A hacker leaks 10K+ API keys belonging to users of crypto trading service 3Commas, which had said its users were “phished”; 3Commas CEO confirms the leaked data
3Commas’ confirmation changes the account from user-targeted phishing to a compromise involving credentials used by its customers. Follow-up coverage broadened the alleged scope and reported an FBI investigation into the 3Commas key leak, while a victim group attributed more than $20M in losses to the incident.
The episode sits alongside crypto-sector exposure through service providers: a HubSpot breach that triggered notifications at several crypto firms and a later Kroll employee SIM swap affecting creditor data show how intermediary access can become a concentrated security risk.
First-order effects
3Commas users whose API keys were exposed face an immediate need to replace credentials, while 3Commas must address the gap between its earlier phishing explanation and the CEO’s confirmation of leaked data.
The confirmed leak gives affected customers and investigators a concrete incident to assess, rather than treating the losses solely as individual phishing cases.
Second-order effects
The reported FBI probe and victims’ loss claims raise the operational and reputational stakes for 3Commas beyond customer support, putting its handling of API credentials under closer scrutiny.
Crypto firms that connect customers through external marketing, claims, or trading-service providers have another reason to review how a supplier’s account compromise can expose their users.
Third-order effects
Repeated breaches involving trading tools and crypto-industry vendors point to access control at intermediaries becoming a defining trust boundary, rather than a back-office security detail.
If this pattern persists, platforms that hold or route customer credentials will compete more on demonstrable credential isolation and incident response, alongside their trading features.
The trend: Crypto’s security risk is increasingly concentrated in the third-party services that hold customer access and connect users to platforms.
1. Statement from 3Commas: We saw the hacker's message and can confirm that the data in the files is true. As an immediate action, we have asked that Binance, Kucoin, and other supported exchanges revoke all the keys that were connected to 3Commas.
I am reasonably sure there are wide spread API key leaks from 3Commas. If you have ever put an API key in 3Commas (from any exchange), please disable it immediately. Stay #SAFU.
3Commas Statement: 1) We have seen the hacker's message and can confirm that the data in the files is true. As an immediate action, we have requested that Binance, Kucoin and other supported exchanges revoke all keys that were connected to 3Commas. https://twitter.com/...
1/ Six hours ago an account messaged me and sent over a db with api keys of 3Commas users. I began working to verify its validity and quickly shared the info with exchanges. https://twitter.com/... https://twitter.com/...
2/ I won't spread the db as some of the keys are potentially still active but here is what the account had to say about the leak in a post: Unfortunately it seems they will be publishing the full database of 3Commas users soon. https://twitter.com/...
4/ 3Commas finally acknowledged the leak but the damage had already been done. For weeks they have been blaming its users and accepting zero responsibility. Make sure to never give incompetent clowns like @3commas_io your business ever again. https://twitter.com/... https://twitt…
@YS_3Commas You kept lying and saying this was our fault instead of taking responsibility and prevented further exploits. Are you going to refund the users now?
@YS_3Commas But didn't you gaslight everyone into thinking that it was their fault for getting “phished?” Where's the apology for people who pulled all their hair out and went bald because they thought it was their fault
On December 26th 3commas stuff (or those to whom they've sold my keys) used my account to buy pumped coin and I've lost about 3/4 of my funds on Binance. How this situation will be solved? @cz_binance @cz_binance @3commas_io https://twitter.com/... https://twitter.com/...
My strong recommendation for all @3commas_io leak victims is to hire the lawyer ASAP Link to leakage below https://pastebin.com/... Best documented lawsuits would win and you will have a chance for compensation
To be safe, if you used @3commas_io with any exchange, you need to go to that exchange and delete the specific API keys. We proactively did this for @krakenfx clients 2 weeks ago. Just disabling @3commas account or removing your API keys there won't protect you. https://twitter.c…
An anonymous Twitter user has leaked what they say are over 10,000 Binance and KuCoin API keys connected to the trading app 3Commas. By @skesslr https://www.coindesk.com/...
Our agile risk team raised a red flag on the #3Commas API key leak and swiftly devised safety measures urging our users to regenerate their keys to minimize counterparty risk. For #OKX, risk management and consumer protection are our priorities. https://twitter.com/...
Literal weeks of “there was no hack, no leak, it's all FUD” Now caught with their pants down doing damage control after someone leaks the data Absolutely pathetic To the streets https://twitter.com/...
Lmao 3commas sent an email to users saying “update your API keys”, no mention of the massive hack they had leaking tens of thousands of user APIs, After weeks of blaming others for their blatant failure. This company is a joke and if you keep using it after today it's on you. htt…
PSA: We understand the importance of security and the need to protect your assets. Exposing your API keys equals exposing your passwords. Here's what #OKX has been doing regarding the situation with @3commas_io: https://twitter.com/...
Unfortunately: 1) Anyone that ever built anything fast built it insecure AF 2) Anyone with any assets is a target for expert criminal hackers 3) Almost every platform will eventually expose your data to an unauthorized 3rd party 4) VC seldom invest in security, it's boring https:…
2. We did everything that we could to investigate an inside job, as it was always a possible scenario and on our watch list, but proof of an inside job was not found.
Hey @3commas_io, you should edit your bio and add ‘...providing traders AND hackers with ultimate control...’ Better start to put money aside to refund all victims. You gaslighted your users into thinking they got phished but it was all your fault. Clowns. https://twitter.com/...…
This 3commas leak is insane - and proves that the 3commas team themselves stole the funds. It seems like a small group of people are taking action against all the bad actors in this space. Pastebin with all the info: https://pastebin.com/...
“there's no api leak!”, then 8 hours later after the data is dumped online they're like “oops yeah there was a leak” lol too funny.. Sharing this incase anyone ever used this service. Stay safe out there! https://twitter.com/... https://twitter.com/...