Crypto Exchanges' API Key Defaults Leave Investors Vulnerable
An API key on a crypto exchange is not like a password - it's a power of attorney that grants specific rights to external software. German investors use these keys for tax tools, portfolio trackers, and trading bots, but often hand over more rights than necessary.
After a phishing wave in September targeted API keys, exchanges were advised to change passwords, enable two-factor authentication, and revoke old API keys. However, many investors are unsure how many keys they have handed out over the years.
We examined the publicly available documentation of eight providers and tools, including Kraken, Bitvavo, and Binance. The findings show that all three exchanges separate reading, trading, and withdrawing into individual rights, but with varying levels of detail.
Kraken offers the finest breakdown, separating rights for querying funds, depositing funds, withdrawing funds, and modifying orders. It also allows an expiry date for keys, including short periods like a week.
Bitvavo knows three rights: viewing account data and balances, trading, and withdrawing to an external address or verified bank account. The provider's help page warns that withdrawals requested through an API key bypass the two-factor prompt.
Binance separates reading, spot, and margin trading into switches of their own, with a peculiar rule that trading rights expire after 90 days without an IP address.
Even without withdrawal rights, a stolen key can still cause damage. Attackers can turn keys into money by trading foreign balances against orders in thinly traded markets.