Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

MEXC User Says He Lost $340,000 Through Hacker’s Unrevoked API Key

MEXC says it has reached an agreement with the user and considers the matter fully resolved, without disclosing terms.

Written By Dhara Chavda
Edited by Divya Mistry
Published 39 minutes ago·Updated 14 minutes ago
Make The Crypto Times preferred on GoogleGoogle
A hooded figure working on a laptop in front of an illuminated MEXC logo on a dark wall.
AI Summary
Show
User regained email after first breach, but attacker’s API key remained active, enabling later theft.
MEXC froze the account, restored email, but failed to revoke the attacker’s authenticator binding or API key.
Support claimed inability to trace withdrawal source, while the attacker exploited the undisclosed API key to move $340,000.

The account had already been hacked once. MEXC had caught it, frozen the account, restored the owner’s email, and helped him regain control. He changed his password, bound a new authenticator app, and waited out the exchange’s 24-hour withdrawal hold.

Twenty-seven minutes after that hold expired, $340,000 left the account anyway. He says it went through an API key the attacker created during the first breach, which nobody revoked and which MEXC never told him existed.

A MEXC user posting on X as @shuangfei8 published a detailed account on September 28, 2026, saying 322,110 USDT and 9,133,999 ONE were withdrawn in 13 minutes late on September 26, in six transactions to two addresses.

大家好,我是MEXC被盗事件的当事人,以下是被盗事件经过
MEXC 确认我的账户被盗、冻结了账户、帮我找回——却漏掉了攻击者留下的 API。24 小时提币限制解除 27 分钟后,34 万美元资产被提空。
1/ 先说结果
2026 年 9 月 27 日 04:12–04:25(北京时间,下同),我的 MEXC 账户被提走 322,110 USDT 和… pic.twitter.com/e9xL5cAZs8

— shuang fei (@shuangfei8) September 28, 2026

MEXC said hours later that it had reached an agreement with him and considers the matter fully resolved, declining to disclose the terms.

The First Breach

The account’s security operation history, in screenshots he published, records the sequence.

He says he received an email at 19:10 on September 24 stating that his account was “applying to reset security items,” specifically to change the bound email and unbind Google Authenticator, and that the request would be processed within one working day. Ten minutes later it was approved. He says he did not submit the application and that the identity photograph and handheld video used were not his.

MEXC customer service later told him in writing that the materials met requirements on first review, but that during a re-review the application was flagged as involving risk, the account was urgently frozen, and the email was rolled back to his original one.

The log shows the email change and authenticator unbinding at 19:20:37, both marked SYSTEM. A password reset follows at 19:22:56, an authenticator binding at 20:19:14, and a further password change at 21:03:30, all marked WEB. He says an API key was created in the account at 21:05:42—83 seconds after the attacker’s second login—which he learned only afterwards from customer service. No API creation entry appears in the history he published.

MEXC’s intervention came at 02:55:26 on September 25, roughly seven and a half hours after the account was taken, when the email was restored.

The Recovery That Left One Thing Behind

That intervention restored his email. On his account, it did not remove the attacker’s authenticator binding, the changed password, or the API key.

He unbound the attacker’s authenticator at 19:34:23 on September 25, reset the password at 19:41:56, and bound a new authenticator at 19:45:07. Under MEXC’s rules, changing security settings triggers a 24-hour withdrawal hold. He says he wanted to move his assets to safety and could not.

The hold expired at 19:45:07 on September 26. The withdrawal record shows the first transaction at 20:12:45, 27 minutes later: a single USDT sent to 0xd3f…96427.

Five more followed within 13 minutes, all to 0xc93…0c5Cf—97,189 USDT at 20:17:33, 97,180 at 20:18:28, 97,150 at 20:19:21, 30,590 at 20:20:54, and 9,133,999 ONE at 20:25:49. The USDT withdrawals total exactly 322,110. He says he was asleep and that his login history shows no new logins during the period.

Why One Key Was Enough

API keys authenticate directly. A withdrawal made through one requires no two-factor code and no email confirmation, which is why changing a password and rebinding an authenticator does not close that route.

MEXC’s April 2023 announcement states that by default the withdrawal whitelist is not enabled for API withdrawals, “i.e. you can withdraw to any address,” and that this applies both to existing keys and newly created ones. The exchange advised users to enable a whitelist and not to disclose their keys.

A separate MEXC account guide states that when an account is frozen, trading and login are disabled and “all API keys associated with your account will become invalid.” That passage describes the self-service Freeze Account function a user triggers from their own security settings, and MEXC has not said publicly whether the same applies to a risk-control freeze imposed by the exchange.

His question follows from those documents: if the freeze invalidated the key, how was it usable afterwards, and if it did not, what did the freeze cover?

He also says he could not have found the key himself. When it was created, the account’s bound email was the attacker’s, so no notification reached him, and the security history visible to him contains no record of its creation.

What MEXC Support Told Him

In the chat screenshots the user published, MEXC customer service says it cannot directly view or confirm which terminal or channel initiated the withdrawals and cannot determine from the withdrawal record alone whether they came from the app, the web interface, or the API. Support said the question had been escalated and that a reply would follow by email under ticket M2026092712031, expected within 24 hours.

He has also published what he says is a police report filed at 03:16:44 on September 28, recording a complaint that virtual currency was stolen from an account at MEXC.

Escalation, Then Agreement

MEXC Customer Support first replied publicly on X, saying the platform takes the matter very seriously and that the incident had been escalated to its security team for a dedicated investigation, with interim updates to follow. It recommended he report the matter to local judicial authorities and said that if police or judicial authorities require information on relevant accounts, transactions, and fund flows, MEXC “will actively cooperate in accordance with the law, providing relevant chain data and evidence support within the scope of our authority.”

您好,关于您反馈的账户资产异常转出一事,平台高度重视。目前该事件已升级至安全团队进行专项调查。

如有阶段性调查进展,我们将第一时间与您同步。…

— MEXC Customer Support (@MEXC_CST) September 28, 2026

Hours later the exchange said the case was closed. “Following the incident, we reached out to the user immediately and have successfully reached an agreement,” it said. “The matter has now been fully resolved. To protect user privacy, we are unable to disclose specific details of the resolution.”

MEXC said it places the highest priority on the security of users’ accounts and assets and has always upheld a user-first approach, adding that it remains committed to prioritizing user asset security and fulfilling its responsibilities to its community.

What Remains Unanswered

The settlement resolves one user’s claim. It does not address the questions his account raised.

MEXC has not said publicly whether an API key was the route the funds took, whether a key created by an attacker survived the account freeze, why its emergency response restored the email without revoking the attacker’s other changes, or why the creation of an API key did not appear in the security history visible to the account holder.

One step is available to any MEXC user in the meantime: open API Management and review the list for keys you did not create. API keys with withdrawal permissions are a known attack surface on the exchange. In January 2026, Socket’s threat research team documented a Chrome extension that silently created MEXC API keys, enabled withdrawal permissions, manipulated the interface so the permission appeared disabled, and sent the credentials to an attacker-controlled Telegram bot. That campaign has not been connected to this case.

Also Read: ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto ExchangeCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
Michael Saylor speaking in front of a Strategy brand backdrop with an integrated Bitcoin logo.
1,665 BTC Added: Strategy’s Bitcoin Treasury Reaches 847,666 Coins with Latest Purchase
The Citi and Coinbase logos displayed side by side against a blue gradient background.
Citi Expands Coinbase Deal to Let Corporates Accept Stablecoin Payments
India's ED Expands Crypto & Cyber Tracing Under Renewed NFSU Pact
India’s ED Expands Crypto & Cyber Tracing Under Renewed NFSU Pact
ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea
ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea

Find Us on Socials

You may also like

A gloved hand holding a smartphone displaying the Bitget logo in front of a hooded, shadowed figure.

Bitget Resumes BTC Withdrawals Four Days Following $387.5M Hack

A glowing red "FAKE" block chained between blue "GIWA" blockchain blocks, topped with Ethereum tokens.

Fake GIWA Chain Drained 766 ETH After 1,335 Addresses Bridged Into It

An illuminated 3D THORChain logo mounted on a dark wall under spotlights.

THORChain Rejects Bitget CEO’s Request to Block $387.5M Hacker Wallets

Crypto Week Ahead: PCE, Jobs Report & Korea Blockchain Week

Crypto Week Ahead: PCE, Jobs Report & Korea Blockchain Week 

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information