What happened
In October 2022 users of the crypto trading-bot platform 3Commas reported unauthorised trades on their FTX and Binance accounts. 3Commas said attackers had built counterfeit 3Commas websites that tricked users into entering their exchange API keys, which were then used to execute wash trades that drained value from the victims' accounts. 3Commas later confirmed that a set of API keys had been leaked, and FTX said it would compensate some affected users.
How the deception worked
Attackers stood up phishing sites imitating 3Commas and lured users, mainly through crypto community channels and search, into connecting their exchange accounts there. Victims typed their exchange API keys into the fake interface believing they were configuring a trading bot, which is exactly what a real 3Commas onboarding asks for, so the request was indistinguishable from the legitimate flow. With trading-enabled API keys the attackers did not need to withdraw funds, which would have hit withdrawal controls; instead they ran wash trades against illiquid pairs, moving value out of victims' accounts through the market itself.
The control that would have caught it· our reading, not a claim from the sources
API keys should be issued with the narrowest permissions and an IP allowlist, and platforms should never accept exchange keys through a page a user reached from an untrusted link.
Sources (2)
- FTX API keys connected to 3Commas confirmed to have been exploitedThe Block·theblock.coOpen ↗
- 3Commas legal statement in regard of violated API keys3Commas·3commas.ioOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.