In December 2022, an anonymous account on Twitter claimed to be holding more than 100,000 stolen API keys connected to 3Commas, a popular crypto trading bot platform, and published 10,000 of them as proof. Users had already been reporting unauthorized trades on their exchange accounts for weeks. What followed was a case study in exactly the risk this blog keeps coming back to: what happens when a third-party tool has access to your exchange account, and something goes wrong.
The technical story is worth understanding on its own. How the company handled telling people about it is arguably the more important lesson.
What actually happened
Users on Binance, KuCoin, and Coinbase started noticing unusual trades on their accounts as early as November 2022. On December 9, Binance CEO Changpeng Zhao (CZ) publicly floated skepticism about the growing reports, noting there was no way to be certain users hadn't leaked their own keys. Two days later, 3Commas' CEO went further, dismissing the leaked screenshots circulating online as fabricated.
That denial held for seventeen days. On December 28, CZ posted again, this time telling his followers he was confident there were widespread API key leaks tied to 3Commas and urging anyone connected to revoke access immediately. Later that same day, 3Commas reversed course and confirmed the breach was real, asking the exchanges it integrated with to revoke connected keys on its behalf.
Trade-only keys limited the damage. They didn't prevent it.
Here's the detail that matters most for anyone evaluating a crypto automation tool: the leaked keys were largely trade-only, not withdrawal-enabled. That's exactly the distinction we've written about before, and it held up under a real attack. Attackers couldn't move victims' funds off the exchange directly, because the keys didn't have that permission.
What they could do instead was place trades inside those accounts: buying up thinly traded pairs the attacker already held a position in elsewhere, pushing the price up, and selling into the resulting volume. The victims' own accounts became the buying pressure in someone else's pump-and-dump. Individual users reported losses in the tens of thousands of dollars each, and total losses across affected accounts ran into the millions.
That's the honest version of the trade-only argument. It isn't that a trade-only key makes a breach harmless. It's that it changes the worst case from "your funds are gone" to "someone traded inside your account without permission," which is bad but recoverable, and which stops the moment the key is revoked. The 3Commas breach is a real-world confirmation of that distinction, not just a theoretical one.
The bigger failure wasn't the leak. It was seventeen days of denial.
Breaches happen. Any company holding API keys for tens of thousands of users is a target, and no security posture makes that risk zero. What's harder to excuse is a company publicly calling its own users' evidence fake for more than two weeks while people kept losing money on trades they never authorized.
If your exchange access is compromised through a tool you connected it to, what you actually need in that moment is fast, honest information: what happened, what's affected, and what to do right now. Seventeen days between the first credible warning and an actual confirmation is time during which every affected user's default move should have been "revoke and wait," and most of them didn't have the information to make that call.
That's arguably the more transferable lesson here. Security design determines how bad a breach can get. How a company behaves when something goes wrong determines how much worse it gets on top of that.
What to actually check before connecting a key to any tool
A few things worth asking about any crypto automation tool, including Rebalance:
Does it request withdrawal permissions, or only trade permissions? Any tool that only needs to place trades has no legitimate reason to ask for the ability to move your funds off the exchange.
If something did go wrong, would you find out from the company, or would you find out from your own account balance? A company's past incident history, if it has one, tells you more about this than its marketing copy does.
Can you revoke access instantly and independently, without needing the tool's cooperation? Your exchange's own settings should let you cut off a key at any time, regardless of what the connected app does on its end.
How Rebalance handles this
Rebalance connects to your exchange with trade-only permissions. Withdrawal access isn't something we request, ever, so it isn't a decision you have to trust us to get right; it simply isn't part of what the connection allows. Keys are encrypted and stored securely. You can revoke access from your exchange's side at any time, independent of anything happening on our end.
If a rebalance or a tax-loss harvest is about to execute, you see a preview first. And if something does happen with your account, automated actions and their outcomes are logged and emailed to you, not something you'd have to notice on your own by checking a balance.
None of that makes a breach impossible anywhere in the industry. It means that if one ever happens here, what's actually at risk is smaller, and you're not left waiting weeks to find out about it.
See how Rebalance handles account access on the security page, or start a 3-day free trial to see it firsthand. A payment method is required to start, but you won't be charged until the trial ends, and you can cancel anytime.