MEXC Users Suffer Account Takeover, API Backdoor Leads to $340,000 in Stolen Assets
According to a post by user @shuangfei8, their MEXC account was compromised on September 25 when attackers used forged identification documents to complete a security reset and breach the account within 10 minutes. Although MEXC subsequently froze the account and assisted in its recovery, it failed to revoke the API key created by the attacker during the period of unauthorized control. At 04:12 on September 27, merely 27 minutes after the 24-hour withdrawal restriction was lifted, the attacker exploited this residual API to bypass Google verification and email verification, draining 322,110 USDT and 9,133,999 ONE (totaling approximately $340,000) from the account across six separate transactions. The user has submitted a formal compensation claim to MEXC and attempted to report the incident to the police, demanding that the platform preserve logs, provide a written response regarding the security vulnerability, and return the stolen assets. Furthermore, multiple MEXC users have recently reported receiving suspicious emails resembling a "request to reset security settings," prompting users to immediately navigate to 【API Management】 to check for any unknown API keys.