Crypto platform 3Commas confirms major API breach, FBI to investigate

How to prevent cyberattacks



(Image credit: Unsplash)

Cryptocurrency trading platform 3Commas has confirmed it suffered a data breach that saw API data stolen.

As per the announcement, an unknown threat actor posted 3Commas’ API database to Pastebin, on December 28. 

After analyzing the database, the company confirmed its authenticity, saying “at this point, 3Commas can unfortunately confirm that some of 3Commas’ users’ API data (API keys, secrets and passphrases) have been disclosed by a third party”. 

Stolen money

While the leaks revolve around API data at the moment, 3Commas’ does not exclude the possibility of other data being taken, as well: “Currently and to the best of our knowledge only API data have been disclosed as part of this incident. As a likely consequence the hacker(s) may use or may have used the API data to connect your exchange accounts to his/their account and/or initiate unauthorized trades,” it says.

In a notice sent to its users via email and a blog post, the company says it has made strides to protect its users and their funds, and reported the issue to relevant law enforcement agencies, including the FBI. 

As per a BleepingComputer report, a set of 10,000 API keys were leaked, which is just 10% of the 100,000-big database. These keys are usually used by 3Commas bots to automatically interact with crypto exchange platforms, make trades and generate profit, without user interaction.

Reacting to the news, 3Commas urged all supported exchanges (including some of the biggest ones – Binance, Coinbase, and Kucoin) to revoke all API keys connected to the platform. The company also urged all users to reissue their keys on all linked endpoints (opens in new tab) personally.

Investigating the leak further, the company eliminated the possibility of this being an inside job: “Only a small number of technical employees had access to the infrastructure, and we have taken steps since November 19 to remove their access,” the company said in a Twitter post. 

“Since then, we have implemented new security measures, and we will not stop there; we are launching a full investigation in which law enforcement will be involved,” the company added.

But the damage has already been done. Apparently, threat actors have been abusing leaked API keys since November, and have managed to steal some $6 million worth of cryptocurrencies so far. 

Via: BleepingComputer (opens in new tab)

Sign up to theTechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read More
Diego Schroeder

Latest

5 Iconic ‘80s Movies You Can Stream Right Now

When we talk about great decades for entertainment, the 1990s usually come up and understandably so. That was a decade of great sci-fi, rom-coms, and more. But the 1990s aren’t the only decade with great movies. The 1980s was also a great time for movie fans, bringing to the screen a wide variety of movies

Sega reports $31.6m net loss during FY26, cancels ‘Super Game’ project amid strategic pivot

Impairment losses from Rovio and Stakelogic push company to reduce free-to-play priority and focus on full game development Image credit: Sega Sega Sammy has released its financial results for the year ending March 31, 2026. While net sales increased by 13.6%, operating income from its entertainment contents, including the video games division, declined from ¥40.8

African Businesses Feel the Pinch as Customers Flock to Online Gambling

African businesses are now competing for discretionary spending against a new sector – online gambling. As it proliferates, regular businesses, whether entertainment providers, phone companies, or even grocery shops, are seeing customers increasingly willing to spend on games of chance rather than perishables, a good flick, or faster internet. “People are spending money in a

Newsletter

Don't miss

5 Iconic ‘80s Movies You Can Stream Right Now

When we talk about great decades for entertainment, the 1990s usually come up and understandably so. That was a decade of great sci-fi, rom-coms, and more. But the 1990s aren’t the only decade with great movies. The 1980s was also a great time for movie fans, bringing to the screen a wide variety of movies

Sega reports $31.6m net loss during FY26, cancels ‘Super Game’ project amid strategic pivot

Impairment losses from Rovio and Stakelogic push company to reduce free-to-play priority and focus on full game development Image credit: Sega Sega Sammy has released its financial results for the year ending March 31, 2026. While net sales increased by 13.6%, operating income from its entertainment contents, including the video games division, declined from ¥40.8

African Businesses Feel the Pinch as Customers Flock to Online Gambling

African businesses are now competing for discretionary spending against a new sector – online gambling. As it proliferates, regular businesses, whether entertainment providers, phone companies, or even grocery shops, are seeing customers increasingly willing to spend on games of chance rather than perishables, a good flick, or faster internet. “People are spending money in a

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand

Getting a business loan now comes with a frequent flyer upside

Australian fintech Prospa has partnered with Qantas Business Rewards, letting eligible SMEs earn up to 500,000 points per loan. What’s happening: Australian fintech lender Prospa has partnered with Qantas Business Rewards to allow eligible small and medium business owners to earn up to 500,000 Qantas Points per loan when taking out a Prospa Small Business