MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
An attacker drained roughly $340,000 from the account of a user of the crypto exchange MEXC, even though the account had already been flagged as compromised, frozen and handed back to its owner. The route in was an API key the attacker had created during the takeover and which the exchange failed to revoke when it restored the account. MEXC admitted exactly that in public on September 28 and 29, 2026, and says it has reimbursed the loss in full.
This is not an exchange hack in the usual sense. No exchange wallet was emptied and no contract flaw was exploited. A single account was affected, and the way in ran through an interface most users never look at. Anyone holding coins on a trading platform will recognise three points in this sequence that can look exactly the same inside their own account.
What happened in the MEXC user's account between September 24 and 27
The account of events comes from the affected user himself, who posts on X as @shuangfei8, and has been picked up independently by several trade publications. His account was taken over on September 24, 2026. MEXC spotted the access, froze the account and helped the user recover the original email address and the authenticator app. Up to that point the exchange reacted fast and in the right direction.
During the takeover, however, the attacker had done a second thing. According to Crypto Economy, he created an API key with withdrawal rights on September 24 at 21:05:42, 83 seconds after his second login to the account. That key stayed live when the account was released back to its owner.
After a security-related intervention on an account, crypto exchanges usually impose a 24-hour withdrawal freeze. That window expired. Twenty-seven minutes later the outflows began. According to the user, 322,110 USDT and 9,133,999 ONE left the account, together worth roughly $340,000, in six transactions to two addresses and within 13 minutes.
Reports differ slightly on timing because they quote different time zones. TechFlow puts the window at 04:12 to 04:25 Beijing time on September 27; The Crypto Times dates the outflow to September 26. Both describe the same window, once in East Asian local time and once converted. The difference changes nothing about the sequence.
API keys with withdrawal rights: why they need neither Google Authenticator nor the email code
An API key is a set of credentials that lets a program talk to the exchange on an account holder's behalf without logging in the way a human does. It consists of a public part and a secret part and carries a fixed list of permissions: read only, trade, or withdraw as well.
The decisive point in this case sits in the design. Two-factor authentication with an authenticator app and the confirmation email are controls for the human login path. A machine cannot read a six-digit code out of an app, so the interface does not ask for one. Whoever holds a key with withdrawal rights needs neither the password nor the authenticator nor access to the email inbox.
That is why restoring the account did not end the attack. Email and authenticator were recovered, and neither mattered for the actual outflow. A trading bot, a portfolio tracker and an attacker technically use the same door.
The practical consequence: changing your password and setting up two-factor authentication again does not yet secure your account. Only revoking every key closes this second route. How differently providers are set up on login protection is something we have written down in our overview of two-factor authentication at the crypto exchange.
The 24-hour withdrawal freeze and its gap
A freeze after a security incident is meant to buy time, on the assumption that anyone with illegitimate access loses it within a day because the owner changes the password and the exchange clears up. That assumption only holds if the clean-up is complete.
In the MEXC case the freeze worked as intended and blocked every withdrawal for 24 hours. Then the window expired, and the key left behind was still valid. The 27 minutes between the end of the freeze and the first transaction suggest the timing was not hit by chance but waited for.
For you that means a withdrawal freeze is a window of time, not a repair. Whatever is not dealt with inside that window keeps working afterwards. And the account holder sees nothing of an existing interface unless he explicitly opens the key management page.

Account takeover through identity verification: the user's account of events
How the attacker got into the account in the first place is the most contested part of the story, and caution is in order here. According to the affected user, whose version TechFlow reports at length, the account's security settings were reset through the identity verification route, using forged identity documents. Neither the password nor an active session had been compromised, he says.
That version comes from the injured party. MEXC has not commented publicly on this point in detail and says the investigation is ongoing. So far, only what the company has itself established counts as confirmed: that the account was taken over, that it was frozen and restored, and that a key left behind made the outflow possible.
Whichever route is eventually confirmed, one question follows that every user can answer for their own account: which routes exist at my exchange for resetting two-factor authentication, and how tightly is that route secured? The reset path is the weakest point of any account, because by design it unhooks every other layer of protection.
Hold your coins in your own custodyWhat MEXC chief Vugar Usi Zade said on X
On September 28, 2026, Vugar Usi Zade, chief executive of MEXC, addressed the case on X and described the sequence from the company's point of view. Customer support had spotted the takeover quickly and frozen the account, he said, after which MEXC helped the user get the email address and authenticator back.
On the decisive point he wrote, as reported by The Crypto Times: “Unfortunately, an API key that remained on the account allowed the attacker to transfer the funds before the issue could be fully contained.”
The investigation is not closed, he said, but one thing is clear: “We do not believe the user should have to bear the consequences of this incident.” MEXC has put its own team on the case and compensated the affected user in full.
The road to that point is notable. As late as September 28, Crypto Economy reported a settlement with the user on undisclosed terms, and customer support had earlier told the account holder it could not determine whether the withdrawals came from the app, from the browser or through an interface. Only the chief executive's statement named the route. Anyone conducting a dispute like this should expect the first answer from customer support not to be the final version.
Compensation without a legal claim: the difference between goodwill and liability
That the user got his money back is good news with a catch. The refund was a company decision, not the enforcement of a claim. Phrases such as “user-first” are a commitment, not contract language.
The difference matters when a case ends badly. Goodwill depends on the attention a case attracts. This one ran visibly for days on X and in the trade press, with timestamps, transaction details and a sequence anyone could follow. An account holding 3,000 euros with no audience does not have that leverage.
A claim, by contrast, hangs on the law the provider is subject to. And it is precisely here that trading venues differ considerably for European users.
MiCA and the crypto exchange's liability for lost client assets
Since the EU regulation on markets in crypto-assets took effect, custody and trading services may only be provided in the European Union by authorised firms. Authorisation comes with an obligation that is rarely read in everyday life and becomes decisive in cases exactly like this one: an authorised custodian is liable to its clients for the loss of crypto-assets or of means of access where the incident is attributable to it. Keeping client holdings segregated from the firm's own assets and maintaining a documented custody policy belong to the same set of duties.
This liability is not automatic and does not cover every loss. It presupposes that the provider is authorised and that the incident falls within its area of responsibility. A seed phrase a user types into a fake wallet page himself is not covered. A means of access that the exchange leaves in place after a detected break-in sits closer to the provider's area of responsibility.
Whether your trading venue falls under these duties is not stated in its advertising but in the supervisor's register. Germany's BaFin lists the crypto-asset service providers authorised there in a public overview, and the European supervisory authority ESMA keeps the register for the whole economic area.

Reverse solicitation: what an unlicensed exchange's status means for European users
Many large trading venues with a wide range of smaller tokens hold no authorisation in the EU. Officially these providers do not market in the Union, but they do accept clients who come to them of their own initiative. That route is called reverse solicitation, and it is meant as a narrow exception, not as a business model.
For you as a user the status has tangible consequences. Without EU authorisation there is no supervisor you can turn to, no complaints body in your language, no enforceable claim out of the European set of duties, and in a dispute a place of jurisdiction far away. What remains is the provider's goodwill.
That is not a recommendation to avoid or to use such venues. It is the condition under which you decide how much sits there. Anyone trading there because the pair exists nowhere else can cap the amount and withdraw after the trade.
Trading venues under European supervisionAPI keys in your own account: permissions, IP binding and expiry dates
Key management sits under account or security settings at most exchanges and is called API management. Every active key is listed there with its permissions, often with the date of creation and of last use. That list is exactly the place that would have made the difference in the MEXC case.
Three settings decide how much damage a key gone astray can do. Withdrawal rights are the first: without that permission a key can trade and read but cannot move anything off the exchange. The second is binding to fixed IP addresses, which lets a key work only from known machines. The third is an expiry date, which many platforms now enforce so that forgotten keys die on their own.
A fourth point is pure hygiene: one key per application, with a recognisable name. Anyone using one key for three programs cannot revoke it on suspicion without switching everything off. Anyone keeping three named keys instead removes the one in question in seconds.
Tax software, portfolio tracker and trading bot: which permissions a key actually needs
In the vast majority of cases the program you connect needs considerably less than it asks for. A tax program or a portfolio tracker reads trade history and holdings and gets by with read-only rights. There is no substantive reason why software that calculates gains should be able to move coins.
A trading bot needs trading rights, because it places orders. It too needs no withdrawal rights. Anyone granting both together has created a route of access that can do everything he can do, permanently and without a second factor.
Which permissions common tax tools actually request, and how they differ, is something you can look up in our overview of crypto tax software and portfolio trackers before you create your next key.
One last note on connections you have long forgotten: a tracker you tried once two years ago still holds its key today. Legacy items like that are immediately recognisable in the list, because their date of last use is far in the past.
Two-factor authentication and the limits of its protection
Two-factor authentication remains right and important. The protection bites on the login path, and that is the most common attack route of all. An app such as an authenticator is clearly superior to SMS here, because a mobile number can be taken over.
What two-factor authentication does not cover are machine routes of access and the reset path. It bypasses both by design, not through a flaw. Security on a trading platform therefore consists of three layers: login protection, key management, and the question of how much sits there at all.
The third layer is the only one entirely in your own hands.
Exchange balances and self-custody: the split after this case
Coins on an exchange are a claim against a company. Coins in your own wallet are a key in your hand. The MEXC case does not fundamentally shift that old trade-off, but it does show an attack surface that does not exist with self-custody. A hardware wallet has no interface an attacker could have unlocked through customer support.
In exchange, self-custody shifts the risk onto you. Lost recovery words are final, and there is no chief executive to authorise a goodwill payment. The split commonly used in practice: what you actively trade stays on the trading venue, what you want to hold for longer sits in your own custody.
For European investors there is a tax point on top. Moving your own coins from the exchange into your own wallet is not a sale and, on the usual reading, triggers no tax, because no change of ownership takes place. You do have to carry the acquisition data, and with it the holding period, yourself, because after the transfer no platform knows the original purchase date any more. Anyone using a tool for that should export the history before closing an account.
API keys at the crypto exchange: your next three steps
- At every exchange where you hold an account, open API management and remove every key you cannot immediately match to a running application. On the ones that remain, take away withdrawal rights and bind them to your IP address. Which venues are under European supervision at all can be found in our list of regulated crypto exchanges.
- Decide what amount may sit on a trading venue, and withdraw the rest. A useful guide is the amount whose total loss would not throw you off course. For the part meant to sit longer, a device with its own key is the next step; the differences are set out in the hardware wallet comparison.
- Look at how two-factor authentication can be reset at your exchange, and switch on every notification available for it. An email about a newly created interface is the only warning that would have arrived in time in this case. If you then withdraw from the trading venue, the software wallet comparison helps with choosing where to send it.
The MEXC case ended lightly because a company paid that did not have to. That is the weakest of all safeguards. The strong version consists of a short list of active keys, a capped balance on the trading venue, and an exchange whose supervisor you can name.
The company's full confirmation including quotes from its chief executive can be read at The Crypto Times.
(As of September 29, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Frequently asked questions about API keys at crypto exchanges
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
- Ripple Cannot Freeze 83 Million Dollars in Stolen XRP: What to Check in Custody and Deposits
- 387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
- Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
- Bybit's Counterparty List Runs to Over 50 Names: What to Check on Balances, Withdrawals and Custody
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 17, 2026 1:24 AM

API Keys on Crypto Exchanges: Which Rights Your Tax Tool Really Needs and Which You Switch Off
An API key is a power of attorney with individually tickable rights, and most investors tick too many of them. We examined twelve documentation pages from eight providers and show which rights a tax tool needs and which you can switch off right away.
September 16, 2026 1:28 PM

Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Seven of ten providers available in Germany offer a payout to a wallet address you control yourself; three do not. Our survey of September 16, 2026, shows how to spot the difference before you buy, and why the question matters right now.
September 4, 2026 4:39 AM

Source of Funds at a Crypto Exchange: Why a Deposit Can Freeze Your Account for 15 Days
OKX chief Star Xu described on September 2 what an unusual deposit sets off: reviews of 15 days and longer, during which balances and account functions can be restricted. What that means for investors in Germany, and which documents you should keep to hand.
September 23, 2026 10:11 AM

Kraken: 45 coins are on cancel only, 21 were announced – what to check when trading pairs are blocked
On September 23, 2026 we counted the public market directories of three trading venues. At Kraken, 82 of 1,450 trading pairs are listed as cancel only, a state in which an order can only be cancelled and no longer executed. The 45 underlying assets affected include just 21 that appear in the delisting notice we reported on September 3.
August 30, 2026 10:38 PM

Crypto Cards: Where Your Card Balance Really Sits and What the August 28 Solana Exploit Reveals About It
An attack on a card balance contract on Solana took the loaded balance from 1,685 users while their wallets stayed untouched. The case shows why it matters whether your crypto card holds funds as e-money at a licensed institution or in a smart contract.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
August 20, 2026 4:20 AM

Crypto Exchange Delisting: What Happens to Your Tokens When Trading and Withdrawals Close
A delisting runs in four stages, and only one of them is genuinely dangerous: the end of the withdrawal deadline. Using two live OKX dates as the example, we show what happens at each stage and how to tell whether it affects you.
September 27, 2026 4:32 AM

Hester Peirce Leaves the SEC: What Now Applies to Your Custody in Germany
The most crypto-friendly voice at the US securities regulator goes on October 2, 2026, and the commission shrinks to two members. For investors in Germany it is still the European rulebook that decides, and there a deadline falls in July 2027.
September 3, 2026 4:41 AM

Kraken Delists 21 Tokens: Trading End on September 11 Has Passed, Withdrawals Run Until December 10
As of September 27, 2026: Kraken had set the end of trading and deposits for 21 cryptocurrencies for September 11, 2026 at 14:00 UTC, and that date has passed. According to the exchange, withdrawals remain possible until December 10, 2026 at 15:00 UTC. Our September 3 survey showed that none of these tokens could be deposited at Bitvavo, Coinbase or Bitstamp.
August 23, 2026 4:25 AM

Crypto Exchange Closure: What Happens to Your Residual Balance and When the Fee Starts
When a crypto exchange stops operating, trading ends on a set date but the account does not. Anyone leaving a residual balance behind now pays a monthly fee at the wind-downs currently under way.
September 11, 2026 1:40 PM

Inactivity Fees at Crypto Exchanges: How to Check Whether Your Dormant Account Loses Money Every Month
Two providers have just raised their rates for dormant accounts, one of them to as much as 52 US dollars a month. Our own survey of 15 fee pages shows why you will almost never find the answer for your account without logging in.
September 8, 2026 7:33 AM

Withdrawal Whitelist at the Crypto Exchange: How to Lock the Withdrawal Path Against Foreign Addresses
A withdrawal whitelist lets balances leave only to addresses approved in advance, and it works even when password and second factor are compromised. On September 8, 2026 we checked which of thirteen providers document the function publicly.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
September 13, 2026 1:13 PM

Sparkasse Crypto Custody: Why You Get No Key to Your Bitcoin and What to Check First
From October, Sparkasse customers are to be able to buy Bitcoin and Ether inside their own banking app, with DekaBank acting as custodian. What you get is a custody position rather than a private key. What that means in practice and what you should settle before your first purchase.
September 25, 2026 4:13 PM

Crypto Exchange Protection Funds Recalculated: What Really Covers Your Balance After the Bitget Hack
The $351.6 million attack on Bitget would eat up three quarters of the exchange's in-house protection fund. We retrieved the protection promises of several exchanges ourselves and measured them against deposit insurance and MiCA liability.
October 2, 2026 10:46 AM

3 Details Are All It Takes: How SIM Swapping Reaches Your Crypto Account
Fraudsters have a new SIM card activated in your name at the mobile operator and intercept every SMS code with it. How the attack on your crypto account unfolds and which settings make it run into the void.
September 15, 2026 10:12 AM

CoinEx Is Shutting Down: The Deadline to Withdraw Your Balance
Crypto exchange CoinEx is winding down and the withdrawal channel closes on December 22, 2026. Our own measurement on the day of the first wind-down stage shows which 37 currencies cannot be withdrawn right now and why the chain you pick decides a double-digit percentage of your residual balance.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
July 10, 2026 10:30 AM

Binance Reveals Where Its EU Users Went After MiCA
Binance just revealed where most departing EU users moved their crypto after MiCA — and the answer is raising hard questions about the new rulebook.
September 30, 2026 10:24 PM

$766 Million Lost to Crypto Hacks in One Month: What It Means for Your Custody
CertiK counts around $766.4 million in damage for September 2026, the highest monthly figure of the year. Two incidents carry more than 92 percent of it, and both hit a place where your balance could be sitting too.
August 20, 2026 7:18 AM

Crypto Exchange Self-Certification: No Answer by 1 January 2027 and Trading Stops
The German Crypto Asset Tax Transparency Act obliges crypto providers to obtain a tax self-certification from every existing customer by 1 January 2027. Anyone who ignores the request, the reminder and the formal notice is barred from trading after 60 to 90 days.
August 22, 2026 1:23 AM

Binance Withdrawal Deadline September 9: What ALCX, ARDR, NFP and POND Holders Should Know Now It Has Passed
Recap as of September 27, 2026: Binance had announced it would stop withdrawals of ALCX, ARDR, NFP and POND on September 9, 2026 at 03:00 UTC. Spot trading in these tokens had been suspended since July 10, and the exchange is winding down its EU business. This article describes the situation before the deadline.
April 21, 2026 11:15 AM

Breaking: Arbitrum Security Council Freezes $71M in ETH Linked to KelpDAO Exploit
The Arbitrum Security Council has frozen 30,766 ETH tied to the KelpDAO hack, sparking a fierce debate over decentralization and emergency powers in DeFi.
More from CryptoTicker


