MEXC User Loses $340k After Unrevoked API Key Exploited in Previous Hack
A MEXC user reported losing $340,000 in cryptocurrencies after a hacker exploited an unrevoked API key. The breach occurred during a previous hacking incident on September 24, when the attacker created the API key just 83 seconds after logging into the compromised account.
The exchange had already detected and frozen the account, partially reversing the original hack. However, it failed to revoke the API key, which allowed the hacker to withdraw funds without needing two-factor authentication.
The user reset their password and unlinked the attacker's authenticator, but this process only activated a 24-hour withdrawal hold period. Twenty-seven minutes after the period expired, six transactions were executed in 13 minutes, with $322,110 USDT and $9,133,999 ONE sent to external addresses.
MEXC reported that it had reached a settlement with the defrauded user but did not disclose the terms of the agreement. The exchange noted that API keys operate independently from two-factor authentication and can be used for withdrawals without additional confirmation or whitelisting.