X user alleges $340,000 loss on MEXC after attacker-created API remained active

X user alleges $340,000 loss on MEXC after attacker-created API remained active

N
News Editor
2026-09-28 06:55:49
An X user, @shuangfei8, said roughly $340,000 was withdrawn from a MEXC account after an attacker allegedly reset key security settings and created an API key that remained usable even after the account was frozen and later restored. According to the user, the incident began early on Sept. 25, when forged identity documents were used to request a reset of account protections, including an email change and removal of Google Authenticator. The request was approved within 10 minutes, and the attacker controlled the account for about 7.5 hours, resetting the password, binding Google Authenticator and creating an API. The user said MEXC later identified the risk, froze the account and restored the original email address, but did not revoke the API. After the user changed the password and rebound Google Authenticator as requested, a 24-hour withdrawal restriction applied. Between 04:12 and 04:25 Beijing time on Sept. 27, about 27 minutes after the restriction was lifted, 322,110 USDT and 9,133,999 ONE were withdrawn, with no new login record shown during the transfers. MEXC said it had completed a preliminary review, provided a corresponding solution, and would continue one-to-one communication by email.

BlockBeats reported on Sept. 28 that X user @shuangfei8 said a MEXC account was compromised, with losses of about $340,000.

According to the user, early on Sept. 25 an attacker used forged identification materials to successfully request a reset of account security settings, including changing the linked email address and removing Google Authenticator. The request was approved within 10 minutes. The attacker then controlled the account for about 7.5 hours, during which time the password was reset, Google Authenticator was rebound, and an API was created.

The user said MEXC later identified the risk during a review, froze the account, and changed the email address back to the original one. However, the exchange allegedly did not revoke the API created by the attacker. After that, the account owner changed the password and rebound Google Authenticator as requested, but the account was subject to a 24-hour withdrawal restriction.

The user said that between 04:12 and 04:25 Beijing time on Sept. 27, roughly 27 minutes after the withdrawal restriction was lifted, 322,110 USDT and 9,133,999 ONE were withdrawn from the account, for a combined value of about $340,000. The user added that no new login record appeared during the withdrawal window.

The account owner also said MEXC's help center states that associated APIs should become invalid after an account is frozen, but that did not happen in this case. The user also said API withdrawals do not require Google Authenticator or email verification.

The user said a formal compensation claim has been submitted to MEXC and that an attempt has been made to report the matter to police. The user is asking the platform to preserve logs, provide written answers to related questions, and return the assets. The post also urged other users to check their API management page for abnormal keys.

In response, MEXC said: "A preliminary investigation has been completed and a corresponding solution has been provided. To better protect the account and personal information, follow-up communication will be conducted one-on-one by email, and related handling progress and required information will be provided at the same time. Users are advised to watch their registered email inbox and official channel emails."

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.