/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Sources: the FBI is investigating the leak of ~100K API keys linked to users of crypto trading service 3Commas, as a victims group claims to have lost over $20M

This week, an anonymous person leaked 100,000 API keys connected to the crypto trading service.

CoinDesk Sam Kessler

Context & Ripple Effects

3Commas first attributed the incident to user phishing before its CEO confirmed the credential leak, a reversal captured in the earlier confirmation that leaked keys were genuine. The FBI inquiry elevates the episode from a platform-security dispute to a law-enforcement matter while a victims group attributes more than $20 million in losses to it.

The case also follows a prior crypto-exchange breach in which Binance said attackers obtained user API keys and 2FA codes, showing why exposed trading credentials carry consequences beyond the service that stores or manages them.

First-order effects

  • 3Commas users whose keys were exposed face the immediate need to revoke or replace trading access, while the victims group’s claimed losses become part of the factual record under FBI scrutiny.
  • 3Commas must answer for the gap between its initial phishing explanation and the subsequently confirmed leak as the investigation examines the incident.

Second-order effects

  • Crypto trading services that rely on API-based account access face renewed pressure to demonstrate that customer credentials are protected and that incident disclosures are reliable.
  • The episode reinforces the relevance of Binance’s earlier API-key and 2FA breach, making credential security a trust issue across services connected to customer trading accounts.

Third-order effects

  • If repeated credential breaches draw law-enforcement attention, crypto intermediaries’ security controls and disclosure practices become a larger part of the sector’s legitimacy test rather than a back-office concern.
  • The recurring exposure of account-access credentials points toward competition based not only on trading tools but also on the safeguards governing delegated access to customer assets.

The trend: Crypto trading platforms are being judged increasingly on whether their API-access security and breach disclosures can sustain trust in a market already marked by major account compromises.

Discussion

  • @wublockchain Wu Blockchain on x
    The U.S. FBI is investigating the 3Commas data breach, 100,000 Binance and KuCoin API keys linked to 3Commas were leaked by an anonymous person. Initially, 3Commas said that users were most likely phished and insisted that the platform was safe. CoinDesk https://www.coindesk.com/…
  • @ys_3commas Yuriy Sorokin on x
    1. Statement from 3Commas: We saw the hacker's message and can confirm that the data in the files is true. As an immediate action, we have asked that Binance, Kucoin, and other supported exchanges revoke all the keys that were connected to 3Commas.
  • @3commas_io @3commas_io on x
    3Commas Statement: 1) We have seen the hacker's message and can confirm that the data in the files is true. As an immediate action, we have requested that Binance, Kucoin and other supported exchanges revoke all keys that were connected to 3Commas. https://twitter.com/...
  • @zachxbt @zachxbt on x
    1/ Six hours ago an account messaged me and sent over a db with api keys of 3Commas users. I began working to verify its validity and quickly shared the info with exchanges. https://twitter.com/... https://twitter.com/...
  • @cz_binance @cz_binance on x
    I am reasonably sure there are wide spread API key leaks from 3Commas. If you have ever put an API key in 3Commas (from any exchange), please disable it immediately. Stay #SAFU.
  • @zachxbt @zachxbt on x
    2/ I won't spread the db as some of the keys are potentially still active but here is what the account had to say about the leak in a post: Unfortunately it seems they will be publishing the full database of 3Commas users soon. https://twitter.com/...
  • @tier10k @tier10k on x
    PSA 3Commas API leak has been published, if you haven't already REMOVE YOUR API KEY https://twitter.com/...
  • @blackbeardxbt Blackbeard on x
    Hey @3commas_io, you should edit your bio and add ‘...providing traders AND hackers with ultimate control...’ Better start to put money aside to refund all victims. You gaslighted your users into thinking they got phished but it was all your fault. Clowns. https://twitter.com/...…
  • @zachxbt @zachxbt on x
    4/ 3Commas finally acknowledged the leak but the damage had already been done. For weeks they have been blaming its users and accepting zero responsibility. Make sure to never give incompetent clowns like @3commas_io your business ever again. https://twitter.com/... https://twitt…
  • @coinmamba @coinmamba on x
    @YS_3Commas You kept lying and saying this was our fault instead of taking responsibility and prevented further exploits. Are you going to refund the users now?
  • @wiseanalyze Zen on x
    On December 26th 3commas stuff (or those to whom they've sold my keys) used my account to buy pumped coin and I've lost about 3/4 of my funds on Binance. How this situation will be solved? @cz_binance @cz_binance @3commas_io https://twitter.com/... https://twitter.com/...
  • @jnun Jason Nunnelley on x
    Unfortunately: 1) Anyone that ever built anything fast built it insecure AF 2) Anyone with any assets is a target for expert criminal hackers 3) Almost every platform will eventually expose your data to an unauthorized 3rd party 4) VC seldom invest in security, it's boring https:…
  • @zseano @zseano on x
    “there's no api leak!”, then 8 hours later after the data is dumped online they're like “oops yeah there was a leak” lol too funny.. Sharing this incase anyone ever used this service. Stay safe out there! https://twitter.com/... https://twitter.com/...
  • @c7five Nick Percoco on x
    To be safe, if you used @3commas_io with any exchange, you need to go to that exchange and delete the specific API keys. We proactively did this for @krakenfx clients 2 weeks ago. Just disabling @3commas account or removing your API keys there won't protect you. https://twitter.c…
  • @buda_kyiv @buda_kyiv on x
    My strong recommendation for all @3commas_io leak victims is to hire the lawyer ASAP Link to leakage below https://pastebin.com/... Best documented lawsuits would win and you will have a chance for compensation
  • @okx @okx on x
    PSA: We understand the importance of security and the need to protect your assets. Exposing your API keys equals exposing your passwords. Here's what #OKX has been doing regarding the situation with @3commas_io: https://twitter.com/...
  • @zachxbt @zachxbt on x
    @Tree_of_Alpha @YS_3Commas Never forget https://twitter.com/...
  • @ys_3commas Yuriy Sorokin on x
    2. We did everything that we could to investigate an inside job, as it was always a possible scenario and on our watch list, but proof of an inside job was not found.
  • @tree_of_alpha @tree_of_alpha on x
    Lmao 3commas sent an email to users saying “update your API keys”, no mention of the massive hack they had leaking tens of thousands of user APIs, After weeks of blaming others for their blatant failure. This company is a joke and if you keep using it after today it's on you. htt…
  • @star_okx @star_okx on x
    Our agile risk team raised a red flag on the #3Commas API key leak and swiftly devised safety measures urging our users to regenerate their keys to minimize counterparty risk. For #OKX, risk management and consumer protection are our priorities. https://twitter.com/...
  • @cz_binance @cz_binance on x
    I strongly believe @tier10k is correct here, not 3comma's official response (BS). https://twitter.com/...
  • @garlamwon @garlamwon on x
    @YS_3Commas But didn't you gaslight everyone into thinking that it was their fault for getting “phished?” Where's the apology for people who pulled all their hair out and went bald because they thought it was their fault
  • @functi0nzer0 Laurence on x
    Literal weeks of “there was no hack, no leak, it's all FUD” Now caught with their pants down doing damage control after someone leaks the data Absolutely pathetic To the streets https://twitter.com/...
  • @zachxbt @zachxbt on x
    Update: Three of the verified victims have found their leaked API in the file. https://twitter.com/...
  • @threadoor @threadoor on x
    This 3commas leak is insane - and proves that the 3commas team themselves stole the funds. It seems like a small group of people are taking action against all the bad actors in this space. Pastebin with all the info: https://pastebin.com/...
  • @zachxbt @zachxbt on x
    @tier10k Clowns https://twitter.com/... https://twitter.com/...
  • @zachxbt @zachxbt on x
    @tier10k *deletes tweet* https://twitter.com/...
  • @zachxbt @zachxbt on x
    @cz_binance I reviewed the new db leak and agree
  • @coindesk @coindesk on x
    An anonymous Twitter user has leaked what they say are over 10,000 Binance and KuCoin API keys connected to the trading app 3Commas. By @skesslr https://www.coindesk.com/...