Our third-party email service provider has experienced a security breach.
If you received an email titled “Data Breach Notice: Please refresh API Keys as soon as possible”, that email was not sent by CoinTracking. It is a phishing attempt.
What you should do
- Do not click any links contained in that email.
- Do not enter your CoinTracking login details, API keys or any other credentials on any page that email links to.
- Delete the email.
If you already clicked the link
If you followed the link and entered any information, change your CoinTracking password immediately. If you entered exchange API keys, revoke and regenerate them directly at the exchange that issued them – never through a link in an email.
What happens next
We are currently investigating the incident and will provide further information as soon as it becomes available. This page will be updated as we learn more.
Last updated: 9 September 2026