- A MEXC user lost $340,000 in 13 minutes through an API key created by a hacker during a breach that was never revoked.
- The account had already been compromised and recovered, but the attacker’s API key remained active and allowed fund withdrawals without needing to bypass two-factor authentication.
- MEXC reported reaching a settlement with the user and considers the case closed, but the terms of the agreement were not disclosed.
A user of the exchange MEXC operating on X as @shuangfei8 published a detailed account of how they lost $340,000 in cryptocurrencies without their password having been compromised or an active session detected.
According to their account, the wallet had previously been hacked on September 24, which MEXC detected, froze and partially reversed: the original email was restored and the user was helped to regain control. What the exchange did not revoke was an API key the attacker created at 21:05:42 on that same day, just 83 seconds after their second login into the compromised account.
大家好,我是MEXC被盗事件的当事人,以下是被盗事件经过
MEXC 确认我的账户被盗、冻结了账户、帮我找回——却漏掉了攻击者留下的 API。24 小时提币限制解除 27 分钟后,34 万美元资产被提空。
1/ 先说结果
2026 年 9 月 27 日 04:12–04:25(北京时间,下同),我的 MEXC 账户被提走 322,110 USDT 和… pic.twitter.com/e9xL5cAZs8— shuang fei (@shuangfei8) September 28, 2026
The user reset their password, unlinked the attacker’s authenticator and registered a new one. That process activated a 24-hour withdrawal hold period under MEXC’s rules. Twenty-seven minutes after that period expired, six transactions were executed in 13 minutes: 322,110 USDT and 9,133,999 ONE sent to two external addresses. The user says they were asleep and that their history shows no login activity during that period.
MEXC Reaches a Settlement with the Defrauded User
API keys operate independently from two-factor authentication. A withdrawal made through one requires no additional code or email confirmation, meaning that changing the password and authenticator does not close that access channel. A statement from MEXC indicates that, by default, API withdrawals have no whitelist enabled and can be directed to any address.


The user notes that they had no way to detect the key on their own: when it was created, the linked email belonged to the attacker, so no notification reached them, and the security history visible to them shows no record of its creation.
MEXC reported hours after the public complaint that it had reached a settlement with the user. “The matter has been fully resolved,” the exchange declared on X, without disclosing the terms of the agreement.
The platform did not publicly respond as to whether the API key was the channel used for the withdrawals, nor did it explain why its emergency intervention restored the email without removing the other changes introduced by the attacker.
In January 2026, the Socket research team had documented a Chrome extension that silently created API keys on MEXC accounts, granted withdrawal permissions and sent the credentials to a Telegram bot controlled by the attacker.





Be the first to comment