|
adultcrypto
|
 |
September 24, 2026, 05:02:17 PM |
|
Where the user set 2FA, it wil require resetting that before being able to access the exchange account and the process may signal the owner of the account through notification. I don't know if the post detailed how to also boycott this in the hacking process. Protecting the email is very important as a lot can be compromised if the email is accessed.
|
|
|
|
Hamza2424
Legendary

Activity: 1778
Merit: 1163
|
 |
September 24, 2026, 06:58:47 PM |
|
If you lose your email you lose everything, because losing your email means losing access to all Google's services like Drive where people are still holding their seed phrases. No matter how many times they read it is not secure, they will still store their seed phrases there, they will still write their portfolio information in spreadsheets because they have to, and that information can be seen by hackers if they have your email. In short, it is the master key so secure it at all costs. Always check and read every policy, make sure every security feature is turned on in your email.
Email forwarding settings are very crucial bro, thanks for mentioning them because it's been a long time since I checked anything like this, but the best practice is to use a completely separate email just for exchanges, and if it is possible to manage multiple emails, then don't use the same email for all the exchanges.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
goldkingcoiner
Legendary

Activity: 2912
Merit: 3129
HoDL
|
 |
September 24, 2026, 07:06:04 PM |
|
As traders, we usually focus on securing our crypto exchange accounts and making sure they will not be hacked, but sometimes the problem is not there, it's actually the email address we are using. So I read this warning from Singapore Police where attackers first gain access to their victim's email account, and once inside they can easily search the inbox and find out what crypto exchanges you are using. And because they are smart, they can create email rules to hide security notifications, then request a password reset from the exchange and intercept the reset link or verification email without the user noticing it. So here's the usual format of the attack: Your old or reused password gets leaked. [1] They gain access to your email [2] They search which crypto exchanges you are using [3] Hide security emails using inbox rules [4] Reset your exchange password [5] If successful, they gain access to the account So even if the exchange has good security, if our email is not properly secured, there is only so much the exchange can do to protect us. For me, using a different password for your email and exchange is really a must, and if there is 2FA available we should activate it. Based on the report, we should also check our email forwarding settings, inbox rules and active sessions from time to time because unusual changes there can be a sign that someone already gained access to our email. With this incident it tells us that securing the exchange account alone is not enough, because the email connected to it can also become the easiest way for an attacker to get inside. As long as you have 2FA authentication on your cryptoexchange account, simply gaining access to their E-Mail will not be enough to withdraw their coins. But then again, anybody who is clumsy enough to get their account info and passwords leaked is probably also clumsy enough to simply not have 2FA authentication set up in the first place. Although many exchanges kind of force it nowadays...
|
|
|
|
|
Z_MBFM
|
 |
September 24, 2026, 07:11:30 PM |
|
As far as I know, hackers hack emails through browser cookies. There is a lot of data available for purchase in the black market, which many people buy for business purposes, from there they get login access data for various platforms including emails, they are third parties, while actual hackers directly hack people's browser cookies through various phishing links through various means and from there they get access to various things. Exchangers without 2FA should be avoided, and many times accounts are hacked despite 2FA being set, this is because the email that the hackers hack has a 2FA backup in the same email. Google Authenticator now keeps 2FA codes as a backup in Gmail, in that case, if they get access to the email, they are automatically available. If the email of the Exchange account and the email of the 2FA backup are the same. You have to be careful in all aspects if you want to stay safe from hackers.
|
|
|
|
Crypto Library
Legendary

Activity: 1722
Merit: 1234
Leading Crypto Sports Betting & Casino Platform
|
 |
September 24, 2026, 08:30:04 PM |
|
As far as I know, hackers hack emails through browser cookies. There is a lot of data available for purchase in the black market, which many people buy for business purposes, from there they get login access data for various platforms including emails, they are third parties, while actual hackers directly hack people's browser cookies through various phishing links through various means and from there they get access to various things. Exchangers without 2FA should be avoided, and many times accounts are hacked despite 2FA being set, this is because the email that the hackers hack has a 2FA backup in the same email. Google Authenticator now keeps 2FA codes as a backup in Gmail, in that case, if they get access to the email, they are automatically available. If the email of the Exchange account and the email of the 2FA backup are the same. You have to be careful in all aspects if you want to stay safe from hackers.
I don't actually know if it is possible to steal email and password by hijacking browser cookies because as far as I know there is a browser session where there is no email or password. Here I think they try to hack websites and collect the email and password that is signed up on them. And then they try to do the brute force with the same email and the password on the others platform including the exchanges. I think the only way to avoid these situations is to use 2-factor authentication and at the same time check various websites where we can see if our email has already been exposed. If it is positive, then we should definitely change the email password. Like you can see, one of my email was exposed with the password- 
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
Dareo
|
 |
September 25, 2026, 06:54:13 AM |
|
Where the user set 2FA, it wil require resetting that before being able to access the exchange account and the process may signal the owner of the account through notification. I don't know if the post detailed how to also boycott this in the hacking process. Protecting the email is very important as a lot can be compromised if the email is accessed.
That's why I think offline devices should be used for two factor authentication. The reason for this is that since no internet is required to use the authenticator, if an authenticator is used on an offline device, then there is almost 0% chance of being hacked. But yes, browser cookies can be stolen, as someone already said above. And this is a very important point. Because if you have your exchange account login in your browser and from there, if your session cookie is stolen due to some malware, then your 2FA security will not be of any use. Then he will be able to access your account without any login. And for this reason, I think the most important thing is that the user must be careful before installing any third party software or crack games.
|
|
|
|
Leahized
Sr. Member
  

Activity: 868
Merit: 257
Bitz.io Best Bitcoin and Crypto Casino
|
 |
September 25, 2026, 03:50:50 PM |
|
Where the user set 2FA, it wil require resetting that before being able to access the exchange account and the process may signal the owner of the account through notification. I don't know if the post detailed how to also boycott this in the hacking process. Protecting the email is very important as a lot can be compromised if the email is accessed.
From my experience, I can say that 2FA can be bypassed when logging into an exchange. Once, despite having funds held in Bitget, I accidentally removed 2FA access from the authenticator. This put me in the most difficult moment. I had to change the 2FA to get the exchange access and was able to do so. Because, with the aim of strengthening security, "Email, Number, 2FA were linked". Which can be used interchangeably for login. And the funny thing is, no code was needed to reset the that. I believe that, by being cautious hackers will not gain access to the email. Any phishing link or suspicious website should be avoided. This will significantly reduce the risk. If unfortunately, hackers gain access to the email, then there is no need to change the exchange password. Because, we save all passwords on Google and which can be easily seen.
|
|
|
|
|
vs2014
|
 |
September 27, 2026, 06:46:04 PM |
|
It's important for a trader to know how to protect assets and secure account alongside trading. There are some traders who mainly focus too much on exchange account but their forget that email account also connected with exchange account. So people have to ensure email security and it's better to use 2FA along with password for both email and exchange account. Besides if we can separate our email then the possiblity of email hacking may reduced while other gets compromised. Sometimes a small mistakes turn into big one, so taking step asap is better instead of dealing with loss later.
|
|
|
|
|
Barcode_
|
 |
September 27, 2026, 07:08:32 PM |
|
It is always good to use a password that is very complex including letters, numbers and symbols if any traders are intending to keep a large amount of their investment including cash and crypto currencies on their trading account.
If a hacker does truly manage to access a victim email and try to execute a 'forget password action' in order to change the password to make it possible for logging into the victim trading account. I think usually all major reputable crypto currencies exchanges websites will have some sort of automated defensive mechanism in their system which will be activated.
The system will detect a change of IP address which differs from the victim usual log in IP address and usually some sort of confirmation will be needed for a 2FA verification which usually requires the victim phone, whether it is a token verification app or a simple 2fa SMS message. Maybe the victim might realize his trading account is in the process of being hack when they receive some notification on their phone app or via the SMS sent to their phone, and they could try to salvage the situation immediately by contacting a customer service agent to freeze all of their assets in their account with the proper authorization.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | ..BTC......XMR... ..USDT.....LTC... ....Fees 0.8%..... |
|
|
|
|
Joy- maker
|
 |
September 27, 2026, 08:43:52 PM Last edit: September 27, 2026, 09:04:28 PM by Joy- maker |
|
It is funny how crypto traders focus only on securing their trading exchanges and then leave the main thing scammers can use to gain access to those trading exchanges unsecured. If a scammer successfully gain access to your Gmail account their is every chance they can gain control of your trading exchanges by simply doing what OP just stated. In my country, one method scammers to gain access to your Gmail account is by swapping your phone number onto another SIM card, then proceed to take control of your exchange, simply by resetting your exchange password since they already have access to your email address to receive the OTP.
|
|
|
|
|
tbterryboy
|
 |
September 28, 2026, 09:01:24 PM |
|
I will say it was a threat a decade back when 2FA was not into picture. We have a number of additional securities now which includes phone verifications, 2FA, facial verifications, etc which can still keep the funds safe even if we lose access to the exchange. Also, most exchanges have integrated a feature where they might detect an unusual IP and restrict account features for a few hours. Most traders would definitely notice this and secure their accounts.
The only solution for this would be to not simply trust email when it comes to security but add another 2FA verification just to be safe. There are a number of ways where we can lose our money. We can only stay cautious and practice best habits to keep our money safe.
|
|
|
|
|
Issa56
Legendary

Activity: 2240
Merit: 1081
|
 |
September 28, 2026, 10:50:04 PM |
|
If you lose your email you lose everything, because losing your email means losing access to all Google's services like Drive where people are still holding their seed phrases. No matter how many times they read it is not secure, they will still store their seed phrases there, they will still write their portfolio information in spreadsheets because they have to, and that information can be seen by hackers if they have your email.
You should properly protect your email, because when someone hacks into our email, then they might have access to some sensitive informations which they are not suppose to have access to, so gmail is suppose to be properly protected. If anyone investing in bitcoin are still leaving their seed phrase on gmail or drives, then they are not really serious. It’s always been warned that we are not suppose to leave our seed phrase in anywhere there is internet connection, but some people still decide to do whatsoever every they want. Your Gmail can be compromised at any moment, so if sensitive informations are there, then hackers will be able to take it easily. It’s easy to store your seed phrase online, but we should know it’s not safe, so since we know it’s not proper, then we should avoid it.
|
|
|
|
otterninja
Newbie
Online
Activity: 4
Merit: 0
|
 |
Today at 01:35:06 AM |
|
Long-time lurker, first reply. The part most people miss is sample size — a few good weeks proves nothing. I keep a journal of every trade with the reasoning attached, and looking back, my biggest losses all came from breaking my own rules, not from bad analysis. That's my two sats anyway.
|
|
|
|
|
|