Crypto platform 3Commas confirms major API breach, FBI to investigate

Cryptocurrency trading platform 3Commas has confirmed it suffered a data breach that saw API data stolen. As per the announcement, an unkn...

Cryptocurrency trading platform 3Commas has confirmed it suffered a data breach that saw API data stolen.

As per the announcement, an unknown threat actor posted 3Commas’ API database to Pastebin, on December 28. 

After analyzing the database, the company confirmed its authenticity, saying “at this point, 3Commas can unfortunately confirm that some of 3Commas’ users’ API data (API keys, secrets and passphrases) have been disclosed by a third party”. 

Stolen money

While the leaks revolve around API data at the moment, 3Commas’ does not exclude the possibility of other data being taken, as well: “Currently and to the best of our knowledge only API data have been disclosed as part of this incident. As a likely consequence the hacker(s) may use or may have used the API data to connect your exchange accounts to his/their account and/or initiate unauthorized trades,” it says.

In a notice sent to its users via email and a blog post, the company says it has made strides to protect its users and their funds, and reported the issue to relevant law enforcement agencies, including the FBI. 

As per a BleepingComputer report, a set of 10,000 API keys were leaked, which is just 10% of the 100,000-big database. These keys are usually used by 3Commas bots to automatically interact with crypto exchange platforms, make trades and generate profit, without user interaction.

Reacting to the news, 3Commas urged all supported exchanges (including some of the biggest ones - Binance, Coinbase, and Kucoin) to revoke all API keys connected to the platform. The company also urged all users to reissue their keys on all linked endpoints personally.

Investigating the leak further, the company eliminated the possibility of this being an inside job: “Only a small number of technical employees had access to the infrastructure, and we have taken steps since November 19 to remove their access,” the company said in a Twitter post. 

“Since then, we have implemented new security measures, and we will not stop there; we are launching a full investigation in which law enforcement will be involved,” the company added.

But the damage has already been done. Apparently, threat actors have been abusing leaked API keys since November, and have managed to steal some $6 million worth of cryptocurrencies so far. 

Via: BleepingComputer



from TechRadar - All the latest technology news https://ift.tt/mRCcOfv
via IFTTT

COMMENTS

BLOGGER
Name

Apps,3858,Business,151,Camera,1155,Earn $$$,3,Gadgets,1741,Games,926,GTA,1,Innovations,3,Mobile,1697,Paid Promotions,5,Promotions,5,Sports,1,Technology,8106,Trailers,796,Travel,37,Trending,4,Trendly News,25335,TrendlyNews,183,Video,5,XIAOMI,13,YouTube - 9to5Google,182,
ltr
item
Trendly News | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Reviews #TrendlyNews: Crypto platform 3Commas confirms major API breach, FBI to investigate
Crypto platform 3Commas confirms major API breach, FBI to investigate
Trendly News | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Reviews #TrendlyNews
http://www.trendlynews.in/2022/12/crypto-platform-3commas-confirms-major.html
http://www.trendlynews.in/
http://www.trendlynews.in/
http://www.trendlynews.in/2022/12/crypto-platform-3commas-confirms-major.html
true
3372890392287038985
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy