MEXC User Loses $340,000 After Hacker Exploits Unrevoked API Key

Blockonomics
fiverr


  • A MEXC user lost $340,000 in 13 minutes through an API key created by a hacker during a breach that was never revoked.
  • The account had already been compromised and recovered, but the attacker’s API key remained active and allowed fund withdrawals without needing to bypass two-factor authentication.
  • MEXC reported reaching a settlement with the user and considers the case closed, but the terms of the agreement were not disclosed.

A user of the exchange MEXC operating on X as @shuangfei8 published a detailed account of how they lost $340,000 in cryptocurrencies without their password having been compromised or an active session detected.

According to their account, the wallet had previously been hacked on September 24, which MEXC detected, froze and partially reversed: the original email was restored and the user was helped to regain control. What the exchange did not revoke was an API key the attacker created at 21:05:42 on that same day, just 83 seconds after their second login into the compromised account.

The user reset their password, unlinked the attacker’s authenticator and registered a new one. That process activated a 24-hour withdrawal hold period under MEXC’s rules. Twenty-seven minutes after that period expired, six transactions were executed in 13 minutes: 322,110 USDT and 9,133,999 ONE sent to two external addresses. The user says they were asleep and that their history shows no login activity during that period.

MEXC Reaches a Settlement with the Defrauded User

API keys operate independently from two-factor authentication. A withdrawal made through one requires no additional code or email confirmation, meaning that changing the password and authenticator does not close that access channel. A statement from MEXC indicates that, by default, API withdrawals have no whitelist enabled and can be directed to any address.

Binance

mexc hackermexc hacker

The user notes that they had no way to detect the key on their own: when it was created, the linked email belonged to the attacker, so no notification reached them, and the security history visible to them shows no record of its creation.

MEXC reported hours after the public complaint that it had reached a settlement with the user. “The matter has been fully resolved,” the exchange declared on X, without disclosing the terms of the agreement.

The platform did not publicly respond as to whether the API key was the channel used for the withdrawals, nor did it explain why its emergency intervention restored the email without removing the other changes introduced by the attacker.

In January 2026, the Socket research team had documented a Chrome extension that silently created API keys on MEXC accounts, granted withdrawal permissions and sent the credentials to a Telegram bot controlled by the attacker.





Source link

Paxful

Be the first to comment

Leave a Reply

Your email address will not be published.


*