$340K Lost in MEXC Account Hack Amid Questions Over API Security
A MEXC user reported losing $340K after an attacker allegedly retained API access following an account takeover.
The incident began on September 25 when Shuang Fei, the affected user, received an email stating that an application had been made to change the account's linked email and remove Google Authenticator. The request was approved 10 minutes later, but Shuang Fei claimed it was unauthorized and not genuine.
MEXC initially met the attacker's requirements for resetting security verification, but during a subsequent review, they detected risk and froze the account, restoring the original email address. Once the attacker controlled the account, they reset the password and linked a new Google Authenticator.
The reported API was created at 05:05:42, according to Shuang Fei's account, but MEXC only disclosed its existence after the funds had already left the account. The user regained control of their account by removing the attacker's Google Authenticator, changing the password, and linking a new authenticator.
The withdrawals began 27 minutes after a 24-hour security lock expired on September 27, with 322,110 USDT and 9,133,999 ONE being withdrawn. MEXC has not publicly disclosed the settlement terms or confirmed whether the user received reimbursement.