()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.

MEXC account hack: How did a user lose $340K?

Olivia Stephanie
Edited by
News
MEXC account hack: How did a user lose $340K?

MEXC has said it resolved a dispute involving a user who reported losing roughly $340,000 after an attacker allegedly retained API access following an account takeover.

Summary
  • MEXC says it reached agreement with the affected user and considers the matter fully resolved.
  • The user says 322,110 USDT and 9.13 million ONE were withdrawn after account recovery procedures.
  • MEXC documentation says frozen accounts invalidate associated API keys, raising questions about the reported API.
  • The reported withdrawals began 27 minutes after a 24-hour security lock expired on September 27.
  • MEXC has not publicly disclosed the settlement terms or confirmed whether the user received reimbursement.

Shuang Fei, the affected user, said 322,110 USDT and 9,133,999 ONE were withdrawn from the account between 04:12 and 04:25 Beijing time on September 27.

MEXC customer support later said the exchange had contacted the user and “successfully reached an agreement.” It described the matter as “fully resolved,” but did not disclose the terms, citing user privacy.

The exchange has not publicly stated whether the user was reimbursed, whether an API key initiated the withdrawals, or what happened to the reported stolen assets.

MEXC account hack began with a security reset

The reported incident began early on September 25 when Shuang Fei received an email stating that an application had been made to change the account’s linked email and remove Google Authenticator.

According to the user’s account, the request arrived at 03:10 Beijing time and was approved 10 minutes later. Shuang Fei said the application was unauthorized and claimed the identification photograph and verification video submitted with it were not genuine materials provided by the account holder.

MEXC later told the user that the materials had initially met its requirements, according to screenshots shared in the thread. During a subsequent review, the exchange detected risk, froze the account and restored the original email address, the user said.

MEXC’s current security reset documentation states that users may be asked to provide account information, identity documents and a video holding their identification when resetting security verification.

Once the attacker controlled the account, Shuang Fei said the password was reset and a new Google Authenticator was linked. Login records shared by the user showed access from an IP address associated with Jakarta, Indonesia.

At 05:05:42, an API was created, according to the user’s account. Shuang Fei said MEXC only disclosed the existence of that API after the funds had already left the account.

Account recovery did not address the reported API

MEXC froze the account at approximately 10:55 on September 25 after its review detected suspicious activity, the user said.

Shuang Fei regained control over the following day by removing the attacker’s Google Authenticator, changing the password and linking a new authenticator. The final change was completed at 03:45:07 on September 26.

MEXC documentation confirms that cryptocurrency and fiat withdrawals are blocked for 24 hours after certain security changes, including modifications to a linked email or Google Authenticator.

A separate MEXC account guide states that freezing an account disables trading and login functions and makes “all API keys associated with your account” invalid.

The user has questioned how the reported API could later have been used if it had become invalid during the account freeze.

“Did this API become invalid at that time?” Shuang Fei asked. The user separately questioned whether it became active again after the account was restored.

MEXC has not publicly answered those technical questions.

$340K left shortly after the withdrawal lock expired

At 04:12:45 on September 27, roughly 27 minutes after the user’s 24-hour withdrawal restriction ended, the first reported outgoing transaction moved 1 USDT.

Five more withdrawals followed within roughly 13 minutes, according to Shuang Fei. The transfers eventually removed 322,110 USDT and 9,133,999 ONE, which the user valued at approximately $340,000.

No fresh login appeared in the account’s login history during those withdrawals, the user claimed.

Security monitoring service CertiK subsequently reported the user’s account of the incident, including the allegation that an attacker-created API remained available and was connected to the withdrawals. CertiK did not independently establish the attack method in its brief notice.

Lookonchain likewise reported the claims and noted that the account showed no new login activity during the withdrawal period.

MEXC completed an initial investigation and offered what it called corresponding solutions, according to an earlier public response reported by BlockBeats. The exchange later said an agreement had been reached with the user.

MEXC API rules allowed withdrawals without a default whitelist

MEXC’s API withdrawal policy provides further context for the user’s questions. In a 2023 announcement, the exchange said withdrawal whitelists would not be enabled by default for API withdrawals, allowing withdrawals to any address unless a whitelist was activated.

The exchange advised API users to enable withdrawal whitelists and avoid disclosing API keys.

Current withdrawal documentation states that normal withdrawals may require email, mobile or Google Authenticator verification, while separate security settings can permit withdrawals under specified conditions without repeated two-factor authentication.

Shuang Fei said the attacker-created API was not visible in the security-operation history available to the user and claimed no notification was received because the account email had already been changed when the API was created.

The user asked MEXC to disclose the IP address used to create the API, its permissions, whether it became invalid while the account was frozen, and which channel initiated the six withdrawals.

The episode follows earlier scrutiny of MEXC’s account controls. In 2025, the exchange returned funds after a separate MEXC $3.15 million frozen-funds dispute involving trader The White Whale.

MEXC has since promoted several user-protection measures, including a planned $500 million Guardian Fund expansion announced in May 2026.

For the current case, MEXC’s public response remains limited. Customer support said the dispute has been resolved and that further details will not be disclosed because of user privacy.