MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze

1 week ago 10



An attacker drained roughly $340,000 from the account of a user of the crypto exchange MEXC, even though the account had already been flagged as compromised, frozen and handed back to its owner. The route in was an API key the attacker had created during the takeover and which the exchange failed to revoke when it restored the account. MEXC admitted exactly that in public on September 28 and 29, 2026, and says it has reimbursed the loss in full. This is not an exchange hack in the usual sense. No exchange wallet was emptied and no contract flaw was exploited. A single account was affected, and the way in ran through an interface most users never look at. Anyone holding coins on a trading platform will recognise three points in this sequence that can look exactly the same inside their own account. What happened in the MEXC user's account between September 24 and 27 The account of events comes from the affected user himself, who posts on X as @shuangfei8, and has been picked up independently by several trade publications. His account was taken over on September 24, 2026. MEXC spotted the access, froze the account and helped the user recover the original email address and the authenti...

Read Entire Article