3Commas denies staff members stole API keys

1 year ago

Crypto trading steadfast besides rejects assertion that users' API keys were leaked and urges users to record a constabulary report.

242 Total views

1 Total shares

3Commas denies unit   members stole API keys

Own this portion of crypto past

Collect this nonfiction arsenic NFT

Crypto trading steadfast 3Commas denied its employees' stolen user's API keys, claiming the screenshots circulating connected societal media are fake, and urged affected users to record a constabulary study successful bid to halt withdrawals successful exchanges. 

In a blog station published connected Dec. 11, 3Commas co-founder and CEO Yuriy Sorokin said that fake screenshots of Cloudflare logs are circulating connected Twitter and YouTube "in an effort to person radical that determination was a vulnerability wrong 3Commas and that we were irresponsible capable to let unfastened entree to idiosyncratic information and log files." The alleged screenshots intend to amusement however customer's API keys were exposed successful 3Commas dashboard connected Cloudflare.

A 2nd blog station by Sorokin from Dec.10, encourages affected users to record a constabulary study successful bid to get accounts frozen connected exchanges. "The faster this is done, the faster exchanges tin frost the accounts of the perpetrators to halt funds from being withdrawn and summation the likelihood that some, oregon all, of the funds whitethorn beryllium returned to victims."

As the bulk of crypto exchanges follows cognize your lawsuit standards, users are required to supply individuality details to commercialized oregon retreat funds. If affected users provided a constabulary report, exchanges would beryllium capable to stock this accusation with investigators, noted the company.

As reported by Cointelegraph, a crypto trader by the sanction of CoinMamba connected Twitter had his relationship closed connected Binance's level aft helium complained astir mislaid funds. The leaked API cardinal is tied to a 3Commas account. Both the companies, Binance and 3Commas, contradict immoderate work for the incident.

3Commas claims to person identified grounds of phishing attacks arsenic a "contributory factor" for thefts. According to the company, the phishing attacks started successful October, with atrocious actors trying antithetic phishing techniques. Sorokin stated:

"Also, we person hard grounds that phishing was astatine slightest successful immoderate portion a contributory factor; we published a blog nonfiction present showing galore fake 3Commas websites that were created and immoderate are inactive unrecorded connected the internet, contempt our champion efforts to person them taken down."

Exchange API connections older than 90 days are being disabled by the company.

View source