀░░▄▄
░░░▀▀█░░▀██▄
███▄░░▀▄░█▀▀
█████░░█░░▄▄█
█████░░██████
█████░░█░░▀▀█
LOW HOUSE
         EDGE         
│██▄
███░░░░░░░▄▄
█▀░░░░░░░████
█▄░░░░░░░░█▀
██▄░░░░░░▄█
███▄▄░░▄██▌
██████████
█████████▌
PREMIUM VIP
 MEMBERSHIP 
│
DICE   ROULETTE   BLACKJACK   KENO   MINESWEEPER   VIDEO POKER   PLINKO   SLOT   LOTTERY
Sammysmart001
Full Member
***
Offline

Activity: 266
Merit: 109


JAH OVER ALL🙇🙏


View Profile WWW
September 20, 2026, 09:31:40 PM
 #31

That is why exchanges offers multiple security layers to avoid unauthorized access even when your email is hacked and some exchanges don't even allow withdrawal after a password change for the same reason too.

Make sure you have 2FA via an authenticator apps and also keep the backup codes offline not in the same cloud storage or the email inbox itself. Also, exchanges might request more details to reset the password when 2FA is enabled. So it is not an easy taks for the hacked to steal the crypto after gaining access to your mail but still being cautious is a good thing.

Keeping of backup codes offline is very important. Users mostly remember to activate their 2FA but also the mistake of storing backup codes inside same email or cloud account they are trying to protect. Backup codes could become a way around tge security if an attacker have an access to their email. You get a separate recovery method by keeping them offline and safely without Having to put everything behind the same point of failure. Adding of more layers is not only about security but for also making absolutely sure that the layers aren’t connected to same account.

PrivacyG
Legendary
*
Offline

Activity: 1652
Merit: 3103


♻️ Automatic Exchange


View Profile
September 20, 2026, 09:32:25 PM
 #32

I used to have a separate e-mail account for each exchange I was registered on to.  It was pretty difficult to manage all of them but I knew which e-mail being compromise affected which account.  I have seen others practice a more simplistic version of this, as in one e-mail for exchanges, another for personal things.

Anyway.  It is kind of obvious an e-mail compromise can hurt you a lot.  Particularly if you use one single account for every thing.  They can contact institutions, make requests, reset passwords et cetera while copying even your writing style with high accuracy, particularly now with 'AI' trending.

░░░░▄▄████████████▄
░▄████████████████▀
▄████████████████▀▄█▄
▄███████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀░▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀░▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄░▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀░
▀████████████▀▀░░░░
 
 CCECASH 
noorman0
Hero Member
*****
Offline

Activity: 2142
Merit: 876


[Nope]No hype delivers more than hope


View Profile WWW
September 20, 2026, 09:48:15 PM
 #33

-snip-
but I am wondering how scammers gain access to emails easily. Do they attempt changing passwords of the mail so that when they gain access to the mail, they go further to check the email inbox and know the exchanges the users are using?
They carry out social engineering attacks, impersonating others to steal login credentials. If they can determine the source of the compromised email, they gain insight into whether it is linked to a service that holds funds. The more information they possess regarding that email, the greater their chances of convincing the victim.

EL MOHA
Hero Member
*****
Offline

Activity: 1274
Merit: 514



View Profile
September 20, 2026, 11:01:37 PM
 #34

I used to have a separate e-mail account for each exchange I was registered on to.  It was pretty difficult to manage all of them but I knew which e-mail being compromise affected which account.  I have seen others practice a more simplistic version of this, as in one e-mail for exchanges, another for personal things.


This what is advisable to practice by any one. This clearly using burner emails and it’s highly recommended. Usually the best is to avoid platforms that requires emails but it’s not possible in some cases as such best yes you do is to use burner emails. The thing is you don’t actually set very difficult login details on them so that you don’t actually get confused if it actually get comprised too. Exchange emails should never be your personal or main email because they are the most easily compromised ones.

Alphakilo
Sr. Member
****
Offline

Activity: 1204
Merit: 318


⭐ Razed.com ⭐ The Best Crypto Casino


View Profile
September 20, 2026, 11:14:16 PM
 #35

I used to have a separate e-mail account for each exchange I was registered on to.  It was pretty difficult to manage all of them but I knew which e-mail being compromise affected which account.  I have seen others practice a more simplistic version of this, as in one e-mail for exchanges, another for personal things.

Anyway.  It is kind of obvious an e-mail compromise can hurt you a lot.  Particularly if you use one single account for every thing.  They can contact institutions, make requests, reset passwords et cetera while copying even your writing style with high accuracy, particularly now with 'AI' trending.
The whole AI trending thing is even what scares me the most because AI can literally give any hacker easier ways to access one's email or other accounts because these hackers know the exact kind of prompt to use that doesn't make it suspicious.

Still, we should make it a daily habit of always checking our emails because I have confidence that if we are online while a hacker tries to meddle into our account, we can easily detect it because I don't believe a strong email service like Gmail which is under Google will make it easier without asking questions or notifying the original device that has strong presence of a steady login activity of a breach in security.
Using separate emails for normal life and exchanges or financial institutions is a better idea and I don't think anyone should underestimate the importance of a 2FA too.



RAZED | 100%  
WELCOME
BONUS
│
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
|
NO
KYC
│███████████████████████
 RAZE THE LIMITS   ►PLAY NOW
███████████████████████
Rengga Jati
Hero Member
*****
Offline

Activity: 2646
Merit: 702


Owlmail.cc


View Profile WWW
September 20, 2026, 11:17:09 PM
 #36

That is why, whenever you create an exchange account, you should ensure a few things:
- Set up email access on more than one device! This ensures you to receive a notification, if a login attempt is from outside your usual location.
- Always enable 2FA! I am sure that most exchanges support this by now. This involves using more than just a standard email code. You can use certain methods. Such as: like Google Authenticator, a specific PIN, phone number notifications, or other options. It will probably provide a higher level of security. Better than relying solely on email notifications.

█▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
███████▀▄▄▄▄▄▄▀
███████▐██████▌
███████████████
███████████████▄
█████████████████
███████▐██████████
███████▐██████████▌
██████████████████▌
████████▀█████████
█████████▀███████▌
████████▄▀▀█░▄▀▀█▌
█▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
 
OWLMAIL
 
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄▄█
 
  ANONYMOUS EMAIL │  No JavaScript. No Logs. Tor Mirror   
█▀▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄▄
▀▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄▄█
X-ray
Hero Member
*****
Offline

Activity: 3738
Merit: 576


Leading Crypto Sports Betting & Casino Platform


View Profile
September 21, 2026, 02:17:26 AM
 #37

Although this is plausible, a simple 2fa and sms authenticator is going to solve this weak link, moreover if you have static IP, the exchange will prompt for face verification when the hacker is trying to log in using different IP even if the hacker use proxy or vpn from the same country.

In simple words, exchange knew this is security hole and has come up with several solution.

Maybe one thing that could really become a threat is cloud authenticator linked with your account, that's when the hacker able to access your 2fa and google password manager if you don't enable on-device encryption.

Other than that, it's pretty outdated security advice but I won't simply dismiss and ignore it, still a good insight for people who aren't really well versed with cyber security even though average people who at least know their way around internet, mostly already know.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
hd49728
Legendary
*
Offline

Activity: 2954
Merit: 1390



View Profile
September 21, 2026, 02:21:44 AM
 #38

That is why, whenever you create an exchange account, you should ensure a few things:
- Set up email access on more than one device! This ensures you to receive a notification, if a login attempt is from outside your usual location.
- Always enable 2FA! I am sure that most exchanges support this by now. This involves using more than just a standard email code. You can use certain methods.
2FA activation for your exchange account and your email is a very good security advice but it's not enough. It's second layer security protection so it must be installed and activated on a second device, that is different than a device you log in your exchange account and email account.

Many people install and store everything on one device, log in every accounts on one device, with such practice, 2FA won't be able to secure their exchange account and fund.

Quote
Such as: like Google Authenticator, a specific PIN, phone number notifications, or other options. It will probably provide a higher level of security. Better than relying solely on email notifications.
Google Authenticator is not a good 2FA application.
It's close source.
Years ago, it launched a feature to allow user backup their 2FA code in cloud storage.

There are other choices, better too, like open source 2FA.
https://getaegis.app/

jcojci
Full Member
***
Offline

Activity: 1960
Merit: 206


Bitz.io Best Bitcoin and Crypto Casino


View Profile
September 21, 2026, 03:51:31 AM
 #39

You should separate email for exchanges and others such as businesses, forums, and else to minimize the hack. We responsible with our security so we must be careful and not mixing all emails in just one or two emails.

While having more than one email is allow, we should use that for our needs so we don't have to worry with the hack. Don't share the email to random place or people and just use email base on the needs. Don't forget to use complex password and more than 8 characters.

osasshem
Full Member
***
Offline

Activity: 1218
Merit: 137


Creating a Safer Crypto Ecosystem


View Profile
September 21, 2026, 04:04:14 AM
 #40

The take away lesson from this is to always have an extra layer of security on both our exchange accounts and our email addresses used in registering those accounts, and also make an occasional password resets. Also, have different passwords for our different accounts online will also help to reduce the password guess on our accounts.

Using 2FA and SMS Verification attached to both our Gmails and exchanges, and Gmail verification codes may sound to be long when all are used at once, but the better the security use for the safety of our different accounts across the internet.

Pages: « 1 [2] 3 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!