Risk notice: trading bots automate execution, not profit. Crypto trading involves substantial risk of loss - never deploy more than you can afford to lose. Some links are affiliate/referral links; rankings stay independent. Risk disclosure.

Security incident timeline

The events that shaped bot-trading security - documented, dated, sourced. We factor vendor response quality into our safety scores.

2022-10-29

First drained 3Commas-connected accounts

Users of 3Commas with exchange API keys report unauthorized trades; a self-reported $30,000 loss on a key that was only ever given to 3Commas. 3Commas attributes the wave to phishing.

2022-11-14

CZ publicly warns against third-party bot platforms

Binance CEO tweets a warning about unexpected trading on accounts that shared API keys with third-party platforms including 3Commas and Skyrex; Skyrex confirms it was hacked. 3Commas publicly denies any leak.

2022-11-24

Thanksgiving Coinbase Pro attacks

Multiple Coinbase Pro accounts connected to 3Commas suffer coordinated drain trades through illiquid pairs (JASMY-style pump-and-dump against attacker wallets). Documented single losses include $150k (1,300 unauthorized transactions) and ~$370k from a ~$500k account. Withdrawal rights were NOT required for the attack.

2022-12-28

Leaked database: ~100,000 API keys published

An anonymous leaker publishes a claimed 100,000 API keys tied to 3Commas (Binance, Coinbase Pro, KuCoin, Kraken, OKX and others). 3Commas CEO confirms the breach; a Binance user reports 0.63 BTC lost via 67 unauthorized trades in 9 minutes. Victim groups estimate collective losses above $20 million.

2023-01-06

KuCoin victim loses 99% of balance after "keys disabled" notice

A KuCoin user reports that both KuCoin and 3Commas notified him the leaked keys were disabled - ten days later ~99% of his balance was traded away overnight. Lesson: revoke keys yourself, immediately.

2023-01-30

Aftermath: BlueVoyant audit, IP-whitelisted Fast Connect

3Commas engages cybersecurity firm BlueVoyant and rolls out OAuth/IP-whitelisted Fast Connect for major exchanges. Binance tightens API key policies in response, which self-hosted bot users with dynamic IPs report as disruptive.

What this means for you

Trade-only API keys are not safe on their own, exchange-side "key disabled" notices have lagged real revocation, and vendor denial during an incident is part of the damage. The mitigations that worked: immediate self-service key revocation, IP whitelisting, low balances, and custody models where keys never leave your control - run the checklist →