Singapore police are warning cryptocurrency users about a growing form of account takeover in which criminals first gain access to a victim’s email account and then use it to break into linked cryptocurrency accounts.
The Singapore Police Force said on Sept. 12 that it had observed an increase in such cases since mid-August. Investigators found that several affected email accounts had previously appeared in data breaches involving other online platforms, suggesting that victims’ login credentials may already have been exposed.
The problem can become particularly serious when people reuse the same password across different services. Criminals who obtain leaked credentials may try those same details on cryptocurrency exchanges or other financial platforms, potentially gaining access without needing to break through the exchange itself.
How hackers can take over a crypto account
Once criminals gain access to an email inbox, they can search through messages to identify which cryptocurrency exchanges or platforms the victim uses.
They may then create inbox rules that automatically archive, forward or delete emails from those platforms. This can hide security alerts and password-reset messages from the account owner while the attackers continue operating in the background.
Criminals can also trigger password-reset requests for cryptocurrency accounts and intercept the reset links, one-time passwords or verification emails sent to the compromised inbox.
If the victim has reused the same password for their email and cryptocurrency account, attackers may be able to use credentials exposed in an earlier data breach to directly access the crypto account.
Police urge users to strengthen email security
The police are advising cryptocurrency users to use strong, unique passwords for every online account rather than relying on the same password across multiple services.
Users should also enable multi-factor authentication or two-factor authentication wherever possible. An authenticator app can provide an additional layer of protection beyond passwords.
Email security settings should also be checked regularly. Users should look for unfamiliar login activity, unauthorised forwarding settings and inbox rules they did not create.
Anyone alerted by a service provider that their credentials may have appeared in a data breach should change the affected password immediately and make sure 2FA or MFA is activated.
Crypto users should watch for unusual activity
The police also recommend enabling notifications for cryptocurrency account activity and regularly checking transactions.
If users suspect that their email or cryptocurrency account has been compromised, they should contact the relevant service provider immediately to secure or freeze the account and report the incident to the police.
The warning comes amid a wider increase in cryptocurrency-related cybercrime. In a separate August advisory, Singapore police and the Cyber Security Agency warned of a crypto scam involving fake job offers and malicious software that caused about US$11.8 million (S$15 million) in reported losses.
Police have also previously warned about scams impersonating technology companies in which victims are tricked into handing over account credentials and authentication codes, allowing criminals to transfer cryptocurrency out of their accounts.
The latest advisory highlights a crucial weakness that users can overlook: protecting a cryptocurrency account is not enough if the email account linked to it is left vulnerable. Once criminals control the inbox, they may be able to intercept the very security measures designed to protect the digital assets.

Leave a Reply