API Key Security for Trading Bots: The 2022 Lesson
In late 2022 roughly 100,000 API keys leaked from 3Commas. Attackers drained accounts without withdrawal permissions by trading illiquid pairs against their own orders. Every lesson below comes from that incident.
table of contents
Trade-only keys do not make you safe
Victims had correctly disabled withdrawal rights. Attackers sold BTC for USD and bought worthless low-cap tokens at inflated prices from their own wallets on the other side of the trade - losses up to $370k per account. Any key that can trade can drain you on a thin market.
The checklist that does protect you
1. Whitelist the bot platform's IPs on the key. 2. Use one key per service, never reuse. 3. Rotate keys on any suspicious activity - immediately, not after the vendor emails you. 4. Prefer OAuth fast-connect where offered (the exchange then revokes centrally). 5. Keep balances on the exchange low; bots only need working capital. 6. Prefer exchange-native bots or self-hosting where your use case allows - then keys never leave your control.
Vendor transparency is a security feature
3Commas denied a breach for two months while users lost money, then admitted it after the leaked database surfaced. When you evaluate a bot platform, look for how it handled incidents: disclosure speed, post-mortems, independent audits. We track these in our incident timeline and factor them into safety scores.
FAQ
Is it safe to give a trading bot my API keys?
Risk is never zero with third-party platforms. Minimize it: IP-whitelisted trade-only keys, one key per service, low exchange balances, and prefer exchanges or setups where keys stay with you (native bots, self-hosted).
What happened in the 3Commas hack exactly?
See the full timeline in our incident archive: ~100k API keys leaked between October and December 2022, exploited via illiquid-pair wash trading, six-figure individual losses, and a delayed disclosure that worsened the damage.