Cybercriminals have abused API keys to steal millions in crypto Cryptocurrencies


API keys are being abused by cybercriminals to steal millions in cryptocurrency from unsuspecting traders according to new research from CyberNews.
As Bitcoin and other cryptocurrencies have become increasingly popular over the past few years, companies have begun to offer apps and other services to make trading easier. In order to uses these services though, traders need to grant third-party programs access to their cryptocurrency exchange accounts via API keys that allow these programs to perform actions on their behalf such as opening and executing automatic trade orders.
These API keys include both a public key and a private key which is often referred to as a secret key. This secret key is what is used by third-party apps to execute trade orders on a user’s behalf. However, if a cybercriminal is able to obtain a users’ secret key, they can then steal their cryptocurrency.
Cryptocurrency exchanges usually provide traders with three types of API permissions in the form of data permissions, trade permissions and withdrawal permissions. Data permissions allow APIs to read a user’s exchange account data, trade permissions allow them to execute trades, place open orders and close orders and withdrawal permissions allow them to take cryptocurrency from a user’s exchange account and transfer it to another location.
For security reasons, cryptocurrency exchanges disable withdrawal permissions by default. This is why cybercriminals have been leveraging trade permissions to empty the cryptocurrency wallets of their victims.
API key abuse
During its investigation, CyberNews discovered that cybercriminals employ ‘sell wall’ buyouts and price boosting to steal funds from traders.
Sell walls are a common market manipulation technique used in both the stock and cryptocurrency markets. When it comes to cryptocurrency, sell walls are massive market sell orders that are artificially created by market manipulators to lower the price of a cryptocurrency or keep them below the maximum threshold in order to buy up a lot of coins on the cheap.
According to CyberNews‘ latest report, cybercriminals have been using trading bots to open many small sell orders to create sell walls in order to force victims to sell their cryptocurrencies. Price boosting is another technique commonly used to exploit stolen API keys which involves buying cheap coins and then selling them back to a victim at extortionary rates.
Cybercriminals don’t even need to install malware or spyware on a user’s device to obtain their API keys as instead, they scan publicly accessible web application environment files and public code repositories for leaked private keys.
In order to protect your cryptocurrencies, CyberNews recommends that traders whitelist IP addresses for API key usage and avoid storing their API keys on a hard drive or disclosing them to anyone. Another step you could take is to store your cryptocurrency offline instead using a hardware wallet like the Ledger Nano X or the Trezor Model T.
Via CyberNews
API keys are being abused by cybercriminals to steal millions in cryptocurrency from unsuspecting traders according to new research from CyberNews. As Bitcoin and other cryptocurrencies have become increasingly popular over the past few years, companies have begun to offer apps and other services to make trading easier. In order…
Recent Posts
- Elon Musk claims federal employees have 48 hours to explain recent work or resign
- xAI could sign a $5 billion deal with Dell for thousands of servers with Nvidia’s GB200 Blackwell AI GPU accelerators
- Race to 100TB HDD heats up as Seagate pulls rug under Western Digital, Toshiba feet by acquiring HAMR-specialist
- The 20 Best Barefoot Shoes for Running or Walking (2025)
- New video leak may have revealed the full Nothing Phone 3a and Phone 3a Pro design
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010