Singapore Police warn of crypto thefts via compromised emails
Authorities report a rise in hackers using email access to bypass security on cryptocurrency exchanges and wallets.
The Singapore Police Force (SPF) has issued a public warning following a rise in unauthorized access to cryptocurrency accounts. The trend involves attackers first compromising a victim's email account to gain control over linked digital asset platforms.
According to the SPF, the warning was issued on Saturday, September 12, after an increase in these cases was observed starting in mid-August. Once attackers gain entry to a user's email, they can utilize password reset functions or bypass security protocols to enter linked cryptocurrency exchanges and wallets, allowing them to steal funds.
The Single Point of Failure
This attack vector highlights a critical vulnerability in digital security where the email account acts as a single point of failure. Because most financial and digital services use email as the primary channel for identity verification and account recovery, controlling the inbox effectively grants the attacker the ability to "own" any linked account. By intercepting password reset links or security notifications, hackers can lock out the legitimate owner and drain assets without needing the original account password.
Industry Implications
This trend underscores the growing financial risk as cryptocurrency adoption increases. The ability to bypass complex exchange security by targeting a simpler email account demonstrates that the weakest link in the security chain is often not the high-security wallet, but the communication tool used to manage it. It emphasizes the urgent necessity for users to implement multi-factor authentication (MFA) that does not rely solely on email—such as hardware keys or authenticator apps—to prevent a single compromise from leading to total financial loss.
What to Watch
While the SPF has alerted the public to the trend, the full scale of the financial losses associated with this mid-August surge remains unconfirmed. Users are encouraged to audit their security settings and ensure that their primary email accounts are protected by robust, non-email-based MFA. Security experts continue to monitor whether these attacks are part of a wider coordinated campaign or a result of opportunistic exploitation of leaked credentials.