Dunamu Warns Even Read-Only API Key Lending Is Risky, Flags Social Media Scam
Summary
- Dunamu said users should beware of a new social media scam in which people ask to rent or buy Upbit accounts or API keys.
- It stressed that even API keys with simple read-only permissions can be misused for fraud or other improper activity, and that users should never hand over account information or keys to others.
- Dunamu said it will step up its response to attempts to obtain accounts and API keys through false or exaggerated advertising, and will strengthen monitoring to protect investors.
Forecast Trend Report by Period



Dunamu, the operator of Upbit, warned users to beware of a new scam in which fraudsters ask to borrow accounts or API keys under the pretense of checking market data.
The company said on October 8 that it had recently found numerous social media posts seeking to rent or buy accounts or read-only API keys that can access Upbit’s Korean won market. Those behind the posts say the credentials would be used only to view data, not for trading or deposits and withdrawals. But general price and market information can already be accessed through public APIs that do not require authentication, leaving no reason to provide a key.
An API key is authentication information that, depending on the permissions granted, can be used to view assets, orders, and deposit and withdrawal records or to access trading functions. Dunamu said even keys with read-only permissions can be misused for fraud or other improper activity, and stressed that users should never hand over account login information, API access keys, or secret keys to others.
If a key has been exposed or users suspect it has been leaked, it should be deleted immediately and reissued if necessary. The company also recommended deleting keys that are no longer in use or are not planned for future use. Suspicious solicitation activity or signs of harm can be reported to Upbit’s customer service center.
Upbit blocks withdrawals by default even when an API key has withdrawal permissions. Users can enable withdrawals only by turning on the feature themselves in the mobile app’s Open API Management menu. If an API call is attempted from an IP address that was not registered in advance, users receive a KakaoTalk alert message and can review the abnormal request before deleting the key.
Dunamu said it will step up its response to attempts to obtain accounts and API keys through false or exaggerated advertising. Accounts found to have been improperly rented out or used for suspicious activity will be suspended, and the company will request supporting documents. It also plans to refer cases to investigative authorities when necessary.
Handing over account information or an API key to someone else, even if they claim it is only for simple data inquiries, is like giving a stranger the key to your safe, a Dunamu official said. The company will strengthen monitoring to protect investors.
YM Lee
20min@bloomingbit.ioCrypto Chatterbox_ tlg@Bloomingbit_YMLEE