|
TedMosby
|
 |
September 21, 2026, 05:24:18 AM |
|
[...] Any exchange that does not have 2FA should be avoided. [...] Some email service providers also give options for 2FA which will be required if you want to login in from a new device.
It's extremely rare for a modern centralized crypto exchange to not offer layered security features like 2FA. Also, as you mentioned, even when the exchange is not providing 2FA, we can provide our email account with an extra layer of security. OTP verification, 2FA, or even a physical hardware security device like YubiKey. It's strange if there's someone who doesn't take it seriously to secure their email account, especially when that account is correlated to money. [...] [1] They gain access to your email [2] They search which crypto exchanges you are using [3] Hide security emails using inbox rules [4] Reset your exchange password [5] If successful, they gain access to the account [...]
Maybe how the hackers gain access to the exchange is not as simple as this. Some people are just too careless to store important stuff like 2FA backup/recovery codes, private keys, or other important information in their drafts. Sometimes, they also send an email about it to themselves. I think this is also significant in making it possible for hackers to gain access easily to an exchange account that is correlated to the email account. Another potential scenario, the 2FA is linked to the email account, so the 2FA can be duplicated by using that email account on another device. Or maybe there's also social engineering involved based on all the information they gather from the email.It's extremely rare for a modern centralized crypto exchange to not offer layered security features like 2FA. Also, as you mentioned, even when the exchange is not providing 2FA, we can provide our email account with an extra layer of security. OTP verification, 2FA, or even a physical hardware security device like YubiKey. It's strange if there's someone who doesn't take it seriously to secure their email account, especially when that account is correlated to money.
|
|
|
|
|
HajiBagi
|
 |
September 21, 2026, 05:39:02 AM |
|
and if there is 2FA available we should activate it.
Any exchange that does not have 2FA should be avoided. All exchanges that know the importance of 2FA make it available for their customers that are using their exchange. Even some exchanges make it mandatory to set before new customers will continue using the exchange. 2FA can also be set on email. A good email service provider will let you know when anyone want to compromise your email account, it will give you options in a way the person will not be able to. Some email service providers also give options for 2FA which will be required if you want to login in from a new device. This is what I used to tell anyone who are very close to me that are holding coin, if they are not using any exchange that has 2FA, they are not safe and they should better do the right thing, some people don't know that scammers are very dangerous and smart people, and no matter how smart you are as an investor, you can get scammed if you are not careful. Scammers have many ways to gain access to your wallet, but there are some steps we can take to protect ourselves against scams. 2FA is really important and we should never forget to activate it, I believe that every exchange has it, it is up to the user to activate it.
|
|
|
|
|
henmark
|
 |
September 21, 2026, 05:42:23 AM |
|
Based on the report, we should also check our email forwarding settings, inbox rules and active sessions from time to time because unusual changes there can be a sign that someone already gained access to our email. With this incident it tells us that securing the exchange account alone is not enough, because the email connected to it can also become the easiest way for an attacker to get inside.
A password for any platform is not good enough for securing your account these days, so there are a few things that every person should do to make sure their accounts are secure. The first and foremost thing is to use Two-Factor Authentication, which is available almost in every platform these days, we even have it on this forum. Two-Factor will not let an attacker gain access to your account even if they manage to hack into your email and resets the password, because they will still need the Two-Factor code to get in. The second thing is to use one email for important stuff such as financial apps and platforms, and you shouldn't use the same email elsewhere. When you have to use other platforms, make sure you create a different email address to use for that, so that even if one of the platforms you are trying to use has evil intentions, they shouldn't be able to find anything connected to that email once they hack into it. These are just a few basic things everyone should follow. The security of your funds is in your hands, the more careful you are, the safer your assets are going to be.
|
|
|
|
|
Somegory
|
 |
September 21, 2026, 05:52:18 AM |
|
It's very simply to avoid this type of stuff.
1. Don't use the same password for your email account on other websites. 2. Every crypto exchanges today have 2FA Auth available, if yours doesn't do not use the exchange. 3. Always consider alternative email accounts, have one aside as the main one and have extra for websites.
Once one of the platforms get attacked and their data got exposed the attackers wil have access to your email and password, they can try it on other platforms to see if you have money on them.
|
|
|
|
|
davis196
|
 |
September 21, 2026, 06:03:12 AM |
|
[1] They gain access to your email [2] They search which crypto exchanges you are using [3] Hide security emails using inbox rules [4] Reset your exchange password [5] If successful, they gain access to the account
So even if the exchange has good security, if our email is not properly secured, there is only so much the exchange can do to protect us. For me, using a different password for your email and exchange is really a must, and if there is 2FA available we should activate it.
AFAIK, this is the most old school way for someone to hack your crypto exchange account, but it still works. It's necessary to activate 2-Factor Authentication for your email address as well, not just for your crypto exchange account. Another popular way of hacking crypto exchange accounts was the "SIM swapping" method, but I do believe that most crypto exchanges have improved their security, so that their customer support cannot be manipulated into giving account access to hackers. I used to keep crypto in my centralized crypto exchange accounts years ago, which was a huge risk, but I moved all my crypto to cold wallets, which don't require an email.
|
|
|
|
|
salad daging
Legendary

Activity: 2520
Merit: 1069
Bitcoin To The Moon 📈📈📈
|
 |
September 21, 2026, 07:56:33 AM |
|
Do not use the same password between Gmail and the store, it must always be different with unique characters.
Always enable the security provided by the exchange: enable 2FA, biometric, anti-phishing code and this should be applied in your email as well to maintain extra security, even though we know hackers are always smart with the loopholes they find.
If you are a trader then the exchange account will be used every day or more often, the point is not to store too many assets on the exchange if only for HODL except for just making trades, and the usual exchange application that you use will get a notification on the screen if there are other devices that try to enter. Anyway as much as possible we should be able to activate security.
I think this topic is more appropriate on trade discussion boards.
|
|
|
|
|
|
red4slash
|
 |
September 21, 2026, 08:05:05 AM |
|
So even if the exchange has good security, if our email is not properly secured, there is only so much the exchange can do to protect us. For me, using a different password for your email and exchange is really a must, and if there is 2FA available we should activate it.
It becomes a very good thing to enable double lock but for some cases especially when it comes to 2FA email also for now synchronized with email so that when the email is broken then All Access can be obtained including for 2FA if the email is the same. So for now protecting email becomes a good thing if we want to secure the exchange especially when the balance in the exchange is still there although for some cases I rarely keep the balance in the exchange but of course prepare from the beginning must be done because of the slightest loss that is felt later we will regret it. The problem that always happens for now at some moments sometimes we are just too focused on things that actually become secondary but forget the primary, like we always try to find options for how we get profit but forget the primary thing in securing the wallet or email that we use in the exchange.
|
| █▄ | R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | ▀█ | THE #1 SOLANA CASINO | ████████████▄ ▀▀██████▀▀███ ██▄▄▀▀▄▄█████ █████████████ █████████████ ███▀█████████ ▀▄▄██████████ █████████████ █████████████ █████████████ █████████████ █████████████ ████████████▀ | ████████████▄ ▀▀▀▀▀▀▀██████ █████████████ ▄████████████ ██▄██████████ ████▄████████ █████████████ █░▀▀█████████ ▀▀███████████ █████▄███████ ████▀▄▀██████ ▄▄▄▄▄▄▄██████ ████████████▀ | ........5,000+........ GAMES ......INSTANT...... WITHDRAWALS | ..........HUGE.......... REWARDS ............VIP............ PROGRAM | . PLAY NOW |
|
|
|
Nathrixxx
Sr. Member
  

Activity: 658
Merit: 299
Bitz.io Best Bitcoin and Crypto Casino
|
 |
September 21, 2026, 02:07:44 PM |
|
Anything that could cause a security breach of the exchange platform we are using can be made easy through the email address, because that is the most commonly used medium for verifying users' information and also receiving login credentials through it. Only a reckless user will allow their email address to be compromised and hijacked by scammers, as this can give them access to reset anything as the new owner of the exchange platform we are using.
|
|
|
|
Anthony Bill
Member


Activity: 140
Merit: 22
|
 |
September 21, 2026, 03:09:19 PM |
|
Anything that will make such hacker to succeed show that he or she knows all the details about your password. Without you giving out your password and other details related to your wallets I don't think any scammers can have access to your coins in your wallet and I have never heard such a thing that without you given out your password or your phone or laptop to someone can withdraw all your coins from your wallet.
|
|
|
|
|
|
M47AK16
|
 |
September 21, 2026, 09:50:11 PM |
|
The take away lesson from this is to always have an extra layer of security on both our exchange accounts and our email addresses used in registering those accounts, and also make an occasional password resets. Also, have different passwords for our different accounts online will also help to reduce the password guess on our accounts.
Using 2FA and SMS Verification attached to both our Gmails and exchanges, and Gmail verification codes may sound to be long when all are used at once, but the better the security use for the safety of our different accounts across the internet.
Sometimes a browser can notify us to reset our password as it may be breached. But it is still better to not wait for that, as things may also be too late. When creating account, it helps if the platform has that password suggestion i.e if the password is now hard to guess. Having different password for each account is also true and being recommended by the many but I have not reached that point yet, as I am a person that easily forgets things  . Luckily I have not been hacked yet but this may be because I still follow other safety measures. There are tools that promise to help with our multiple password but isn't it clearly unsafe? Even if we say the company who does this are well-established. A lot trusted companies before still turned shady, or they might get hacked and data's stored there are going to be stolen.
|
|
|
|
|
Ashawowo(OS)
|
 |
September 22, 2026, 09:08:11 AM |
|
2FA can also be set on email. A good email service provider will let you know when anyone want to compromise your email account, it will give you options in a way the person will not be able to.
Some email service providers also give options for 2FA which will be required if you want to login in from a new device.
Nowadays password compromise isn't an automatic access to social media accounts, for Gmail, they would send a notification for you to approve that you're the person accessing the email account. Let's say you even approve by mistake, you can rush to the security settings and remove the new device and the scammer gets logged out immediately. There are still people naive enough not to set 2FA on their devices and they are the major candidates for what OP is describing, so I understand that people still gets exploited, but it is thanks to their stupidity, laziness and carelessness because 2FA is a very popular thing that everyone should prioritize it for their own security. Another good measure is checking your active devices from your email security settings. Some people log into their emails from a cyber cafe PCs to print out an attachment or so and forget to log it out, so in that case, you can still be exploited. If you regularly check your connected devices, you can easily remove the device and stop the potential harm.
|
|
|
|
Charles-Tim
Legendary

Activity: 2408
Merit: 6566
Leading Crypto Sports Betting & Casino Platform
|
 |
September 22, 2026, 06:03:25 PM |
|
Sometimes a browser can notify us to reset our password as it may be breached. But it is still better to not wait for that, as things may also be too late.
Which browser have you used that notified you that your password has been breeched? No browser will do this that I have seen before. When creating account, it helps if the platform has that password suggestion i.e if the password is now hard to guess.
Numbers, upper case, lower case and other characters up to 8 digit is already a strong password on all the sites that I have set password before, but I will advice people to make the password longer than that and it should be a password that is not guessable.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
Justbillywitt
|
 |
September 22, 2026, 08:38:15 PM |
|
They do provide it, but what if it's not compulsory and the user does not activate 2FA?
The exchange will provide the 2fa feature, but it is left for the user to choose to activate it or not. But if a user don’t activate it and anything happens to the account, then such person will blame himself. Although some people do decide not to activate the 2fa because they don’t hold their assets in the exchange, once their business for the day is done at the exchange, they withdraw their funds to their wallet. Don’t think anyone will attack an empty exchange account. I still know some exchanges where 2FA is not required and transaction confirmation is only through email.
Someone who understands the importance of security their assets will avoid such an exchange, because they are not security conscious. I can’t trust such exchange. This is not 2010, an exchange in 2026 that doesn’t have 2fa feature is a joke.
|
|
|
|
shinratensei_
Legendary

Activity: 3962
Merit: 1070
Leading Crypto Sports Betting & Casino Platform
|
 |
September 23, 2026, 01:09:23 AM |
|
[1] They gain access to your email [2] They search which crypto exchanges you are using [3] Hide security emails using inbox rules [4] Reset your exchange password [5] If successful, they gain access to the account
This is old method, today's hacker is creating fake arbitrage bot tutorial and give you harmful code and steal your API key, they either tell you to enable withdrawal through API key or use your account to counter-trade on shitcoin market with low liquidity. This method doesn't seem to be widely known and I believe there are people who have become the victim and it's more subtle than having access to your email which usually triggers device notification about strange activity. API key and email, two most important thing to understand that leaking one of them could get yourself wiped out of your own money, unfortunately most don't even know what API is.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
hafiztalha
|
 |
September 23, 2026, 02:38:46 PM |
|
Reusing password is definitely one way for the attackers to compromise other accounts after the data breaches. But protection of email deserves more attention here. Like if someone gets the email connected to Exchange, they can try or maybe be able to reset password. Using different passwords is good. 2FA provides extra layer of safety but not every 2FA provides same level of security. Having a separate email account reduces the damage if one gets breached but it's not the main security solution. The goal should be to avoid having one compromised account that acts as key for everything else.
|
|
|
|
eaLiTy
Legendary

Activity: 2982
Merit: 1006
Have Fun )@@( Stay Safe
|
 |
September 23, 2026, 08:17:53 PM |
|
~ The first and foremost thing is to use Two-Factor Authentication, which is available almost in every platform these days, we even have it on this forum. Two-Factor will not let an attacker gain access to your account even if they manage to hack into your email and resets the password, because they will still need the Two-Factor code to get in. It actually isn't accurate regarding the 2FA feature on this forum if your email gets hacked. Once you use the forgotten password function, you can easily bypass or remove the 2FA entirely. The security depends completely on how strictly every platform handles that bypass. Some exchanges will let you disable the 2FA once you reset the password, but they will lock your funds for a couple of days as a safety measure. If you use the forgotten-password function, then there's an option to remove the 2FA. So 2FA does not provide any protection in case of a compromised email. Make sure that your email address is secure.
The second thing is to use one email for important stuff such as financial apps and platforms, and you shouldn't use the same email elsewhere. When you have to use other platforms, make sure you create a different email address to use for that, so that even if one of the platforms you are trying to use has evil intentions, they shouldn't be able to find anything connected to that email once they hack into it. You can't just create unlimited email addresses anymore. Services like Google pretty much force you to use a phone number when you're setting up a new account, and honestly, I wouldn't be surprised if they start forcing KYC in the future. Making a brand new address for every single app just isn't a realistic solution. Make sure that you change your password often and enable 2FA for your email account. If you get locked out, you can only recover it using backup codes or through your recovery email address. Taking these steps is a much better option than creating multiple email addresses for every single application.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
Issa56
Legendary
Online
Activity: 2240
Merit: 1080
|
 |
September 23, 2026, 08:51:23 PM |
|
Anything that could cause a security breach of the exchange platform we are using can be made easy through the email address, because that is the most commonly used medium for verifying users' information and also receiving login credentials through it. Only a reckless user will allow their email address to be compromised and hijacked by scammers, as this can give them access to reset anything as the new owner of the exchange platform we are using.
We are suppose to have more than 1 gmail, we should use one to register on random sites, we can make the gmail public, that’s the Gmail which people will know, and we should have the one which we will use in registering on exchanges or other important sites, gmail like this is not suppose to be made public, you shouldn’t even allow anyone to know about the Gmail, and we shouldn’t make use of the same password for the Gmail. When we are making use of any exchange, then we should make sure we activate the 2Fa for additional security. Incase if your Gmail is compromise, and someone has access to it, your 2Fa will stop the scammer from accessing your exchange.
|
|
|
|
Cleanshit
Full Member
 

Activity: 350
Merit: 111
SIG-21828D6CB0
|
 |
September 23, 2026, 09:01:24 PM |
|
[1] They gain access to your email [2] They search which crypto exchanges you are using [3] Hide security emails using inbox rules [4] Reset your exchange password [5] If successful, they gain access to the account
This is old method, today's hacker is creating fake arbitrage bot tutorial and give you harmful code and steal your API key, they either tell you to enable withdrawal through API key or use your account to counter-trade on shitcoin market with low liquidity. This method doesn't seem to be widely known and I believe there are people who have become the victim and it's more subtle than having access to your email which usually triggers device notification about strange activity. API key and email, two most important thing to understand that leaking one of them could get yourself wiped out of your own money, unfortunately most don't even know what API is. The API key point is important Claus many users might not even realize that an exchange API can give a third party access to their account. Fake trading bot can look real, legitimate enough in convince somone to connect without having a proper understanding of what permissions they are giving. That why we should only be force alone on protecting our email and passwords. Checking out of what permission an API key has it important before connecting to any third party tool and disable of any withdrawal permission if not needed. Cause any careless approval can just create another way or things for attackers to reach out to the funds.
|
|
|
|
savetheFORUM
Full Member
 
Online
Activity: 1638
Merit: 142
Bitz.io Best Bitcoin and Crypto Casino
|
 |
September 24, 2026, 02:58:23 PM |
|
Reusing password is definitely one way for the attackers to compromise other accounts after the data breaches. But protection of email deserves more attention here. Like if someone gets the email connected to Exchange, they can try or maybe be able to reset password. Using different passwords is good. 2FA provides extra layer of safety but not every 2FA provides same level of security. Having a separate email account reduces the damage if one gets breached but it's not the main security solution. The goal should be to avoid having one compromised account that acts as key for everything else.
Emails are actually too important these days. Not just our exchanges but even bank accounts can be accessed just with our email. If our email was hacked, the only two options would be to either try regaining access to our email or change email on all accounts. If our email is hacked, we would be locked out of it and that is when we can try securing other accounts or at least making sure that the money in the exchange wallet is safe or locked. Hackers would try all possible ways to get hands on your funds so you need to be one step ahead of them. Knowledge is really important here. We should educate ourselves on how to keep our accounts safe from these digital threats. There are online courses where one can learn to be safe from such threats. We can refer those courses to the ones we know are not technology friendly and might become a blame victim.
|
|
|
|
crwth
Copper Member
Legendary

Activity: 3626
Merit: 1625
|
 |
September 24, 2026, 03:21:37 PM |
|
What a complicated way of attack it's just that you really need to have multifactor authentication just to make sure that even with just a password it wouldn't be enough to get the funds out of an exchange.
Knowledge is really important here. We should educate ourselves on how to keep our accounts safe from these digital threats. There are online courses where one can learn to be safe from such threats. We can refer those courses to the ones we know are not technology friendly and might become a blame victim.
You know that knowledge is okay but application is better. Like having a password manager to make sure that you have different passwords all over the place and it would be hard to really crack it. Maybe a little bit of paranoia could help
|
|
|
|
|