Review of the whole process:3Commas API KEY ‘leak’, FTX user funds was stolen by contra trade
On October 21, a Chinese user broke the news to WuBlockchain: his FTX account suddenly went "crazy" on the night of the 19th with more than 5,000 transactions, and his account assets of $1.6 million were close to zero, including more than 10 BTC, hundreds of ETH and thousands of FTT, all stolen by DMG Pair‘s contra trade. The user started using the quantitative robot 3Commas 1 year ago, the FTX API does not need to be updated, so it has never moved or saved the API. FTX feedback is due to someone who has access to the API KEY through the REST API, which may have leaked the user API KEY. FTX said it needs to get a notice of case to cooperate with related work such as freezing, but no response after the user submitted a report receipt. 3Commas said there was no leak. Victim 1: #FTX #SBF @FTX_Chinese
@FTX_Official
@SBF_FTX
@Phyrex_Ni
@wublockchain12
@FTX_Benson
@Constance_FTX
@3Commas_ZH
@3commas_io
(事情的第一段)1.事情发生在北京时间2022年10月19号晚上,突然发现我的FTX账户在疯狂交易,我急忙登录查看,账户资产110万美金(总市值160万美金左右)接近归零 It is worth noting that FTX customer service initially replied that "you are not the only one affected", but then FTX customer service stopped contacting and said it was a misunderstanding. The question came to 3Commas, which responded promptly after WuBlockchain said the report: "At the moment, 3Commas considers this matter a top priority. We use 2FA and OTP etc. with the highest security when logging in to ensure that user accounts are always secure. We are in contact with our users to ensure that they receive all the support they need. Subsequently, 3Commas made an announcement: On the 20th of October, the 3Commas team was alerted to an incident that occurred where a number of partner exchange API keys connected to 3Commas and used to perform unauthorized trades for DMG cryptocurrency trading pairs on partner exchange accounts. During a collaborative investigation conducted by 3Commas and our partner exchanges, a number of API keys were found to be linked to new 3Commas accounts that were created and used for the first time to perform unauthorized trades for the DMG trading pairs on the partner exchange. The API keys were not taken from 3Commas but from outside of the 3Commas platform. Our team widened the investigation and found several fake 3Commas websites that were used to "phish" 3Commas users by replicating the design of the 3Commas web interface and captured API keys from 3Commas users that had accidentally used the fake website to try and connect their exchange accounts. The API keys were then stored by the fake website and later used to place the unauthorized trades on the DMG trading pairs on the partner exchange. If you have an exchange account connected to 3Commas and it is saying the API is "invalid" or "requires updating", then it is possible your API details were compromised and the API key has been deleted by the partner exchange. We urge you to create new API keys on that exchange and update your linked exchange accounts in 3Commas using the guide below to ensure any trades or deals you have active will be unaffected. learn more: https://3commas.io/blog/3commas-security-update-october-20 After the announcement, however, more victims began to appear. One victim from Paraguay told WuBlockchain that he lost nearly 104 bitcoins in the attack, stressing that FTX had known about the vulnerability since October 19, two days after I was attacked! 3Commas said it was a phishing attack, but I never used my 3Commas account to set up the bot, and the account had even expired and been downgraded to a free account. I have not had access to the account for over a year and I have never saved keys or API keys to any document, but only used it to set up an FTX connection over a year ago. I am also an IT engineer and my laptop and smartphone are protected by Norton 360 and other mechanisms that actively prevent any phishing or virus attacks. Another victim of quantitative trading from China also reported never having used 3Commas. In his screenshots, the coin theft on the 19th, 20th, and 21st all occurred in relation to DMG's counter-attack, but surprisingly FTX did not take precautions against this. Hello Ftx, My name is Bruce and I am one of the victims of the 3Commas API exploit on FTX.I lost about 1.5 million USD in the attack(counting the market value of BTC).It happened on 21th in Beijing time. As public opinion festered, SBF finally responded on October 24, saying it would pay $6 million in compensation, but that "this is a one-time event and we will not make a habit of compensating for phishing by counterfeit versions of other companies." The attackers of the FTX contra trade incident have transferred the profits they made to Binance and FixedFloat exchanges. SBF says it will absolve the attackers of any legal liability if they return 95% of the stolen funds within 24 hours. So far, both FTX and 3Commas have insisted that the API KEY was compromised by a user accessing a fake phishing site, which the victims certainly don't agree with. But at the heart of the matter is the fact that the API KEY was leaked and uniformly contra trade on FTX. Since the data is in the hands of 3Commas and FTX, the information disclosed is very sparse, so the truth may not be fully understood by the outside world. All in all, we need to be more careful about the authorization and management of API KEY. Follow us Twitter: https://twitter.com/WuBlockchain Telegram: https://t.me/wublockchainenglish If you liked this post from Wu Blockchain, why not share it? |
Older messages
Asia's weekly TOP10 crypto news (Oct 17 to Oct 23)
Sunday, October 23, 2022
Author:Lily Editor:Colin Wu 1. Huobi's weekly summary 1.1 Justin Sun plans to make Huobi Global the top three in the world link Justin Sun tweeted that he will concretely land measures to empower
Weekly project update: frxETH was introduced, Polkadot CEO resigns, Bitget cooperated with Messi and Top 10 projec…
Saturday, October 22, 2022
1. Publicchain Sui's weekley summary a. Sui: There are currently no official airdrop plans. link Public Chain Sui announced on October 22 that SUI Token is not currently available online or for
WuBlockchain Weekly:Aptos、Justin Sun $HT Bag、WhatsMiner and Top10 News
Friday, October 21, 2022
Top10 News 1、Aptos: Mainnet Launch, Release of Token Economics, Airdrop On October 17, Aptos Labs announced the launch of its mainnet, Aptos Autumn, followed by the release of token economics and the
Element, a new NFT market invested by Sequoia, can it succeed?
Thursday, October 20, 2022
Author: @0xMavWisdom After more than three months of exploring the 1.0 phase, Element 2.0, the multi-chain aggregated NFT marketplace with its founder Wang Feng and Sequoia Capital investment ring, has
Be VEE: Korean Artist's Free Mint and NFT Traffic Monetization Attempt
Wednesday, October 19, 2022
Author: Carol (Twitter: @CC99Carol) Editor: Wu Shuo Blockchain Abstract: Recently, the emerging NFT project Be VEE has gradually come to the fore, and its creator RDR tries to explore a complete path
You Might Also Like
MicroStrategy buys nearly 80,000 BTC in November, outpacing US Bitcoin ETF purchases
Monday, November 18, 2024
The Michael Saylor-led firm now holds more than 330000 BTC, which valued at around $30 billion. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Talk with Yan Meng: Trump's Election Victory and Its Impact on Crypto Policy, Market Dynamics, and Future Outlook
Monday, November 18, 2024
In this podcast episode, Wu Blockchain founder Colin Wu engages in a dialogue with Yan Meng, co-founder of Solv Protocol, to discuss the potential impact of Trump's election win on the crypto
📈 BTC overtook silver and Saudi Aramco as the 7th-largest asset by market cap; Crypto.com acquired Australian bro…
Monday, November 18, 2024
BTC overtook silver and Saudi Aramco as the 7th-largest asset by market capitalisation; Crypto.com acquired Australian brokerage firm Fintek; BlackRock's BUIDL is available on five more blockchains
Bitcoin futures break records with 29% OI surge in November
Sunday, November 17, 2024
Bitcoin derivatives market surges as institutional confidence grows amid post-election rally. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Asia's weekly TOP10 crypto news (Nov 11 to Nov 17)
Sunday, November 17, 2024
CZ and Vitalik attended an event in Bangkok hosted by Binance Labs in collaboration with the BIO Protocol, showcasing leading DeSci projects. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Navigating DAO Priorities: Balancing Retroactive Rewards and Future Funding | BanklessDAO Weekly Rollup
Saturday, November 16, 2024
Catch Up With What Happened This Week in BanklessDAO ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Gary Gensler claims SEC helped crypto, takes credit for Bitcoin ETFs, dismisses altcoins and hints at resignation
Saturday, November 16, 2024
Gensler also excluded Ethereum and stablecoins from other digital assets which he deems 'non-compliant.' ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Weekly Project Updates: Linea Plans to Launch Token in Q1 Next Year, Movement Set to Launch Mainnet, Over $10 Mill…
Saturday, November 16, 2024
Ethereum Layer 2 network Starknet announced that it will launch STRK token staking on the mainnet on November 26. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Weekly Project Updates: Linea Plans to Launch Token in Q1 Next Year, Movement Set to Launch Mainnet, Over $10 Mill…
Saturday, November 16, 2024
Ethereum Layer 2 network Starknet announced that it will launch STRK token staking on the mainnet on November 26. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Trump could put billions into US Bitcoin reserve without Congress approval
Friday, November 15, 2024
David Bailey suggests over $10 billion could be put into a reserve before needing to get Congress to approve funding. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏