FTX plans to offer $6M to account holders impacted by a phishing incident via a third-party site, but says this kind of relief will not become the norm
Digital-asset exchange FTX will provide about $6 million compensation to its account holders impacted by a phishing incident via a third-party website.
BloombergSunil Jagtiani
Context & Ripple Effects
FTX initially framed the phishing payout as a limited exception rather than a standing customer-protection policy. Weeks later, the exchange paused withdrawals after a rapid run on the platform, turning the distinction between discretionary relief and customer claims into a far larger issue.
Subsequent coverage describes recovery efforts after FTX's collapse, including identified liquid assets and unauthorized transfers and a bankruptcy finding that customer deposits had been commingled and misused.
First-order effects
Affected FTX account holders are slated to receive roughly $6 million for losses tied to the third-party phishing site.
FTX establishes that comparable phishing losses will not automatically qualify for compensation, limiting its immediate reimbursement exposure.
Second-order effects
Users facing future third-party-site scams have a clearer incentive to treat account security and site verification as their own risk, since FTX has rejected an ongoing relief precedent.
FTX's decision draws a line between a one-off customer-service payment and liabilities it will recognize, a boundary that became consequential once withdrawals were paused and customer funds were at issue.
Third-order effects
The later collapse shows how quickly isolated operational-loss decisions can be overtaken by a platform-wide creditor process when customer assets and internal controls fail.
For custodial exchanges, trust increasingly rests not only on reimbursement promises but on whether controls and records can support customer claims during a crisis.
The trend: Crypto platforms are moving from ad hoc customer-loss remediation toward sharper scrutiny of custody controls, liability boundaries, and recoverability of customer funds.
14) But this once, we'll do it; roughly $6m total. (To be clear, only for FTX accounts! Hopefully other exchanges will comp theirs.) BUT AGAIN NOT A PRECEDENT, WE WILL NOT GOING FORWARD.
13) But in this particular case, we will compensate the affected users. THIS IS A ONE-TIME THING AND WE WILL NOT DO THIS GOING FORWARD. THIS IS NOT A PRECEDENT. We will not making a habit of compensating for uses getting phished by fake versions of other companies!
WuBlockchain learned that there have been four incidents of coin theft by stealing API KEYs and contra trading in FTX. Three of the cases were related to 3Commas, which 3Commas said was because users landed on fake websites. https://twitter.com/... https://twitter.com/...
Yes. 1. Remove password. Even 2fa is not enough and can be gamed (social engineering of mobile operators) 2. Take down impersonators site. (Tools to expedite this) 3. Union to fight phishing of 3rd party sites (create a working reporting group with all top players) https://twitte…
SBF is taking their loss basically, and this is not even remotely his or FTX fault, literally. (neither 3commas fault, but wtvr). Phising can be vicious.but it's the user's fault only. Nice one Sam. https://twitter.com/...
8) Anyway, recently a frustrating thing happened. We've mostly stamped out sites that try to phish users by masquerading as FTX. But we can't fix fake sites impersonating *other* services. A few users accidentally registered at fake other sites, including 3 Commas.
The FTX API exploit story is getting crazier. Apparently this exploit has been going on since the 18th and no one noticed millions of dollars were being stolen? According to @cz_binance something similar happened once at @binance & they recovered the funds for the users 1/2
5) We have a huge number of controls in place to attempt to prevent fake FTX sites from being able to drain users' accounts. And generally they work: it was a lot of work but it's mostly successful.
3) Usually, phishing looks like an email, and it has a bad attachment, or something. In crypto, the scams have gotten sophisticated. For instance—we have a team of people who work to make sure fake FTX clones don't gain prominence.
Meanwhile @FTX_Official is pretending this didn't happen and according to those affected... not helping or trying to recover the funds at all. This is all very bad. Hopefully @FTX_Official will be like @cz_binance and do the tight thing here for their customers.
A summry of 4 victims. All contra trades happened between October 18th to October 21st on FTX compromised account of victims in low liquidity pairs: DMG/USD MER/USD PORT/USD. FTX and 3commas has been alerted of this incident, but they didn't prevent the ongoing hack to happen. ht…
6) To be clear, phishing is almost always a case where the user voluntarily (but unknowingly) gives their account credentials to a scammer by going to a bad site or something like that—but despite that, we take our duty to protect customers seriously, even from themselves.
10) In general, there's very little we can do about this: other sites can fail to squash phishing attempts on them, and users can ask to let those sites control their FTX API keys. (This happened to accounts on other exchanges 3C was connected to as well, e.g. Binance.)
4) Why fake websites? Well, generally, a phishing scam will copy someone's website, but intercept the username/password/etc.—so now they control the login, and can try to drain the user's account.