MEXC has confirmed that an API key left on a compromised account allowed an attacker to drain roughly $340,000 from it and says it has fully compensated the user.
The confirmation matters because until now the exchange had not said how the funds left. Its customer support team told the account holder it could not determine whether the withdrawals came from the app, the web interface, or an API, and its public statements described only an agreement reached and a matter resolved.
Vugar Usi Zade, MEXC’s chief executive, set out the sequence in a post on X on September 28, 2026. Customer service identified the compromise quickly and froze the account, he said, and MEXC then worked with the user to restore the original email and authenticator, helping secure the account and prevent further risk.
“Unfortunately, an API key that remained on the account allowed the attacker to transfer the funds before the issue could be fully contained,” he wrote.
Zade said the investigation into exactly what happened is continuing, but that one thing was clear to the company: “We do not believe the user should have to bear the consequences of this incident.” MEXC immediately assembled a dedicated team to handle the case and has fully compensated the user, he said.
“We have always believed that being user-first means more than just saying it,” he wrote. “When our users need us to step up, we will.” He thanked the user for giving the team time to work through the matter and said the company would keep learning and improving.
What the User Reported
The statement follows an account published by the account holder, posting on X as @shuangfei8, who said 322,110 USDT and 9,133,999 ONE were withdrawn from his account in 13 minutes on September 26, in six transactions to two addresses.
By his account, the withdrawals began 27 minutes after a 24-hour security hold expired. That hold had been triggered when he reset his password and bound a new authenticator, steps he took after MEXC froze the compromised account and restored his email.
He said the API key had been created by the attacker during the earlier breach, that it was never revoked when the account was frozen and restored, and that he had no way of knowing it existed, because the account’s email had been changed to the attacker’s at the time and no record of the key’s creation appeared in the security history visible to him.
What Remains Unexplained
Zade’s statement confirms the mechanism but not the process failure behind it.
MEXC has not said why its emergency response restored the account’s email without revoking the attacker’s other changes, whether the key survived the account freeze, or why the creation of an API key did not appear in the security history the account holder could see. Its earlier statement said that to protect user privacy it could not disclose the details of the resolution.
The exchange’s own account guide states that freezing an account renders all API keys associated with it invalid, though that passage describes the self-service freeze a user triggers from their security settings rather than a risk-control freeze imposed by the exchange.
Also Read: SlowMist Warns Apple Zero-Day May Put Crypto Wallet Data at Risk
