MEXC says it has settled a dispute with user Shuang Fei, who reported losing about $340,000 after an attacker allegedly kept API access to the account even after recovery steps were completed. The exchange said it had “successfully reached an agreement” with the user and considers the matter fully resolved, but it has not disclosed the terms.

The case drew attention because the user’s account of events appeared to conflict with MEXC’s own documentation. Shuang Fei claimed the withdrawals were carried out through an API created during an account takeover, while MEXC’s account guide says freezing an account should invalidate all associated API keys.

Dispute ended without public details

MEXC customer support later told the user that the two sides had reached an agreement. The exchange has not publicly said whether Shuang Fei was reimbursed, whether an API key was confirmed as the withdrawal method, or what became of the reported stolen assets.

For now, the exchange’s public position is limited to saying the matter has been resolved and that additional details will not be released because of user privacy. That leaves several technical questions raised by the incident unanswered in public.

Timeline began with an unauthorized security reset request

According to Shuang Fei, the incident started on September 25 after an email arrived at 03:10 Beijing time saying someone had applied to change the account’s linked email and remove Google Authenticator. The user said the request was unauthorized and that the identification photo and verification video used in the process were not genuine materials supplied by the account holder. The request was reportedly approved about 10 minutes later.

MEXC later told the user, according to screenshots shared by the user, that the submitted materials had initially met the platform’s requirements. The user said the exchange then detected risk during a later review, froze the account and restored the original email address. MEXC’s security-reset documentation says users may be asked to provide account information, identity documents and a video holding identification when resetting security verification.

Once the attacker had control, the password was changed and a new Google Authenticator was linked, according to the user. Login records shared by Shuang Fei showed access from an IP address associated with Jakarta, Indonesia. At 05:05:42, an API was created, the user said, adding that MEXC disclosed the API’s existence only after the funds had already been withdrawn.

Recovery steps were followed by withdrawals

Shuang Fei said MEXC froze the account at about 10:55 on September 25 after suspicious activity was detected. The user then regained control the following day by removing the attacker’s Google Authenticator, changing the password and linking a new authenticator. The final change was completed at 03:45:07 on September 26.

MEXC documentation says crypto and fiat withdrawals are blocked for 24 hours after certain security changes, including changes to a linked email or Google Authenticator. The user said the first outgoing transfer took place at 04:12:45 on September 27, about 27 minutes after that 24-hour lock ended. Five more withdrawals followed over roughly 13 minutes.

The reported transfers removed 322,110 USDT and 9,133,999 ONE, which the user valued at about $340,000. Shuang Fei also said no new login appeared in the account’s login history during the withdrawal window.

API policy became a central question

A key issue in the dispute is whether an attacker-created API could still function after the account had been frozen. MEXC’s account guide says freezing disables trading and login functions and invalidates all API keys linked to the account. Shuang Fei has publicly questioned how the reported API could later have been used if that policy was applied. MEXC has not publicly answered that point.

The exchange’s API withdrawal rules add further context. In a 2023 announcement, MEXC said withdrawal whitelists would not be enabled by default for API withdrawals, meaning funds could be sent to any address unless a whitelist had been switched on. The platform advised API users to enable whitelists and protect their API keys.

The user also said the attacker-created API was not visible in the account’s accessible security-operation history and that no notice was received when it was created because the account email had already been changed. Shuang Fei asked MEXC to disclose the IP address used to create the API, the permissions attached to it, whether it was invalidated during the freeze, and which channel initiated the six withdrawals.

What is confirmed next

The incident was later summarized by CertiK and Lookonchain, both of which repeated the user’s claim that no fresh login activity appeared during the withdrawal period. CertiK said only that it was reporting the account and did not independently establish the attack method in its notice.

What is confirmed at this stage is narrower: the user reported the sequence of events publicly, MEXC said it conducted an investigation and offered solutions, and the exchange now says an agreement has been reached. Unless either side releases more information, the settlement closes the dispute publicly without resolving all of the technical questions raised by the case.

Source: crypto.news