{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-3commas-users-phished-for-api-keys-leading-to-unauthorised-trades-on-ftx"},"incident":{"slug":"2022-3commas-users-phished-for-api-keys-leading-to-unauthorised-trades-on-ftx","title":"3Commas users phished for API keys, leading to unauthorised trades on FTX accounts","date":"2022-10","date_precision":"month","year":2022,"victim_org":"3Commas users (with linked FTX and Binance accounts)","sector":"Cryptocurrency","country":"Estonia","primary_vector":"Credential Phishing Portal","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Cryptocurrency Theft","Credential Theft"],"loss_usd":6000000,"loss_kind":"aggregate","loss_note":"Reported aggregate user losses of roughly US$6 million across affected accounts; FTX said it would compensate some affected users. Individual reported losses ranged widely.","records_affected":null,"threat_actor":null,"summary":"In October 2022 users of the crypto trading-bot platform 3Commas reported unauthorised trades on their FTX and Binance accounts. 3Commas said attackers had built counterfeit 3Commas websites that tricked users into entering their exchange API keys, which were then used to execute wash trades that drained value from the victims' accounts. 3Commas later confirmed that a set of API keys had been leaked, and FTX said it would compensate some affected users.","how_it_worked":"Attackers stood up phishing sites imitating 3Commas and lured users, mainly through crypto community channels and search, into connecting their exchange accounts there. Victims typed their exchange API keys into the fake interface believing they were configuring a trading bot, which is exactly what a real 3Commas onboarding asks for, so the request was indistinguishable from the legitimate flow. With trading-enabled API keys the attackers did not need to withdraw funds, which would have hit withdrawal controls; instead they ran wash trades against illiquid pairs, moving value out of victims' accounts through the market itself.","lessons":"API keys should be issued with the narrowest permissions and an IP allowlist, and platforms should never accept exchange keys through a page a user reached from an untrusted link.","confidence":"Reported","sources":[{"title":"FTX API keys connected to 3Commas confirmed to have been exploited","url":"https://www.theblock.co/post/179237/ftx-api-keys-3commas-exploited","publisher":"The Block"},{"title":"3Commas legal statement in regard of violated API keys","url":"https://3commas.io/blog/3commas-legal-statement-in-regard-of-violated-api-keys","publisher":"3Commas"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-3commas-users-phished-for-api-keys-leading-to-unauthorised-trades-on-ftx"}}