The account had already been hacked once. MEXC had caught it, frozen the account, restored the owner’s email, and helped him regain control. He changed his password, bound a new authenticator app, and waited out the exchange’s 24-hour withdrawal hold.
Twenty-seven minutes after that hold expired, $340,000 left the account anyway. He says it went through an API key the attacker created during the first breach, which nobody revoked and which MEXC never told him existed.
A MEXC user posting on X as @shuangfei8 published a detailed account on September 28, 2026, saying 322,110 USDT and 9,133,999 ONE were withdrawn in 13 minutes late on September 26, in six transactions to two addresses.
MEXC said hours later that it had reached an agreement with him and considers the matter fully resolved, declining to disclose the terms.
The First Breach
The account’s security operation history, in screenshots he published, records the sequence.
He says he received an email at 19:10 on September 24 stating that his account was “applying to reset security items,” specifically to change the bound email and unbind Google Authenticator, and that the request would be processed within one working day. Ten minutes later it was approved. He says he did not submit the application and that the identity photograph and handheld video used were not his.
MEXC customer service later told him in writing that the materials met requirements on first review, but that during a re-review the application was flagged as involving risk, the account was urgently frozen, and the email was rolled back to his original one.
The log shows the email change and authenticator unbinding at 19:20:37, both marked SYSTEM. A password reset follows at 19:22:56, an authenticator binding at 20:19:14, and a further password change at 21:03:30, all marked WEB. He says an API key was created in the account at 21:05:42—83 seconds after the attacker’s second login—which he learned only afterwards from customer service. No API creation entry appears in the history he published.
MEXC’s intervention came at 02:55:26 on September 25, roughly seven and a half hours after the account was taken, when the email was restored.
The Recovery That Left One Thing Behind
That intervention restored his email. On his account, it did not remove the attacker’s authenticator binding, the changed password, or the API key.
He unbound the attacker’s authenticator at 19:34:23 on September 25, reset the password at 19:41:56, and bound a new authenticator at 19:45:07. Under MEXC’s rules, changing security settings triggers a 24-hour withdrawal hold. He says he wanted to move his assets to safety and could not.
The hold expired at 19:45:07 on September 26. The withdrawal record shows the first transaction at 20:12:45, 27 minutes later: a single USDT sent to 0xd3f…96427.
Five more followed within 13 minutes, all to 0xc93…0c5Cf—97,189 USDT at 20:17:33, 97,180 at 20:18:28, 97,150 at 20:19:21, 30,590 at 20:20:54, and 9,133,999 ONE at 20:25:49. The USDT withdrawals total exactly 322,110. He says he was asleep and that his login history shows no new logins during the period.
Why One Key Was Enough
API keys authenticate directly. A withdrawal made through one requires no two-factor code and no email confirmation, which is why changing a password and rebinding an authenticator does not close that route.
MEXC’s April 2023 announcement states that by default the withdrawal whitelist is not enabled for API withdrawals, “i.e. you can withdraw to any address,” and that this applies both to existing keys and newly created ones. The exchange advised users to enable a whitelist and not to disclose their keys.
A separate MEXC account guide states that when an account is frozen, trading and login are disabled and “all API keys associated with your account will become invalid.” That passage describes the self-service Freeze Account function a user triggers from their own security settings, and MEXC has not said publicly whether the same applies to a risk-control freeze imposed by the exchange.
His question follows from those documents: if the freeze invalidated the key, how was it usable afterwards, and if it did not, what did the freeze cover?
He also says he could not have found the key himself. When it was created, the account’s bound email was the attacker’s, so no notification reached him, and the security history visible to him contains no record of its creation.
What MEXC Support Told Him
In the chat screenshots the user published, MEXC customer service says it cannot directly view or confirm which terminal or channel initiated the withdrawals and cannot determine from the withdrawal record alone whether they came from the app, the web interface, or the API. Support said the question had been escalated and that a reply would follow by email under ticket M2026092712031, expected within 24 hours.
He has also published what he says is a police report filed at 03:16:44 on September 28, recording a complaint that virtual currency was stolen from an account at MEXC.
Escalation, Then Agreement
MEXC Customer Support first replied publicly on X, saying the platform takes the matter very seriously and that the incident had been escalated to its security team for a dedicated investigation, with interim updates to follow. It recommended he report the matter to local judicial authorities and said that if police or judicial authorities require information on relevant accounts, transactions, and fund flows, MEXC “will actively cooperate in accordance with the law, providing relevant chain data and evidence support within the scope of our authority.”
Hours later the exchange said the case was closed. “Following the incident, we reached out to the user immediately and have successfully reached an agreement,” it said. “The matter has now been fully resolved. To protect user privacy, we are unable to disclose specific details of the resolution.”
MEXC said it places the highest priority on the security of users’ accounts and assets and has always upheld a user-first approach, adding that it remains committed to prioritizing user asset security and fulfilling its responsibilities to its community.
What Remains Unanswered
The settlement resolves one user’s claim. It does not address the questions his account raised.
MEXC has not said publicly whether an API key was the route the funds took, whether a key created by an attacker survived the account freeze, why its emergency response restored the email without revoking the attacker’s other changes, or why the creation of an API key did not appear in the security history visible to the account holder.
One step is available to any MEXC user in the meantime: open API Management and review the list for keys you did not create. API keys with withdrawal permissions are a known attack surface on the exchange. In January 2026, Socket’s threat research team documented a Chrome extension that silently created MEXC API keys, enabled withdrawal permissions, manipulated the interface so the permission appeared disabled, and sent the credentials to an attacker-controlled Telegram bot. That campaign has not been connected to this case.
Also Read: ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea
