Dunamu urged investors to be cautious about requests spreading mainly on social media to lend or purchase accounts and API keys.
Dunamu said on Oct. 8 it has confirmed many cases of approaches to investors offering to borrow or buy accounts that can access Upbit's won (KRW) market, or read-only API keys that grant only inquiry permissions.
They explain they will not use deposit, withdrawal or trading functions and will use them only to view market data, but Dunamu said that claim is not true.
Upbit's standard prices and market data can be checked through public APIs that do not require separate authentication, so there is no need to obtain an account or API key for price checks, it said.
API keys are authentication information that, depending on granted permissions, can be used to view a member's assets, orders and deposit and withdrawal information, or to access actual trading functions. If account login information or API keys are leaked externally, they could be misused for fraud, improper use or asset theft.
Dunamu stressed that users must not lend their Upbit accounts to others or provide the open API access key and secret key for any reason.
It said users should immediately delete a key if it is exposed or suspected of being leaked, and issue a new key if necessary. It recommended deleting API keys that have not been used for a long time or are not planned to be used in the future to reduce leak risks.
It is also strengthening API-related security features as new types of scams, such as QR-code phishing known as "Qishing", increase.
Upbit blocks withdrawals by default even if an API key includes the "withdraw" permission. For an actual withdrawal, the user must enable the withdrawal approval function directly in the mobile app under "More-Security verification-Open API management".
If an API call occurs from an unregistered internet protocol (IP) address, Upbit allows users to check it through a KakaoTalk alert message. If access that the user did not request is found, the user can check the connection IP environment and delete the relevant API key in the mobile app.
It will also strengthen its response to acts that demand users' accounts and API keys by promoting false or exaggerated advertisements or unverified services.
If related acts are detected, it plans to immediately suspend member accounts used for suspicious activity or improperly lent out and request supporting materials. If necessary, it also plans to report cases to investigative authorities.
A Dunamu official said, "Handing over your account information or API key to someone else is like giving the key to your safe to a stranger." The official said, "We will continue to put investor protection first, strengthen monitoring and do our best to keep members' assets safe."