Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Litecoin Summit Day 2 LitVM's $50M Bet and BasicSwapDEX's Bold Vision
    Litecoin Summit Day 2: LitVM’s $50M Bet and BasicSwapDEX’s Bold Vision
    Litecoin Summit Day 1 Quantum Warnings, Privacy Coin Breakthroughs, & MiCA's Looming Deadline
    Litecoin Summit Day 1: Quantum Warnings, Privacy Coin Breakthroughs, & MiCA’s Looming Deadline
    Inside the High-Stakes Corporate War Over the GENIUS Act
    Inside the High-Stakes Corporate War Over the GENIUS Act
    From Demonetization to Digital Rupee India's Decade-Long Blockchain Journey
    From Demonetization to Digital Rupee: India’s Decade-Long Blockchain Journey
    The 7% Premium Trap Exposed How India Makes Crypto More Expensive Than Dollars
    The 7% Premium Trap Exposed: How India Makes Crypto More Expensive Than Dollars
  • Opinion
    OpinionShow More
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

3Commas confirms the API Key Leak after Denying their Involvement

Binance CEO CZ already tweeted before the incident that he is sure there are widespread API key leaks from 3Commas.

Written By Vismaya V Vismaya V
Published 2022-12-29
Make The Crypto Times preferred on GoogleGoogle
Last updated: December 29, 2022 9:43 AM
Published 2022-12-29
Share
Last updated: December 29, 2022 9:43 AM
Published 2022-12-29
3Commas confirms the API Key Leak after Denying their Involvement

After several weeks of denial, crypto trading firm 3Commas finally admitted that it was the source of the massive API key leak that cost its users millions of funds.

1. Statement from 3Commas:

We saw the hacker’s message and can confirm that the data in the files is true. As an immediate action, we have asked that Binance, Kucoin, and other supported exchanges revoke all the keys that were connected to 3Commas.

— Yuriy Sorokin (@ysoro13) December 28, 2022

Late October saw the start of 3Commas’ security concerns. In response to reports from users of unlawful trades of trading pairs with the DMG coin on FTX at the time, the still operational FTX exchange issued a security notice. The trades were carried out using accounts that were created by hackers, according to 3Commas and FTX.

Users can connect their multiple crypto exchange accounts, such as Binance, KuCoin, OKX, and other platforms, to automated trading software using the 3Commas platform. Application programming interfaces (APIs) are standardized procedures that let various software components connect with one another and carry out activities.

3Commas and its CEO Yuriy Sorokin denied their involvement multiple times since November, even after users were complaining relentlessly. In November, 3Commas released a blog post stating that, using a number of phishing techniques, malicious actors were able to steal the exchange API keys of some crypto traders. 

3Commas noted the hackers may have also compromised the security of the user’s personal computers by installing malware and browser extensions to gain access to the files containing the keys.

“The wide number of exchanges and trade automation services involved provides strong evidence that this is a sophisticated multi-month phishing attack executed by a criminal organization targeting individual crypto traders,” the firm stated. 

Sorokin has consistently responded to the criticisms of the platform in a series of blog pieces published on the 3Commas website.

In addition to denying that its employees stole users’ API keys, 3Commas asserted that screenshots making the rounds on social media were fraudulent and urged anybody who had been harmed to contact the authorities to prevent further fund theft.

In a blog post published this month, 3Commas noted, “In the latest edition to this saga of API keys and attacks on exchanges, we’re now seeing individuals on Twitter and YouTube circulating fake screenshots of Cloudflare logs in an attempt to convince people that there was a vulnerability within 3Commas and that we were irresponsible enough to allow open access to user data and log files.”

3Commas appeared really confident in their innocence by claiming, “As an overall conclusion, we see that the bad actors have put a lot of effort into creating these fake images. This is an unprecedented information attack. But it would be nonsense to take any “security reports” that rely on such kind of “proof” seriously.”

Later, famous crypto trader CoinMamba tweeted that their Binance was compromised due to a breach of the 3Commas API key, which resulted in them taking a loss. The post sparked a series of conversations between CoinMamba and CZ, CEO of Binance, which resulted in the closure of CoinMamba’s Binance account.

Hey guys. Unfortunately two days ago my Binance account got exploited through an API which I’ve created 2 years ago and haven’t used since which I assumed I deleted but apparently didn’t. It was used to make trades on low cap coins to push up the price to make profit.

— CoinMamba (@coinmamba) December 8, 2022

Crypto sleuth ZachXBT chimed in on the situation, saying that over the past couple of weeks, a number of 3Commas users have reported unauthorized trades on their CEX accounts. 

“3Commas blames it on “phishing”, but I now have verified a group of 44 victims who’ve had $14.8m in total stolen,” ZachXBT tweeted.

3Commas addressed the concern but by repeating that there is no hacking or API leak at the platform, encouraging victims to file a police report.

We maintain that there is no hacking or API leak at 3commas. You can read it here https://t.co/4Hzn5wksDK

We also encourage victims to file a police report, so that the exchanges can be investigated and the trading accounts can be traced and the funds returned to the users.

— 3Commas (@3commas_io) December 20, 2022

A Twitter user was able to gain almost 100,000 API keys belonging to 3Commas customers. Over 10,000 of the keys were released by the leaker, and the remainder will be revealed randomly in the upcoming days, according to the leaker.

And today, after continuous irresponsible behavior by 3Commas, Twitter user db reported that all of 3Commas’ API keys have been leaked. Before that, Binance CEO CZ tweeted that he is sure there are widespread API key leaks from 3Commas.

PSA

3Commas API leak has been published, if you haven't already REMOVE YOUR API KEY pic.twitter.com/yEvrxyWBIq

— db (@tier10k) December 28, 2022

Following the 3Commas commotion, ZachXBT said an account messaged him and sent over a database with API keys of 3Commas users. ZachXBT checked in with the 3Commas victims group, and they confirmed multiple people had matched their API keys in the database.

1/ Six hours ago an account messaged me and sent over a db with api keys of 3Commas users. I began working to verify its validity and quickly shared the info with exchanges. pic.twitter.com/MBKatUyzBE

— ZachXBT (@zachxbt) December 28, 2022

The message sent to ZachXBT notes that the API keys were compromised “to teach everybody a low lesson, not a hard one to do not trust 3Commas.”

Sorokin finally bent his knees and acknowledged the event after verifying the leaked API keys, tweeting, “We are sorry that this has gotten so far and will continue to be transparent in our communications around the situation.” 

As an immediate action, 3Commas has asked that Binance, Kucoin, and other supported exchanges revoke all the keys that were connected to 3Commas.

3Commas announced, “We urge every user to reissue their keys on the exchanges. Again, we commit to saying that no keys after Nov 16 are at risk. In case you do not update those, they will be revoked by exchanges to ensure your account security.”

The 3Commas API leak victims are demanding compensation and an apology from the 3Commas and Sorokin for mishandling the whole situation even after the victims continuously reported the situation for weeks. 

Also Read: N Korean Hackers pull off NFT Phishing Scam worth 300 ETH

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Binance
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Vismaya V - Content Writer
By Vismaya V
Vismaya is a crypto content writer with over two years of experience in the field. With a passion for writing and research, Vismaya has made a name for herself in the crypto community with her in-depth analysis and clear explanations of complex topics. In addition to her love for writing and crypto, Vismaya is also a big fan of football and anime.

Latest News

Why Indian Traders Pay Over 10% Premium When Crypto Crashes
Why Indian Traders Pay Over 10% Premium When Crypto Crashes?
Kalshi Sues Illinois in Escalating Fight Over Prediction Markets
Kalshi Sues Illinois in Escalating Fight Over Prediction Markets
Kalshi Eyes $40B Valuation as Prediction Market Boom Continues Report
Kalshi Eyes $40B Valuation as Prediction Market Boom Continues: Report
Dave Portnoy Questions Bitcoin’s $1M Future as Price Drops Below $60K
Dave Portnoy Questions Bitcoin’s $1M Future as Price Drops Below $60K
STRC Stock Tumbles 7% to Near Yearly Lows Following Bitcoin Slump
STRC Stock Tumbles 7% to Near Yearly Lows Following Bitcoin Slump

Find Us on Socials

You may also like

Prediction Markets Score Rare Bipartisan Support in New Polls

Prediction Markets Score Rare Bipartisan Support in New Polls

Crypto Market Crash Wipes out $861M as BTC, ETH, XRP, BNB, SOL Price Drops

Crypto Market Crash: Wipes out $861M as BTC, ETH, XRP, BNB, SOL Price Drops

Binance Withdraws Greece Bid—But Its MiCA Plans Aren’t Dead

Binance Withdraws Greece Bid—But Its MiCA Plans Aren’t Dead

Binance Founder CZ Surpasses Bill Gates on Forbes Billionaires List

Binance Founder CZ Surpasses Bill Gates on Forbes Billionaires List

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information