Official Wallsec emails only ever come from an @wallsec.co.uk address.
← All daily briefings

Mitigating Risks When Delegating API Keys to Third-Party Trading Platforms

Unauthorised account draining frequently occurs when investors grant excessive application programming interface permissions to automated trading software. Ensuring withdrawal rights remain disabled and monitoring account activity helps protect exchange-held digital assets.

  • Never enable withdrawal permissions on exchange application programming interface keys generated for external analytics, portfolio trackers, or automated algorithmic trading applications.
  • Restrict external keys to specific trusted internet protocol addresses whenever your exchange supports IP whitelisting to prevent compromised credentials from functioning elsewhere.
  • Delete dormant or unverified keys immediately and instruct your exchange compliance team to freeze trading credentials if unexpected automated transactions occur onchain.
  • Report unauthorised asset disposals to Action Fraud and inform your bank promptly if linked payment methods were used to purchase or replenish drained accounts.

Written by the Wallsec investigations team. General information only, not legal or financial advice.

Need a case reviewed?

Tell us what happened and we will say honestly whether the onchain data supports a trace.

Request a case review