3Commas denies staff members stole API keys

Share This Post

Crypto trading firm also rejects claim that users’ API keys were leaked and urges users to file a police report.

Crypto trading firm 3Commas has denied its employees’ stole user’s API keys, claiming that screenshots circulating on social media are fake and urging affected users to file police reports to stop the perpetrators from stealing their funds. 

In a blog post published on Dec. 11, 3Commas co-founder and CEO Yuriy Sorokin said that fake screenshots of Cloudflare logs are circulating on Twitter and YouTube “in an attempt to convince people that there was a vulnerability within 3Commas and that we were irresponsible enough to allow open access to user data and log files.” The alleged screenshots intend to show how customer’s API keys were exposed in 3Commas dashboard on Cloudflare.

In an another blog post, on Dec. 10, Sorokin encouraged affected users to file a police report to get their exchange accounts frozen. “The faster this is done, the faster exchanges can freeze the accounts of the perpetrators to stop funds from being withdrawn and increase the likelihood that some, or all, of the funds may be returned to victims.”

Since the majority of crypto exchanges follow Know Your Customer standards, users are required to provide identity details to trade or withdraw funds. If affected users provided a police report, exchanges would be able to share this information with investigators, noted the company.

As reported by Cointelegraph, a crypto trader who goes by CoinMamba on Twitter had his Binance account closed after he complained about lost funds. The leaked API key was tied to a 3Commas account. Both Binance and 3Commas deny any responsibility for the incident.

3Commas claims to have identified evidence of phishing attacks as a “contributory factor” for thefts. According to the company, the phishing attacks started in October, with bad actors trying different techniques. Sorokin stated:

“Also, we have hard evidence that phishing was at least in some part a contributory factor; we published a blog article here showing many fake 3Commas websites that were created and some are still live on the internet, despite our best efforts to have them taken down.”

Exchange API connections older than 90 days are being disabled by the company.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Trump Appoints Former SEC Chair to a Role That Could Influence Crypto Oversight

US President-elect Donald Trump has appointed former SEC Chair Jay Clayton to a key role, drawing attention to his crypto regulatory legacy and enforcement record Former SEC Chair Steps Into a Role

WIF Slide Below $3.582 Sparks Fears Of Further Losses

WIF latest dip below the crucial $3582 support has triggered concerns across the market, as bearish sentiment appears to be gathering strength Its break below this key level could pave the way for

Court filings reveal Elon Musk blocked OpenAI’s ICO plans to protect its reputation

Elon Musk revealed in recent court filings that he personally intervened to stop OpenAI from launching an initial coin offering (ICO) in 2018, a move he claimed would have severely damaged the

Cardano (ADA) Could Soar by 55%, Price Reaches Crucial Level

The post Cardano (ADA) Could Soar by 55%, Price Reaches Crucial Level appeared first on Coinpedia Fintech News Cardano (ADA) is making headlines as it leads the market with a remarkable price surge,

Bitcoin Hacker Sentenced To 5 Years For Laundering $10.5 Billion From Bitfinex

Ilya Lichtenstein, who pleaded guilty to his role in the 2016 Bitcoin hack of the cryptocurrency exchange Bitfinex, has been sentenced to five years in prison, as announced by the US Department of

A Crypto Mixer’s Endgame: Helix Operator Sentenced With $400M Asset Forfeiture

The DOJ has sentenced the operator of Helix, a cryptocurrency mixer, to prison and ordered the forfeiture of over $400 million in assets tied to money laundering DOJ Ends Helix’s Reign: Operator