3Commas: API Keys and Attacks on Exchanges Not Due to System Vulnerability

Yuriy Sorokin, founder and CEO of trading bot platform 3Commas, released an update on investigation into API keys and attacks on exchanges.

The update states that 3Commas collected information from affected users, but the information shows that each case is different and there is no commonality between the cases except for unauthorized trading activity. The large number of high net-worth individuals using 3Commas who haven't been affected is a further indication that it wasn't a vulnerability in its system. In addition, 3Commas has indicated that phishing was at least in some part a contributory factor.

In the future, 3Commas will continue to work with exchanges to provide additional and more secure, exchange connection options, such as Fast Connect; disable old and inactive exchange API connections more than 90 days old; and contact individual exchanges to provide the Public API keys for the disabled connections so they may be deleted on the exchange side to ensure the safety of its users. In addition, 3Commas recommends that all users review their exchange API keys.

Previously, a number of users of Binance, OKX, FTX and some other exchanges experienced unauthorized trades initiated via API keys.

Source