Skip to content
Monday, September 28, 2026
News

MEXC user loses $340K after AI deepfake bypasses KYC and API key is left active

MEXC user loses $340K after AI deepfake bypasses KYC and API key is left active

A MEXC user lost around $340,000 after an attacker used an AI-generated deepfake video to pass KYC, reset account details, and create an API key that was never revoked—allowing automated withdrawals once a 24‑hour cooling period ended.

What happened: timeline of the breach

What happened: timeline of the breach
  • Sept 25: The attacker allegedly obtained the victim’s personal data and submitted an account recovery request using an AI “hand-held” video that mimicked the user’s face and movements.
  • MEXC’s KYC review accepted the video, enabling the attacker to change core settings like email and phone. During this window, the attacker also created an API key with withdrawal permissions.
  • The real user noticed suspicious activity, contacted support, and MEXC froze the account and helped restore access (password and 2FA were reset).
  • A standard 24‑hour withdrawal restriction was applied after recovery.
  • Sept 27, ~04:12: Just 27 minutes after the cooling period lifted, six API-driven transactions drained 322,110 USDT and 9,133,999 ONE (about $340,000 total). No new login was recorded during the withdrawals.

How the attacker got in: AI deepfake + account recovery flow

How the attacker got in: AI deepfake + account recovery flow

The incident centers on two failure points: identity verification and post-recovery cleanup.

  • AI deepfake bypassed KYC. The attacker used a synthetic “hand-held” video to impersonate the account holder during MEXC’s identity check. This allowed them to reset email, phone, and other security bindings quickly.
  • API key created during takeover. While in control, the attacker generated an API key that could execute withdrawals. API keys can operate without triggering typical login or 2FA prompts if they already hold the needed permissions.
  • Recovery missed the API layer. MEXC confirmed the intrusion, froze the account, and restored user credentials—but did not revoke the malicious API key. When the 24‑hour withdrawal hold expired, the API automatically executed transfers.

Why the 24‑hour withdrawal hold wasn’t enough

Exchanges often impose a short cooling period after sensitive changes to slow down thieves. In this case, the hold delayed—but did not prevent—the loss because:

  • The attacker’s API key remained valid after the account was restored.
  • API-driven withdrawals can proceed without a fresh login or 2FA code if the key already has withdrawal rights.
  • Once the timer expired, the pre-configured API logic executed immediately, moving funds in multiple transactions within minutes.

MEXC’s response and next steps

MEXC’s response and next steps

MEXC said it completed a preliminary investigation, set up a special task force, and is following the case closely while encouraging the user to report to local authorities. The exchange has not reported a platform-wide breach; this appears to be an account-level compromise tied to identity verification and API management gaps during recovery.

While this case involved an exchange account rather than a stolen seed phrase, it shows why protecting sensitive crypto credentials is essential, as explained in our guide to seed phrase security.

What users can do now to reduce risk

Even if an exchange improves its KYC and recovery checks, users should treat API keys and withdrawal settings as critical attack surfaces.

  • Audit API keys regularly. Go to your exchange’s API management page and delete any key you don’t recognize or no longer use. After any security incident, revoke all keys immediately.
  • Use withdrawal whitelists. Enable address whitelisting so new withdrawal destinations require additional waiting periods and approvals. This can block API-driven transfers to unknown addresses.
  • Limit API permissions. If you must use APIs, restrict them to read-only or trading-only scopes; avoid granting withdrawal rights unless absolutely necessary.
  • Keep most funds off exchanges. Store long-term holdings in self-custody wallets or hardware wallets, and keep only what you need for active trading on the exchange.
  • Watch for social engineering and deepfakes. Be cautious with unsolicited support messages, fake login pages, and requests for codes. If you suspect compromise, change passwords, re‑link 2FA, and contact official support through verified channels.

As attackers increasingly combine social engineering with AI-generated identities, users should also understand the Common Crypto Scams that can put their accounts and funds at risk.

Bottom line

This was not a classic “exchange hack” but a targeted account takeover that exploited AI-assisted identity fraud and a missed step in post-recovery security: leaving an attacker-created API key active. For traders, the practical lesson is clear—after any breach or suspicious activity, manually revoke all API keys, enable withdrawal whitelists, and minimize on-exchange balances to limit exposure.

Sabnam is a passionate Blockchain student and dedicated Content Writer at Cryptodarshan.com, where she focuses on simplifying complex cryptocurrency and blockchain concepts for everyday readers. With a strong interest in decentralized technology, digital finance, and Web3 innovation, she is committed to spreading awareness about the future of money and technology.

Leave a Reply

Your email address will not be published. Required fields are marked *