SINGAPORE — Cryptocurrency holders have been warned to look beyond their digital wallets when securing their assets, after Singapore police detected an increase in cases where criminals apparently gained access to crypto accounts by first compromising the victims’ email.
The Singapore Police Force said on September 12 that it had observed an increase in unauthorised access to cryptocurrency accounts since mid-August. Investigators discovered that several email accounts linked to the affected crypto accounts had previously surfaced in data breaches involving other platforms, suggesting that login credentials may already have been exposed.
The warning highlights a security weakness that can easily be overlooked: even a well-protected cryptocurrency account may be vulnerable if the email address connected to it has already fallen into the wrong hands.
How a compromised inbox can become a gateway to crypto
According to police, perpetrators may take advantage of credentials leaked in earlier data breaches, particularly when victims reuse the same passwords across multiple websites and services.
Once criminals enter an email account, they can search the inbox for messages revealing which cryptocurrency exchanges or platforms the victim uses. They may then attempt password resets on those accounts and intercept reset links, verification messages or one-time passwords delivered by email.
But gaining access is only part of the danger.
Attackers can also create email rules designed to automatically archive, forward or delete messages from cryptocurrency companies. That means warnings about password changes, logins or transactions could potentially disappear from the victim’s normal inbox before they notice anything unusual.
The technique could give criminals more time to manipulate an account while reducing the chance that the legitimate owner immediately sees security alerts.
Password reuse makes the problem worse
One of the key risks highlighted by authorities is password reuse.
If an email address and password combination exposed in one unrelated data breach is reused for a cryptocurrency platform, criminals can try the same credentials against other services. This method, commonly associated with credential-stuffing attacks, can turn an old breach involving one platform into a threat to several unrelated accounts.
Police are therefore advising users to create strong, unique passwords for every online account rather than relying on a single password across email, financial services and cryptocurrency platforms.
Multi-factor authentication or two-factor authentication should also be enabled wherever possible. Singapore police specifically recommend using an authenticator application where available rather than relying solely on SMS-based verification, which can face additional interception risks.
Check the settings criminals hope you never look at
Changing a password may not be enough after an email compromise.
Users should examine their email security settings for unfamiliar forwarding addresses, suspicious inbox rules, unexpected recovery methods and devices they do not recognise. Login histories should also be reviewed for access from unfamiliar devices or locations.
Crypto holders should separately inspect their exchange or wallet activity, enable transaction and login notifications where available, and respond immediately to warnings that their credentials may have appeared in a data breach.
Anyone who believes an email or cryptocurrency account has already been compromised should contact the relevant email provider and cryptocurrency exchange immediately to secure or freeze the affected account where possible. Passwords should also be changed on any other service where the same credentials were reused.
Warning comes amid wider crypto-related scam threat
The latest alert comes against the backdrop of several separate cryptocurrency-related crime warnings in Singapore this year.
In August, police warned of a scam involving criminals impersonating Apple support personnel. Since August 7, at least five cases had been reported, involving losses of at least S$195,000. Victims were directed to fraudulent websites and asked for sensitive information including Apple credentials, cryptocurrency credentials and one-time passwords.
Another joint advisory issued by the Singapore Police Force and the Cyber Security Agency of Singapore on August 14 described a different scheme involving fake cryptocurrency-related job offers and malicious software. Authorities said that operation had resulted in losses of US$11.8 million, or about S$15 million.
Separately, Singapore police said on September 3 that a joint operation with digital-payment-token service providers identified more than 355 potential scam victims and prevented over S$8.94 million in potential losses between July 1 and August 31. The exercise involved blockchain analysis and cooperation with exchanges including Coinbase, Coinhako, Gemini, OKX and others.
Those figures relate to separate operations and scam variants and should not be interpreted as losses from the newly reported compromised-email cases. The September 12 warning, as reported by AsiaOne, CNA and The Star, did not disclose a total number of victims or financial losses linked specifically to the latest trend.
The bigger lesson: your email may be part of your crypto security
For cryptocurrency users, the latest warning changes the way account security needs to be viewed.
Protecting the exchange login alone is not enough when an email account can contain password-reset links, authentication messages, transaction notifications and clues about where digital assets are held.
An old password leaked years ago can remain dangerous if it is still being reused today.
And an attacker who quietly gains control of an inbox may not need to break through the front door of a cryptocurrency account at all — because the email account could give them another way in.
Singapore residents who suspect scam activity can contact the 24-hour ScamShield Helpline at 1799. Information relating to such crimes can also be reported to police through the Police Hotline at 1800-255-0000 or the police i-Witness platform.

Leave a Reply