Recently my email attached to this site was hacked. I am using this email only for this site. Today someone tried to hack my Paypal account too attached to this email. I am not sure how it happened i am not blaming anyone but guys be careful.
sorry to hear but:
"I am using this email only for this site"
"my Paypal account too attached to this email"
... doesn't add up.
Anyway, I hope in the future Numista provides an MFA option. It's 2020, there are loads of leaked username/password sets around and people tend to reuse same passwords across different websites. While it is a good practice to use a different password everywhere, it is also a service responsibility to keep user accounts and data secure. Or just offload it to someone who has invested a lot into it - give an option for federated logins with Google, Facebook, etc