Dunamu, the operator of South Korean crypto exchange Upbit, has warned users about a scam campaign seeking account access and API credentials under the pretense of checking market data. The company said it recently identified many social media posts offering to rent or buy Upbit accounts or read-only API keys tied to the exchange’s Korean won market.
According to Dunamu, the posts typically claim the credentials would be used only to view data rather than to trade or move funds. The company said that explanation does not hold up because basic price and market information is already available through public APIs that do not require authenticated access.
Why Dunamu says the pitch is suspicious
Dunamu said there is no legitimate reason to hand over authenticated credentials for simple market checks. Public API endpoints already provide general price and market data without requiring users to share account-linked information.
The company said an API key is a form of authentication that can grant access, depending on the permissions attached, to asset balances, order history, and deposit or withdrawal records, and in some cases to trading functions. For that reason, it said users should never share account login details, API access keys, or secret keys with third parties.
Even read-only access carries risk
A central part of the warning is that limited-permission keys are not harmless. Dunamu said even read-only API keys can be abused for fraud or other improper activity, despite claims that they cannot be used for trading or withdrawals.
The company urged users to act quickly if they believe a key has been exposed. Any leaked or suspected leaked key should be deleted immediately and reissued only if needed. Dunamu also recommended removing API keys that are no longer being used or are not expected to be used in the future.
Existing safeguards and reporting steps
Dunamu noted that Upbit blocks withdrawals by default, even when an API key has withdrawal permissions available. Users must manually enable that feature themselves through the Open API Management menu in the mobile app.
The company also said that if an API request comes from an IP address that was not registered in advance, the user receives a KakaoTalk alert. That notice allows the user to review the abnormal request and delete the key if necessary.
Users who encounter suspicious solicitation or believe they may have suffered harm were told to report the matter to Upbit’s customer service center.
Stronger enforcement and what comes next
Dunamu said it will intensify its response to attempts to obtain accounts and API keys through false or exaggerated advertising. It also warned that accounts found to have been rented out improperly or linked to suspicious activity will be suspended.
In such cases, the company said it may request supporting documents and, when necessary, refer matters to investigative authorities. In its warning, Dunamu compared handing over account information or an API key for supposed data inquiries to giving a stranger the key to a safe, underscoring that the next confirmed step is tighter monitoring and enforcement by the exchange operator.
Source: en.bloomingbit.io