Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Cryptohopper AI Signal Clone - Impersonating Official Subscription Services to Harvest and Cross-Trade API Keys

Victims are mostly crypto retail investors new to automated trading, aged 20 to 40, who have a preliminary awareness of the Cryptohopper brand but lack API permission management and fund security experience. These users generally hope to obtain stable signals through a low-cost subscription, while harboring a quick-recovery mindset, making them easily swayed by forged live-trading screenshots and limited-time discount pitches. Some victims held substantial spot balances on platforms like Binance or Coinbase, but failed to enable withdrawal whitelists or independent transaction passwords, leading to their accounts being directly manipulated after authorization.

SCAM

Key Fields

FIELD STAMPS
IndustrySaaS / Enterprise Software
RegionGlobal
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Victims are mostly crypto retail investors new to automated trading, aged 20 to 40, who have a preliminary awareness of the Cryptohopper brand but lack API permission management and fund security experience. These users generally hope to obtain stable signals through a low-cost subscription, while harboring a quick-recovery mindset, making them easily swayed by forged live-trading screenshots and limited-time discount pitches. Some victims held substantial spot balances on platforms like Binance or Coinbase, but failed to enable withdrawal whitelists or independent transaction passwords, leading to their accounts being directly manipulated after authorization.

骗局怎么运作

  • Fraudsters deploy clone services named Cryptohopper AI Signal in Telegram groups or YouTube ads, using avatars, domain names, and promotional materials similar to the official ones, claiming to provide 24-hour AI quantitative signals with monthly fees of only 29 to 99 US dollars. The pitches emphasize official endorsement and historical backtested win rates, inducing users to click short links to enter fake landing pages.
  • The fake landing page requires users to register and link their exchange account, guiding them to create API keys with trade and withdrawal permissions while disabling IP whitelist restrictions. Under the pretext of authorizing signal push notifications, the page asks users to copy and paste the API Key and Secret into the clone backend while promising not to touch user funds.
  • After obtaining API permissions, the clone backend does not provide any real AI signals. Instead, it uses scripts to execute small, high-frequency cross-trades within the user's account—simultaneously placing buy and sell orders and executing them against each other—to create the illusion of activity and consume transaction fees. Some scripts also pump or dump prices on low-liquidity coins.
  • When users check their exchange statements, discover abnormal transactions, and attempt to contact customer service, the clone's support uses excuses like system delays or AI model parameter tuning, while inducing users to deposit additional funds to unlock so-called advanced signals. If the user refuses, support directly closes the chat session and disbands the community.
  • Finally, after accumulating enough victims, the fraudsters centrally initiate large-scale withdrawals or asset transfers, rapidly operating multiple accounts during late-night hours using the previously collected API permissions. Because some users failed to set up withdrawal whitelists, their assets were transferred out within minutes, and the clone website was subsequently shut down.

红旗信号(看到这些快跑)

  • 🚩 Demanding API Key and Secret while disabling IP whitelists, claiming it is only for signal subscription yet requiring full trading permissions
  • 🚩 Subscription links coming from Telegram private chats or URL shortener redirects rather than the official cryptohopper.com domain
  • 🚩 Yield screenshots displaying overly smooth curves or double-your-money data over fixed periods that cannot be verified on third-party platforms
  • 🚩 Customer service evading questions about the scope of API permissions when discussing fund security, repeatedly emphasizing regular returns rather than risk disclosures
  • 🚩 Demanding upfront deposits to unofficial designated addresses or so-called margin accounts to activate AI signals

真实案例

  • In October 2024, a user clicked a Cryptohopper AI signal promotion link in a Telegram group, linked their Binance account and enabled withdrawal permissions. Within three days, 47 imperceptible small cross-trades occurred in the account, resulting in a fee loss of about 320 USDT, after which the user received an invitation from clone support to deposit more funds.
  • In June 2025, a developer provided KuCoin API keys in a Discord channel impersonating a Cryptohopper signal service. Just two hours later, they found that about 1,800 USDT in their account had been swapped for low-liquidity tokens and withdrawn in batches; the channel was subsequently untraceable.
  • In November 2025, a cross-border payments professional registered on a clone named Cryptohopper Signal Pro guided by a YouTube ad, followed page instructions to disable Coinbase's IP whitelist, and the next morning found ETH and USDC in the account cleared out, resulting in a loss equivalent to about 5,300 US dollars.
  • In March 2018, multiple Binance exchange users employing third-party trading bot services suffered API key leakage and asset theft. Attackers holding keys with trade-only permissions could not withdraw directly, so they instead pre-pumped the minor coin Viacoin, then manipulated victim accounts to buy high at market peaks, completing cross-trades to siphon profits. The attackers walked away with over 60 Bitcoins starting from a small capital base, while victim accounts suffered massive losses due to high-position buying. (Source: [https://hackernoon.com/how-your-trading-api-keys-can-be-used-to-drain-your-funds-f9148d1e6d33](https://hackernoon.com/how-your-trading-api-keys-can-be-used-to-drain-your-funds-f9148d1e6d33))
  • In September 2026, trading bot platform Bitsgap cited a mid-2026 report by SlowMist disclosing that a total of 182 security incidents occurred in the industry between January and June 2026, of which 17 explicitly involved private key or credential leaks, cumulatively causing about 130 million US dollars in losses. Common tactics included phishing messages impersonating customer service and fake technical support personnel directly soliciting API keys; even keys granted only trading permissions were used to place manipulative orders for cross-trading profits. (Source: [https://bitsgap.com/zh/blog/api-mi-yao-xie-lu-li-ji-cai-qu-de-cuo-shi](https://bitsgap.com/zh/blog/api-mi-yao-xie-lu-li-ji-cai-qu-de-cuo-shi))

Official Stance

  • On August 20, 2025, Rapid7 released a report disclosing Operation ASTERIX, pointing out that AI-driven cryptocurrency phishing campaigns were stealing exchange API keys and executing automated fund transfers, warning users to verify the domain names and permission scopes of signal subscription platforms.
  • In December 2025, the Supreme People's Procuratorate mentioned in a notification on new types of illegal business cases that manipulating quantitative trading software has been characterized as illegal operation, emphasizing that any unauthorized automated trading tool used for cross-trading or market manipulation may involve criminal liability.
  • In January 2026, the Cyberspace Administration of China issued a notice regarding the illegal operation of AI large model API interfaces, warning that certain fake technology platforms use free trials or high-yield signals as bait to harvest user keys, constituting a major threat to personal information and fund security.

How to Protect Yourself

  • ✅ Create API keys only under Cryptohopper's official documentation and website guidance, disable withdrawal permissions, and set up IP whitelists, avoiding pasting Secrets into any third-party web pages.
  • ✅ Remain vigilant against Cryptohopper signal subscription links appearing in Telegram and Discord, confirm whether the service exists via the official support center first, and do not click unfamiliar shortened URLs.
  • ✅ Regularly check the API key list and recently logged-in devices in the exchange backend, immediately delete unfamiliar authorizations, and enable withdrawal address whitelists and independent fund passwords.
  • ✅ Do not believe high-return promises based on screenshots or copy-trading yield displays; all automated trading strategies should be verified for at least a month in paper trading or with minimal funds.