I don't think this incident did any harm to exchange-api users.
As far as I understand, the problem was mainly that some leaked data got cached on some search engines like google and was therefor longer available and publicly readable.
But as an user of exchange api's this would not affect us, because api calls are surely not indexed by spiders. I this incident is more of a problem for "normal sites". But I could be wrong here.
Some other things to put into perspective:
- Only sites which used cloudflare are possibly affected. (
Here a list of possibly affected sites).
In our CAT perspective: Possibly affected: btc-e.com, poloniex.com, kraken.com.
All other trading sites, f.e. bitstamp.net, bittrex, bitfinex are surely not affected.
- The greatest period of impact was from February 13 and February 18 with around 1 in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (thats about 0.00003% of requests).
Meaning: If you didn't use CAT on this timespan on the mentioned exchanges there was most surely no leak of your data.
As you can also see, only 0.00003% of requests were affected by this leak. It is highly inlikely that someone of here was even inside those requests.
And even if they were, those requests must have been captured or cached to become a serious problem. The probability for that is even smaller.
- If you have withdrawal disabled on your api key, any possible leak could not directly steal any funds from you. The only thing an attacker could do is buy/sell coins on your behalf, but they would still remains on your account. It is not even sure, that anyone was/is trying to make profit of this leak. I would really doubt that anyone would just messing around with some unknown trading portfolio if he can't use the fund for himself afterwards.
So, as far as I can see, only 3 sites from here are affected and it's highly unlikely to be even a real problem.
I don't think its necessary to change the keys. If your paranoid you can change btc-e, polo and kraken if you used them in the mentioned timespan.
Just my two cents.