A hacker leaks 10K+ API keys, claiming to have ~100K, of crypto trader 3Commas' users; 3Commas told users they were “phished” before its CEO confirmed the leak
3Commas first attributed the incident to user phishing; the company’s later confirmation of the leaked API-key dataset changes the account from an alleged user-side compromise to a confirmed exposure at a trading-service intermediary.
The stakes widened quickly in related coverage: the FBI was reported to be examining a larger cache, while a victims group reported more than $20 million in losses. Earlier breaches at Mailchimp and HubSpot had likewise made crypto customers targets through service-provider compromises.
First-order effects
3Commas must address a confirmed exposure of user API keys rather than rely on its earlier phishing explanation, while affected users must treat the leaked credentials as compromised.
The confirmation gives the reported FBI inquiry a concrete company acknowledgement to assess alongside claims of a much larger key cache.
Second-order effects
Crypto traders using third-party automation services face a sharper trust test: a compromise at the service layer can affect credentials tied to multiple user accounts.
The incident reinforces the pattern seen after Mailchimp’s customer-data breach, in which attacks on an intermediary create follow-on risk for crypto users rather than only for the breached company.
Third-order effects
If these incidents continue, crypto firms and the vendors around them will be judged increasingly on how they secure and disclose access credentials, not solely on the security of their own customer-facing systems.
Law-enforcement scrutiny of credential leaks may push crypto-service providers toward more formal incident-response and account-access controls, especially where user losses are alleged.
The trend: Crypto users are becoming exposed through the security and disclosure practices of the platforms and service providers that sit between them and their accounts.
1. Statement from 3Commas: We saw the hacker's message and can confirm that the data in the files is true. As an immediate action, we have asked that Binance, Kucoin, and other supported exchanges revoke all the keys that were connected to 3Commas.
3Commas Statement: 1) We have seen the hacker's message and can confirm that the data in the files is true. As an immediate action, we have requested that Binance, Kucoin and other supported exchanges revoke all keys that were connected to 3Commas. https://twitter.com/...
1/ Six hours ago an account messaged me and sent over a db with api keys of 3Commas users. I began working to verify its validity and quickly shared the info with exchanges. https://twitter.com/... https://twitter.com/...
I am reasonably sure there are wide spread API key leaks from 3Commas. If you have ever put an API key in 3Commas (from any exchange), please disable it immediately. Stay #SAFU.
2/ I won't spread the db as some of the keys are potentially still active but here is what the account had to say about the leak in a post: Unfortunately it seems they will be publishing the full database of 3Commas users soon. https://twitter.com/...
Hey @3commas_io, you should edit your bio and add ‘...providing traders AND hackers with ultimate control...’ Better start to put money aside to refund all victims. You gaslighted your users into thinking they got phished but it was all your fault. Clowns. https://twitter.com/...…
4/ 3Commas finally acknowledged the leak but the damage had already been done. For weeks they have been blaming its users and accepting zero responsibility. Make sure to never give incompetent clowns like @3commas_io your business ever again. https://twitter.com/... https://twitt…
@YS_3Commas You kept lying and saying this was our fault instead of taking responsibility and prevented further exploits. Are you going to refund the users now?
On December 26th 3commas stuff (or those to whom they've sold my keys) used my account to buy pumped coin and I've lost about 3/4 of my funds on Binance. How this situation will be solved? @cz_binance @cz_binance @3commas_io https://twitter.com/... https://twitter.com/...
Unfortunately: 1) Anyone that ever built anything fast built it insecure AF 2) Anyone with any assets is a target for expert criminal hackers 3) Almost every platform will eventually expose your data to an unauthorized 3rd party 4) VC seldom invest in security, it's boring https:…
“there's no api leak!”, then 8 hours later after the data is dumped online they're like “oops yeah there was a leak” lol too funny.. Sharing this incase anyone ever used this service. Stay safe out there! https://twitter.com/... https://twitter.com/...
To be safe, if you used @3commas_io with any exchange, you need to go to that exchange and delete the specific API keys. We proactively did this for @krakenfx clients 2 weeks ago. Just disabling @3commas account or removing your API keys there won't protect you. https://twitter.c…
My strong recommendation for all @3commas_io leak victims is to hire the lawyer ASAP Link to leakage below https://pastebin.com/... Best documented lawsuits would win and you will have a chance for compensation
PSA: We understand the importance of security and the need to protect your assets. Exposing your API keys equals exposing your passwords. Here's what #OKX has been doing regarding the situation with @3commas_io: https://twitter.com/...
2. We did everything that we could to investigate an inside job, as it was always a possible scenario and on our watch list, but proof of an inside job was not found.
Lmao 3commas sent an email to users saying “update your API keys”, no mention of the massive hack they had leaking tens of thousands of user APIs, After weeks of blaming others for their blatant failure. This company is a joke and if you keep using it after today it's on you. htt…
Our agile risk team raised a red flag on the #3Commas API key leak and swiftly devised safety measures urging our users to regenerate their keys to minimize counterparty risk. For #OKX, risk management and consumer protection are our priorities. https://twitter.com/...
@YS_3Commas But didn't you gaslight everyone into thinking that it was their fault for getting “phished?” Where's the apology for people who pulled all their hair out and went bald because they thought it was their fault
Literal weeks of “there was no hack, no leak, it's all FUD” Now caught with their pants down doing damage control after someone leaks the data Absolutely pathetic To the streets https://twitter.com/...
This 3commas leak is insane - and proves that the 3commas team themselves stole the funds. It seems like a small group of people are taking action against all the bad actors in this space. Pastebin with all the info: https://pastebin.com/...
An anonymous Twitter user has leaked what they say are over 10,000 Binance and KuCoin API keys connected to the trading app 3Commas. By @skesslr https://www.coindesk.com/...