币圈老司机🔶BNB|Sep 28, 2026 05:14
Another netizen was identified by facial recognition and stole 340000 US dollars
Can each exchange avoid using immature AI in risk control
On September 25, 2026, a friend discovered that their MEXC account had been frozen
After contacting customer service, it was learned that someone had changed their bound email and Google Authenticator through the platform's appeal process without authorization from a friend
The customer service then replied clearly: "After reviewing the materials, they meet the requirements, so the application to change your email has been approved. However, during the re examination, it was discovered that this application involves risks, so the account was urgently frozen and reverted back to your initial email
That is to say, unauthorized email changes have already been approved, and the platform only discovered the risks during the review. Of course, the platform's ability to forcibly replace the email that was replaced by the attacker is also out of the question
My friend cooperated with customer service to retrieve my account as requested
My friend changed the password for binding the email, submitted the account information, and applied for unfreezing
Early morning of September 26, 2026:
01:01, Apply to unbind the Google Authenticator bound by the attacker
03:41, Change account password
03:44, bind a new Google Authenticator
At 04:00, log in to your account again. The email has been restored, the password has been changed, and the validator has been rebind
My friend thought he had regained control of the account
Wants to transfer assets, but is subject to 24-hour withdrawal restrictions
After experiencing this anomaly, I tried to withdraw but found that after modifying the security settings, I needed to wait for 24 hours
On the morning of September 27th, the assets disappeared
At around 09:00 that day, a friend opened their account and found that 6 withdrawals were not initiated by the person themselves
The loss includes approximately 322110 USDT and ONE token in the account, with a total value of approximately 340000 USDT
My friend has already followed the platform process to retrieve their account, change their password, and rebind their validator. Why can the assets still be transferred by others?
Afterwards, the customer service mentioned an API that I was not aware of
As an ordinary individual user, I don't usually use APIs, so I have very little knowledge about the creation, permissions, and calling methods of APIs. I also haven't created or authorized the creation of this API
According to customer service, the account created an API on September 25, 2026 at 05:05:42
My friend did not create or authorize the creation of this API
What is even more incomprehensible is that MEXC has confirmed that the account has been hacked, frozen the account, and forced the email to be restored to its original email address, but it seems to have overlooked this API maliciously created by the attacker
My friend only found out about the existence of such an API after contacting customer service on September 27th for verification, because according to common sense, I changed the account password, Google Binding tool, and the password of the corresponding email of the account
This can be considered that the account is already very secure. Since the platform has such great authority to force the attacker to replace the email that has been changed with the original email, why did it allow the attacker to create a malicious API?
If the platform has identified risks in the account, why hasn't it synchronized troubleshooting, revoked abnormal APIs, or at least clearly informed me of the existence and permissions of the API?
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink