Risk notice: trading bots automate execution, not profit. Crypto trading involves substantial risk of loss - never deploy more than you can afford to lose. Some links are affiliate/referral links; rankings stay independent. Risk disclosure.

API Key Security for Trading Bots: The 2022 Lesson

In late 2022 roughly 100,000 API keys leaked from 3Commas. Attackers drained accounts without withdrawal permissions by trading illiquid pairs against their own orders. Every lesson below comes from that incident.

table of contents
  1. Trade-only keys do not make you safe
  2. The checklist that does protect you
  3. Vendor transparency is a security feature

Trade-only keys do not make you safe

Victims had correctly disabled withdrawal rights. Attackers sold BTC for USD and bought worthless low-cap tokens at inflated prices from their own wallets on the other side of the trade - losses up to $370k per account. Any key that can trade can drain you on a thin market.

The checklist that does protect you

1. Whitelist the bot platform's IPs on the key. 2. Use one key per service, never reuse. 3. Rotate keys on any suspicious activity - immediately, not after the vendor emails you. 4. Prefer OAuth fast-connect where offered (the exchange then revokes centrally). 5. Keep balances on the exchange low; bots only need working capital. 6. Prefer exchange-native bots or self-hosting where your use case allows - then keys never leave your control.

Vendor transparency is a security feature

3Commas denied a breach for two months while users lost money, then admitted it after the leaked database surfaced. When you evaluate a bot platform, look for how it handled incidents: disclosure speed, post-mortems, independent audits. We track these in our incident timeline and factor them into safety scores.

FAQ

Is it safe to give a trading bot my API keys?

Risk is never zero with third-party platforms. Minimize it: IP-whitelisted trade-only keys, one key per service, low exchange balances, and prefer exchanges or setups where keys stay with you (native bots, self-hosted).

What happened in the 3Commas hack exactly?

See the full timeline in our incident archive: ~100k API keys leaked between October and December 2022, exploited via illiquid-pair wash trading, six-figure individual losses, and a delayed disclosure that worsened the damage.