币圈老司机🔶BNB
币圈老司机🔶BNB|Sep 28, 2026 05:14
Another netizen was identified by facial recognition and stole 340000 US dollars Can each exchange avoid using immature AI in risk control On September 25, 2026, a friend discovered that their MEXC account had been frozen After contacting customer service, it was learned that someone had changed their bound email and Google Authenticator through the platform's appeal process without authorization from a friend The customer service then replied clearly: "After reviewing the materials, they meet the requirements, so the application to change your email has been approved. However, during the re examination, it was discovered that this application involves risks, so the account was urgently frozen and reverted back to your initial email That is to say, unauthorized email changes have already been approved, and the platform only discovered the risks during the review. Of course, the platform's ability to forcibly replace the email that was replaced by the attacker is also out of the question My friend cooperated with customer service to retrieve my account as requested My friend changed the password for binding the email, submitted the account information, and applied for unfreezing Early morning of September 26, 2026: 01:01, Apply to unbind the Google Authenticator bound by the attacker 03:41, Change account password 03:44, bind a new Google Authenticator At 04:00, log in to your account again. The email has been restored, the password has been changed, and the validator has been rebind My friend thought he had regained control of the account Wants to transfer assets, but is subject to 24-hour withdrawal restrictions After experiencing this anomaly, I tried to withdraw but found that after modifying the security settings, I needed to wait for 24 hours On the morning of September 27th, the assets disappeared At around 09:00 that day, a friend opened their account and found that 6 withdrawals were not initiated by the person themselves The loss includes approximately 322110 USDT and ONE token in the account, with a total value of approximately 340000 USDT My friend has already followed the platform process to retrieve their account, change their password, and rebind their validator. Why can the assets still be transferred by others? Afterwards, the customer service mentioned an API that I was not aware of As an ordinary individual user, I don't usually use APIs, so I have very little knowledge about the creation, permissions, and calling methods of APIs. I also haven't created or authorized the creation of this API According to customer service, the account created an API on September 25, 2026 at 05:05:42 My friend did not create or authorize the creation of this API What is even more incomprehensible is that MEXC has confirmed that the account has been hacked, frozen the account, and forced the email to be restored to its original email address, but it seems to have overlooked this API maliciously created by the attacker My friend only found out about the existence of such an API after contacting customer service on September 27th for verification, because according to common sense, I changed the account password, Google Binding tool, and the password of the corresponding email of the account This can be considered that the account is already very secure. Since the platform has such great authority to force the attacker to replace the email that has been changed with the original email, why did it allow the attacker to create a malicious API? If the platform has identified risks in the account, why hasn't it synchronized troubleshooting, revoked abnormal APIs, or at least clearly informed me of the existence and permissions of the API?
+2
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads