Anonymous Twitter User Leaks 3Commas API Database
The leak comes after 3Commas repeatedly told users that they had been “phished” after widespread hacks.
An anonymous Twitter user has obtained around 100,000 API keys belonging to users of the crypto trading service 3Commas. The leaker published more than 10,000 of the keys on Wednesday and says the rest “will be published full [sic] randomly in the upcoming days.”
3Commas CEO Yuriy Sorokin confirmed the authenticity of the leak in a tweet on Wednesday, adding that "as an immediate action, we have asked that Binance, KuCoin, and other supported exchanges revoke all the [API] keys that were connected to 3Commas."
1. Statement from 3Commas:
— Yuriy Sorokin (@YS_3Commas) December 28, 2022
We saw the hacker’s message and can confirm that the data in the files is true. As an immediate action, we have asked that Binance, Kucoin, and other supported exchanges revoke all the keys that were connected to 3Commas.
The leak comes after dozens of users of 3Commas claimed that their API keys were used to execute trades on exchanges such as Binance, KuCoin and Coinbase without their consent. As CoinDesk previously reported, 3Commas confirmed that users lost at least $6 million to attackers starting in October, but that sum has at least doubled in recent weeks according to users who spoke to CoinDesk.
CoinDesk isn't linking to or naming the pseudonymous leaker's Twitter account because doing so could further expose sensitive private information.
3Commas initially told CoinDesk its users' losses resulted from phishing attacks, but those users – more than 50 of whom have organized themselves into Telegram chat groups – have insisted that their credentials must have been leaked by 3Commas or an exchange like Binance or Coinbase.
Read more: Alameda-Backed Crypto Trading Firm 3Commas Says It’s Pretty Sure It Wasn’t Breached
Wednesday's data dump is the clearest evidence yet that the credentials were leaked rather than phished. Multiple 3Commas users confirmed to CoinDesk that they were able to find their API keys among those that were shared by the leaker.
In his tweet, 3Commas' Sorokin noted that he and his company "did everything that we could to investigate an inside job, as it was always a possible scenario and on our watch list, but proof of an inside job was not found."
Before 3Commas made its statement, Binance CEO Changpeng Zhao cautioned users on Wednesday afternoon that "if you have ever put an API key in 3Commas (from any exchange), please disable it immediately."
I am reasonably sure there are wide spread API key leaks from 3Commas. If you have ever put an API key in 3Commas (from any exchange), please disable it immediately.
— CZ 🔶 Binance (@cz_binance) December 28, 2022
Stay #SAFU.
3Commas allows users to set up trading bots that automatically execute trades on their behalf on third-party crypto exchanges. Those exchanges generate API keys, and users plug those keys into 3Commas in order to grant the app access to their accounts. The API keys included in this week’s leak were, according to the leaker, generated on Binance and KuCoin.
UPDATE (Dec. 28, 2020 20:13 UTC): Adds tweet from Binance CEO.
UPDATE (Dec. 28, 2020 21:08 UTC): Adds confirmation and statements from 3Commas, removes 'Alleged' from headline.
More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
More For You
NFT Project Pudgy Penguins Takes Over Las Vegas Sphere in Holiday Campaign

The NFT brand’s animated segments will air on the Sphere across Christmas week, signaling the crypto company's move into real-world consumer markets.
What to know:
- Pudgy Penguins will run an ad campaign at the Las Vegas Sphere during Christmas week, one of the few crypto brands to secure a spot at the high-profile venue.
- The NFT project, which launched on Ethereum in 2021, has expanded into physical toys and digital gaming as part of a broader consumer push.
- Pudgy Penguins briefly overtook Bored Apes in floor price earlier this year and recently launched its PENGU token on Solana, now trading on major exchanges.










