A pop-up window, a call, and the wallet empties. The Singapore Police Force has issued a public alert regarding a scam impersonating Apple to siphon cryptocurrencies. At least five victims have been reported, with over 195,000 Singapore dollars going up in smoke (nearly 130,000 euros), and a modus operandi that requires no technical prowess: a well-placed notification, a reassuring voice on the phone, a six-digit code extracted at the right moment.
The Singapore police statement cites two domain names used by the scammers, << chat-apple.com >> and << case-apple.com >>, as well as a recurring phone code: << +1 >>, that of North America.
It all starts with an unexpected alert on the victim's Apple device: unauthorized access attempts have targeted their account, and they need to change their Apple ID password without delay. Moments later, the phone rings. On the line, a supposed technician from Apple support confirms the bad news and takes control of the conversation.
The victim is then directed to one of the fake support sites, where they are asked for their Apple credentials, those of their crypto account, and then the famous OTPs (One-Time Passwords, these one-time codes meant to validate each sensitive operation). With this complete keychain, the scammers log into the linked trading accounts or wallets and transfer the funds in a matter of minutes. Most victims only realized what had happened when they discovered the history of outgoing transactions.
The detail of the << +1 >> code is not trivial. In Singapore, all incoming calls from abroad are marked by a << + >> displayed before the number, a measure imposed on operators specifically to defuse this type of impersonation. A safeguard that weighs little when the screen has just displayed a security alert and the interlocutor speaks the language of technical support.
<< Apple will never ask you to provide your Apple ID password, your one-time codes, or any other login identifiers via unsolicited phone calls, pop-up windows, or links. Never disclose this information to anyone. >>
Public Affairs Department, Singapore Police Force -- Source
No line of blockchain code was forced in this case. The attackers target the layer before: the user account and its owner. A compromised Apple ID opens access to the iCloud keychain, synchronized notes, and the photo library. This is exactly where many investors, for convenience, store a screenshot of their seed phrase or a note containing their twelve words. Once the Apple ID falls, the wallet follows without resistance.
The OTP layer remains the last lock before withdrawal. It does not yield to a cyber attack, but rather to a well-conducted phone conversation: the victim themselves dictates the code that authorizes the transfer. And unlike credit card fraud, no chargeback procedure will rectify the mistake. A confirmed on-chain transfer is final, making these accounts a far more lucrative target than a checking account.
Singapore is not new to alerts. The city-state recorded over 51,000 cases of fraud in the year 2024 alone, with approximately 1.1 billion Singapore dollars stolen, a record. The Parliament responded with the Protection from Scams Act, which allows the police to temporarily freeze the banking operations of a person deemed to be under duress. This is an effective tool against a bank transfer, but significantly less so against a crypto withdrawal executed from a platform located on the other side of the world.
The Singaporean police outline their recommendations in three steps, summarized by the acronym ACT:
A few additional adjustments close the door even earlier. Replacing SMS OTP with a passkey or a physical security key removes the very object of the scammers' call, as there is no longer a code to dictate. Activating the withdrawal address whitelist on your exchange, with a 24 to 48-hour grace period applied after any addition or connection from a new device, allows time to react. And a seed phrase has no place in the cloud, a note, or a photo: its place remains an offline medium, ideally a hardware wallet.
A single point of reference is often enough to stop everything: Apple support only exists on apple.com and support.apple.com, and they never call first to request an identifier. << chat-apple.com >> and << case-apple.com >> have never belonged to the Cupertino firm. In case of doubt, the ScamShield line 1799 is available 24/7, and the portal scamshield.gov.sg lists the circulating variants.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

![[SCAN 2026 Final Interview] ⑬ BITSkrieg: Indian Engineering Students' Challenge for SCAN2026 Victory](/public-static/40_d9655504cd.png?format=avif)



























