MEXC User Lost $340,000 After API Key Oversight

The exchange failed to revoke an attacker-created API key, allowing unauthorized withdrawals after a previous compromise.

Updated on Sept. 29, 2026 in Cybersecurity

Bold flat-color editorial illustration of a geometric gateway arch, symbolizing systemic vulnerability in digital exchange security.
A cryptocurrency user lost $340,000 in assets on MEXC after the exchange failed to revoke an attacker's API key following a prior compromise. AI Illustration. Upload story photo >

Live Poll

Do you trust cryptocurrency exchanges to keep your assets secure from hackers?

A cryptocurrency user lost $340,000 worth of assets from their MEXC account over a 13-minute period. The incident occurred after the exchange failed to revoke an API key generated by an attacker during a prior account compromise.

Why it matters

The breach highlights systemic risks in exchange security architectures where API keys persist even after user-initiated password or authenticator changes. This event underscores the critical need for exchanges to invalidate all active session tokens and keys when a security breach is reported.

The attacker transferred 322,110 USDT and 9,133,999 ONE tokens in under 13 minutes. These transactions were facilitated by an API key created 83 seconds after the initial account login, which bypassed two-factor authentication requirements.

The players

MEXC

A centralized cryptocurrency exchange that provides trading services for digital assets and integrates API access for automated market participation.

Socket

A cybersecurity research group that specializes in detecting malicious software, including browser extensions designed to steal credentials.

The details

API keys are strings of characters used to authenticate and authorize requests between a user's account and an exchange's server. Because these keys effectively allow for programmatic trading and withdrawals without subsequent two-factor authentication prompts, they remain high-value targets for attackers. MEXC's failure to purge these keys following the September 24 account breach allowed the attacker to retain access despite the user registering a new authenticator.

Timeline

  1. January 2026: The Socket research team documented a malicious Chrome extension.

  2. September 24, 2026: The attacker hacked the account and created the API key at 21:05:42.

  3. September 28, 2026: The user reported losses and MEXC settled the case.

The Tech Race

This breach highlights the security gap between exchange infrastructure and legacy API authentication protocols. It follows a pattern of sophisticated attacks, such as those involving malicious browser extensions identified by Socket in 2026, which target these specific vulnerabilities.

Users should manually review and rotate or delete all active API keys in their exchange account settings immediately following any security concern. This case serves as a reminder that changing a login password is often insufficient to secure an account if API-based access tokens remain active.

The takeaway

Account security hygiene must extend beyond the primary login to include auditing all automated access permissions. Users should track security advisories from organizations like Socket to stay informed about evolving account-compromise tactics.

Further reading

For broader trends in platform security, visit Cybersecurity.

Source note: This article includes information reported by Crypto Economy.

Live Poll

Do you trust cryptocurrency exchanges to keep your assets secure from hackers?

MEXC User Lost $340,000 After API Key Oversight | Highwise Tech