Crypto platform 3Commas confirms major API breach, FBI to investigate


Cryptocurrency trading platform 3Commas has confirmed it suffered a data breach that saw API data stolen.
As per the announcement, an unknown threat actor posted 3Commas’ API database to Pastebin, on December 28.
After analyzing the database, the company confirmed its authenticity, saying “at this point, 3Commas can unfortunately confirm that some of 3Commas’ users’ API data (API keys, secrets and passphrases) have been disclosed by a third party”.
Stolen money
While the leaks revolve around API data at the moment, 3Commas’ does not exclude the possibility of other data being taken, as well: “Currently and to the best of our knowledge only API data have been disclosed as part of this incident. As a likely consequence the hacker(s) may use or may have used the API data to connect your exchange accounts to his/their account and/or initiate unauthorized trades,” it says.
In a notice sent to its users via email and a blog post, the company says it has made strides to protect its users and their funds, and reported the issue to relevant law enforcement agencies, including the FBI.
As per a BleepingComputer report, a set of 10,000 API keys were leaked, which is just 10% of the 100,000-big database. These keys are usually used by 3Commas bots to automatically interact with crypto exchange platforms, make trades and generate profit, without user interaction.
Reacting to the news, 3Commas urged all supported exchanges (including some of the biggest ones – Binance, Coinbase, and Kucoin) to revoke all API keys connected to the platform. The company also urged all users to reissue their keys on all linked endpoints (opens in new tab) personally.
Investigating the leak further, the company eliminated the possibility of this being an inside job: “Only a small number of technical employees had access to the infrastructure, and we have taken steps since November 19 to remove their access,” the company said in a Twitter post.
“Since then, we have implemented new security measures, and we will not stop there; we are launching a full investigation in which law enforcement will be involved,” the company added.
But the damage has already been done. Apparently, threat actors have been abusing leaked API keys since November, and have managed to steal some $6 million worth of cryptocurrencies so far.
Via: BleepingComputer (opens in new tab)
Audio player loading… Cryptocurrency trading platform 3Commas has confirmed it suffered a data breach that saw API data stolen. As per the announcement, an unknown threat actor posted 3Commas’ API database to Pastebin, on December 28. After analyzing the database, the company confirmed its authenticity, saying “at this point, 3Commas…
Recent Posts
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
- Lenovo is going all out with yet another funky laptop design: this time, it’s a business notebook with a foldable OLED screen
- Elon Musk’s first month of destroying America will cost us decades
- The first iOS 18.4 developer beta is here, with support for Priority Notifications
- Fortnite’s new season leans heavily on heist mechanics
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010