FINANCE

Bithumb warns of fake AI trading malware promising high returns

by
Kyoung Ye-eun
Published : Sept. 10, 2026 - 09:05:30
    • Copy Completed!

View Korean Original

September Information Protection Day campaign

Bithumb advises blocking withdrawal permissions and immediately discarding exposed API keys

[Courtesy of Bithumb]
[Courtesy of Bithumb]

Bithumb said Thursday that it is running a campaign to prevent malware damage from fake artificial intelligence auto-trading programs and investment analysis tools, marking Information Protection Day in September.

Cases have recently emerged in which scammers lure investors with claims such as "AI trades automatically for high returns" or "connect your API key for loss-free automatic trading," only to induce them to install unauthorized malware that steals sensitive information.

Such malware carries a high risk of leaking not only usernames, passwords and login session cookies stored in browsers but also the private keys and seed phrases of personal wallets. Attackers have been found to use stolen login sessions to access user accounts without passwords, or to exploit API key permissions to siphon off assets without authorization.

Bithumb urged users not to download unauthorized programs distributed as executable or compressed files through search ads, SNS or messenger links. It added that users should exercise caution even with websites disguised as legitimate services if the distribution path is unclear.

For automatic trading, users should rely only on official services, and it is advisable not to grant withdrawal permissions even when issuing an API key, Bithumb said. Users should allow only essential permissions such as viewing or ordering, and immediately discard any key that is unused or has been exposed externally, the exchange explained.

In particular, Bithumb warned users never to directly enter information that grants asset access — such as API keys, private keys or seed phrases — into external programs, websites or AI services.

If an unauthorized program has been installed and an unfamiliar browser extension is added, or a notification about changed security settings appears, users should immediately suspect a malware infection. They should disconnect from the internet and, using a separate device, change their passwords, delete API keys and check withdrawal addresses.

"Unauthorized information-stealing malware that exploits expectations around AI and the psychology of chasing high returns is running rampant," a Bithumb official said. "We will strengthen our security systems and expand our prevention campaigns so that users can safely use official AI services."

Meanwhile, Bithumb released a guide on preventing AI supply chain attacks last month as part of its information protection campaign. A supply chain attack refers to a method in which malicious code is planted during the software development process, and Bithumb stressed that users should verify a program's official developer name before installing it.


kyoung@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ