Dunamu, the operator of the digital asset exchange Upbit, recently stated that messages requesting the “rental or purchase of API keys and accounts” spreading across social media are a new type of scam. API keys are critical authentication information that, depending on the permissions granted, allow access to a user’s assets, orders, deposit/withdrawal details, or trading functions.

Dunamu announced on the 8th, “We have detected multiple cases where scammers approach investors on social media, claiming, ‘We rent or purchase Upbit accounts with access to the KRW market or API keys granted only read-only (Read-Only) or inquiry permissions.’” The company emphasized, “Although they claim, ‘We will not deposit, withdraw, or trade funds and will use the data only for legitimate market analysis,’ these requests are entirely false.” This is because general market data and prices on Upbit are publicly accessible without requiring authentication.

Dunamu warned, “If an API key is leaked, it can be exploited for fraud or unauthorized transactions, leading to financial losses,” and added, “Under no circumstances should you lend your account to others or share open API keys.” If an API key is exposed or suspected of being leaked, the key must be immediately deleted and a new one issued. Unused API keys should also be deleted.

A source from Dunamu stated, “Handing over your account information or API key to others, even if they claim it’s for simple inquiry purposes, is like giving a stranger the key to your safe.” The company added, “We will respond strictly, without tolerance, to any suspicious activities that harm members by promoting unverified services or requesting accounts and API keys through false or exaggerated advertisements.”

Leave a comment

Trending