Binance CEO Changpeng Zhao (CZ) warned his 8 million Twitter followers on Dec. 28 that he is “reasonably sure” that API key leaks are taking place at the cryptocurrency trade management platform.
I am reasonably sure there are wide spread API key leaks from 3Commas. If you have ever put an API key in 3Commas (from any exchange), please disable it immediately.Stay #SAFU.
The disclosure by CZ followed an incident on Dec. 9, when Binance cancelled the account of a user who complained about losing funds a day earlier. That user claimed a leaked API key tied to 3Commas was used “to make trades on low cap coins to push up the price to make profit.” Binance declined to reimburse the user. CZ tweeted that the loss was unverifiable, and if the company made up for such losses “we will just be paying for users to lose their API keys.”
Mamba, there is almost no way for us to be sure users didn’t steal their own API keys. The trades were done using API keys you created. Otherwise we will just be paying for users to lose their API keys. Hope you understand.
On Dec. 11, 3Commas CEO Yuriy Sorokin claimed on the company blog that fake screenshots were circulating on Twitter and YouTube to show the company had lax security and that employees were stealing API keys. Sorokin denied the allegations in an in-depth technical analysis of the fakes:
Security issues first arose at 3Commas in late October. At that time, the still-functional FTX exchange issued a security alert in response to reports from users of unauthorized trades of trading pairs with the DMG coin on FTX. 3Commas and FTX determined that hackers had created 3Commas accounts to perform the trades. However, according to the 3Commas blog, “the API keys were not taken from 3Commas but
Read more on cointelegraph.com