Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

3Commas Admits It Was Source of API Leak That Led to Hacks

Altszn.com by Altszn.com
December 29, 2022
in Blockchain
0
3Commas Admits It Was Source of API Leak That Led to Hacks
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter



A group of traders last week said that $22 million worth of crypto had been stolen through compromised API keys from the trading platform 3Commas. On Wednesday, 3Commas admitted it was the source of that API leak.

The announcement came after an anonymous Twitter user obtained around 100,000 API keys belonging to 3Commas users and published it online. 

3Commas had initially insisted there was no security issue on its end, and co-founder Yuriy Sorokin repeatedly suggested on Twitter that a phishing attack caused users to give up their data. 

But on Wednesday, Sorokin tweeted: “We saw the hacker’s message and can confirm that the data in the files is true… We are sorry that this has gotten so far and will continue to be transparent in our communications around the situation.”

1. Statement from 3Commas:

We saw the hacker’s message and can confirm that the data in the files is true. As an immediate action, we have asked that Binance, Kucoin, and other supported exchanges revoke all the keys that were connected to 3Commas.

— Yuriy Sorokin (@YS_3Commas) December 28, 2022

3Commas is a platform that lets users link multiple crypto exchange accounts—such as those kept on Binance—to automated trading software. This is all done via APIs (application programming interfaces), the standardized mechanisms that enable separate software components to communicate with each other and perform tasks. The idea is that humans don’t have to do the hard work of thinking about their trades. Instead, it’s all done instantly and automatically via code. 

Until the wrong people get access to the APIs.

Blockchain sleuth @ZachXBT previously said on Twitter that he had verified a group of 44 victims who lost a total of $14.8 million through API keys stolen from 3Commas.

In response, Sorokin tweeted that “If you are a victim, then it means that somehow your keys were leaked,” but “not from 3Commas.” If the leaked API keys had been from 3Commas, “you would’ve seen millions of cases, not a hundred,” he reasoned.

If you are a victim – then it means that somehow your keys were leaked. Not from 3Commas, as otherwise, you would’ve seen millions of cases, not a hundred. browser extensions, stealers, and all kinds of malware are out there.

— Yuriy Sorokin (@YS_3Commas) December 23, 2022

In a separate thread, he blasted “incompetency from big media sources” and questioned the validity of a crowdsourced spreadsheet of compromised accounts. “Pay attention that the majority of the users reporting losses didn’t even open a support ticket with the exchange, and didn’t go to the police,” Sorokin tweeted. “How was this information verified?”

Again he asserted that there were too few incidents for it to have been a 3Commas exploit. “There are over 1 [million] keys connected to 3Commas, with ~100 users reporting issues with their accounts,” Sorokin tweeted. “Why would that happen if [database] was leaked?”

Today, a vindicated ZachXBT tweeted that “for weeks [3Commas] have been blaming its users and accepting zero responsibility.” 

“You kept lying and saying this was our fault instead of taking responsibility and prevented further exploits,” added @CoinMamba, another 3Commas user who said he lost funds. “Are you going to refund the users now?”

This isn’t the first time 3Commas and its API handling came under scrutiny. About a month before FTX filed for bankruptcy, Sam Bankman-Fried agreed to refund $6 million to customers affected by what was described as a phishing scam involving 3Commas.

On Wednesday, Binance CEO Changpeng Zhao tweeted that he was “reasonably sure” there were “widespread API key leaks” from 3Commas. 

I am reasonably sure there are wide spread API key leaks from 3Commas. If you have ever put an API key in 3Commas (from any exchange), please disable it immediately.

Stay #SAFU.

— CZ 🔶 Binance (@cz_binance) December 28, 2022

CZ added that users should disable their API keys in 3Commas. This is what 3Commas is now recommending as well.

“As an immediate action, we have asked that Binance, Kucoin, and other supported exchanges revoke all the keys that were connected to 3Commas,” Sorokin tweeted.

3Commas has not responded to a request for further comment from Decrypt.

Stay on top of crypto news, get daily updates in your inbox.





Read More: decrypt.co

Tags: 3commasadmitsAPIBlockchainHacksLeakLedSource
ADVERTISEMENT

Recent

SEC flags legal issues with Ethereum, Solana ETFs – Delay ahead?

SEC flags legal issues with Ethereum, Solana ETFs – Delay ahead?

June 2, 2025
The Dark Times Are Here. Where Is Bitcoin?

The Dark Times Are Here. Where Is Bitcoin?

June 2, 2025
Monero price eyes $500, but $420 stands as the next key hurdle

Monero price eyes $500, but $420 stands as the next key hurdle

June 2, 2025

Categories

  • Bitcoin (4,497)
  • Blockchain (10,728)
  • Crypto (8,668)
  • Dark Web (438)
  • DeFi (8,076)
  • Ethereum (4,525)
  • Metaverse (6,747)
  • Monero (246)
  • NFT (1,063)
  • Solana (4,896)
  • Web3 (19,764)
  • Zcash (458)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    SEC flags legal issues with Ethereum, Solana ETFs – Delay ahead?

    SEC flags legal issues with Ethereum, Solana ETFs – Delay ahead?

    June 2, 2025
    The Dark Times Are Here. Where Is Bitcoin?

    The Dark Times Are Here. Where Is Bitcoin?

    June 2, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 105,881.00
    • ethereumEthereum (ETH) $ 2,609.26
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.20
    • bnbBNB (BNB) $ 665.96
    • solanaSolana (SOL) $ 156.93
    • usd-coinUSDC (USDC) $ 0.999799
    • dogecoinDogecoin (DOGE) $ 0.195674
    • tronTRON (TRX) $ 0.268900
    • cardanoCardano (ADA) $ 0.690362
    • staked-etherLido Staked Ether (STETH) $ 2,607.08
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 105,836.00
    • hyperliquidHyperliquid (HYPE) $ 36.47
    • suiSui (SUI) $ 3.34
    • wrapped-stethWrapped stETH (WSTETH) $ 3,136.38
    • chainlinkChainlink (LINK) $ 14.10
    • avalanche-2Avalanche (AVAX) $ 21.21
    • stellarStellar (XLM) $ 0.271705
    • bitcoin-cashBitcoin Cash (BCH) $ 403.94
    • the-open-networkToncoin (TON) $ 3.21
    • leo-tokenLEO Token (LEO) $ 8.50
    • shiba-inuShiba Inu (SHIB) $ 0.000013
    • hedera-hashgraphHedera (HBAR) $ 0.171653
    • usdsUSDS (USDS) $ 0.999874
    • wethWETH (WETH) $ 2,614.00
    • litecoinLitecoin (LTC) $ 89.79
    • wrapped-eethWrapped eETH (WEETH) $ 2,780.68
    • moneroMonero (XMR) $ 357.53
    • polkadotPolkadot (DOT) $ 4.15
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.997150
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • bitget-tokenBitget Token (BGB) $ 4.76
    • pepePepe (PEPE) $ 0.000012
    • pi-networkPi Network (PI) $ 0.647738
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 105,893.00
    • whitebitWhiteBIT Coin (WBT) $ 31.38
    • aaveAave (AAVE) $ 257.24
    • uniswapUniswap (UNI) $ 6.46
    • daiDai (DAI) $ 1.00
    • bittensorBittensor (TAO) $ 403.42
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • aptosAptos (APT) $ 4.90
    • crypto-com-chainCronos (CRO) $ 0.103267
    • nearNEAR Protocol (NEAR) $ 2.51
    • okbOKB (OKB) $ 50.17
    • jito-staked-solJito Staked SOL (JITOSOL) $ 189.35
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • internet-computerInternet Computer (ICP) $ 5.13
    • ondo-financeOndo (ONDO) $ 0.851695
    • ethereum-classicEthereum Classic (ETC) $ 17.58
    • bitcoinBitcoin (BTC) $ 105,881.00
    • ethereumEthereum (ETH) $ 2,609.26
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.20
    • bnbBNB (BNB) $ 665.96
    • solanaSolana (SOL) $ 156.93
    • usd-coinUSDC (USDC) $ 0.999799
    • dogecoinDogecoin (DOGE) $ 0.195674
    • tronTRON (TRX) $ 0.268900
    • cardanoCardano (ADA) $ 0.690362
    • staked-etherLido Staked Ether (STETH) $ 2,607.08
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 105,836.00
    • hyperliquidHyperliquid (HYPE) $ 36.47
    • suiSui (SUI) $ 3.34
    • wrapped-stethWrapped stETH (WSTETH) $ 3,136.38
    • chainlinkChainlink (LINK) $ 14.10
    • avalanche-2Avalanche (AVAX) $ 21.21
    • stellarStellar (XLM) $ 0.271705
    • bitcoin-cashBitcoin Cash (BCH) $ 403.94
    • the-open-networkToncoin (TON) $ 3.21
    • leo-tokenLEO Token (LEO) $ 8.50
    • shiba-inuShiba Inu (SHIB) $ 0.000013
    • hedera-hashgraphHedera (HBAR) $ 0.171653
    • usdsUSDS (USDS) $ 0.999874
    • wethWETH (WETH) $ 2,614.00
    • litecoinLitecoin (LTC) $ 89.79
    • wrapped-eethWrapped eETH (WEETH) $ 2,780.68
    • moneroMonero (XMR) $ 357.53
    • polkadotPolkadot (DOT) $ 4.15
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.997150
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • bitget-tokenBitget Token (BGB) $ 4.76
    • pepePepe (PEPE) $ 0.000012
    • pi-networkPi Network (PI) $ 0.647738
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 105,893.00
    • whitebitWhiteBIT Coin (WBT) $ 31.38
    • aaveAave (AAVE) $ 257.24
    • uniswapUniswap (UNI) $ 6.46
    • daiDai (DAI) $ 1.00
    • bittensorBittensor (TAO) $ 403.42
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • aptosAptos (APT) $ 4.90
    • crypto-com-chainCronos (CRO) $ 0.103267
    • nearNEAR Protocol (NEAR) $ 2.51
    • okbOKB (OKB) $ 50.17
    • jito-staked-solJito Staked SOL (JITOSOL) $ 189.35
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • internet-computerInternet Computer (ICP) $ 5.13
    • ondo-financeOndo (ONDO) $ 0.851695
    • ethereum-classicEthereum Classic (ETC) $ 17.58