MEXC Hacker Uses AI Deepfakes to Steal $340,000 in Cryptocurrency
A recent incident at MEXC highlights the growing threat of AI-generated deepfakes in cryptocurrency security. An attacker used low-cost AI face-swapping technology to impersonate a user, passing the exchange's KYC review system and stealing $340,000 from the account.
The attack began when the attacker obtained the victim's personally identifiable information, likely through a data breach or social engineering attack. The attacker then generated an AI deepfake handheld video simulating the victim's facial features and movements, submitting an application to modify account information to MEXC.
MEXC's KYC system accepted this video verification, and the attacker successfully changed core security settings such as the account email and phone number. While taking control of the account, the attacker simultaneously created an API key with withdrawal permissions.
The victim discovered the anomaly and contacted MEXC, which confirmed the intrusion, froze the account, and restored the user's login credentials and two-factor authentication. However, the security team missed a crucial step: revoking the API key created by the attacker during the recovery process.