MEXC User Lost $340,000 After API Security Breach
A user lost funds in minutes after an unrevoked API key allowed unauthorized withdrawals from their account.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust cryptocurrency exchanges to keep your assets secure from hackers?
A cryptocurrency user lost $340,000 in assets on the MEXC exchange after an attacker utilized an unrevoked API key to bypass security. The incident occurred despite the user recently resetting their account password and authentication settings.
Why it matters
The breach highlights critical vulnerabilities in how exchanges manage legacy API keys during account recovery processes. Failing to invalidate keys created by unauthorized actors can leave user assets exposed to automated drainage.
The attacker transferred 322,110 USDT and 9,133,999 ONE tokens over a 13-minute window. These API-based transactions successfully bypassed two-factor authentication requirements.
The players
MEXC
MEXC is a global cryptocurrency exchange that provides trading services for various digital assets.
Socket
Socket is a security research firm that tracks vulnerabilities in browser extensions and web-based applications.
The details
The attacker established the malicious API key just 83 seconds after accessing the account on September 24. These keys permit direct withdrawals, meaning the system processed the theft despite subsequent password and authenticator resets performed by the legitimate user.
Timeline
January 2026: Socket research documented a malicious Chrome extension.
September 24, 2026: The attacker compromised the account and created the API key.
September 28, 2026: The user reported the losses and reached a settlement with MEXC.
The Tech Race
This incident follows the pattern established by recent security findings regarding browser-based exploits. It highlights the ongoing struggle to secure exchange infrastructure against increasingly sophisticated automated bypass methods.
Users should actively review and revoke any unused or suspicious API keys in their exchange account settings immediately. Always verify that security settings updates fully invalidate prior access tokens created during a potential compromise.
The takeaway
Security recovery protocols must ensure that account resets automatically invalidate all previously generated access credentials. Users must treat API keys as high-risk gateways that require as much vigilance as passwords.
Further reading
For broader insights into digital asset protection, explore the Cybersecurity section.
Source note: This article includes information reported by Crypto Economy.
Live Poll
Do you trust cryptocurrency exchanges to keep your assets secure from hackers?







