BTC $83,212.38 -1.82%
ETH $2,669.84 -0.86%
BNB $762.44 -2.07%
XRP $1.49 -3.13%
SOL $118.28 -3.97%
TRX $0.3358 +0.63%
DOGE $0.0932 -4.13%
ADA $0.2438 -4.56%
BCH $306.24 -8.63%
LINK $15.02 +6.68%
HYPE $87.73 -4.49%
AAVE $146.69 -5.32%
SUI $1.13 -10.02%
XLM $0.2268 +4.74%
ZEC $1,460.10 -9.01%
AAPL $338.72 -0.52%
AMZN $246.27 -1.65%
GOOGL $342.40 -0.52%
MSFT $509.48 -1.55%
META $717.25 -4.24%
NVDA $228.60 +1.40%
TSLA $358.26 -4.05%
SNDK $1,713.16 -3.98%
INTC $116.03 -7.69%
SPCX $146.46 -1.63%
MU $1,053.73 -3.96%
AMD $607.37 -4.24%
BTC $83,212.38 -1.82%
ETH $2,669.84 -0.86%
BNB $762.44 -2.07%
XRP $1.49 -3.13%
SOL $118.28 -3.97%
TRX $0.3358 +0.63%
DOGE $0.0932 -4.13%
ADA $0.2438 -4.56%
BCH $306.24 -8.63%
LINK $15.02 +6.68%
HYPE $87.73 -4.49%
AAVE $146.69 -5.32%
SUI $1.13 -10.02%
XLM $0.2268 +4.74%
ZEC $1,460.10 -9.01%
AAPL $338.72 -0.52%
AMZN $246.27 -1.65%
GOOGL $342.40 -0.52%
MSFT $509.48 -1.55%
META $717.25 -4.24%
NVDA $228.60 +1.40%
TSLA $358.26 -4.05%
SNDK $1,713.16 -3.98%
INTC $116.03 -7.69%
SPCX $146.46 -1.63%
MU $1,053.73 -3.96%
AMD $607.37 -4.24%

transfer

All
Article
Flash

first_img MEXC user: API not revoked after account was hacked, approximately 340,000 USD was transferred away

A MEXC user posted on X that their account was compromised after someone reset the security items. MEXC has confirmed the account was hacked, frozen the account, and assisted in recovery, but did not revoke the API left by the attacker. From 04:12 to 04:25 on September 27, 2026 (Beijing time), the account transferred out 322,110 USDT and 9,133,999 ONE, totaling approximately $340,000, about 27 minutes after the 24-hour transfer limit was lifted.The user stated that at 03:10 on September 25, they received a reset security item email that was not submitted by them, and about 10 minutes later, the request was approved. Subsequently, the account was logged in from an IP in Jakarta, Indonesia, bound to Google verification, and at 05:05, an API was created, approximately 83 seconds after logging in. At 10:55 that day, MEXC froze the account after a risk review and reverted to the original email. Customer service responded in writing that the review materials met the requirements, so the binding change was approved, and after the risk review, the account was urgently frozen and reverted to the initial email. The user changed their password and Google verification on September 26 but stated that the API was not revoked, and there were no related records in the security operation history.The user also claimed that there were no new login records in the login history when the assets were transferred out. They have submitted a formal claim to MEXC and attempted to report to the police, with the ticket number M2026092712031, requesting the platform to preserve logs, provide a written explanation of the review and API situation, and return the aforementioned assets. MEXC customer service stated that it is currently unable to confirm whether these transfers were initiated via APP, WEB, or API, and the issue has been forwarded to the relevant department.

first_img Bitget: A small amount of hot wallets were unauthorizedly transferred, involving 351.6 million USD; the vast majority of the platform's assets are safe, and the protection fund can cover the losses

The cryptocurrency trading platform Bitget announced on its official X account that on September 24, 2026, at 18:31 (UTC), its security system detected unauthorized transfers from a small number of hot wallets. The security team has immediately initiated an emergency response procedure and started a comprehensive investigation.Bitget stated that, based on current assessments, approximately $351.6 million in assets are affected. Cold wallets and the vast majority of assets on the platform remain secure and unaffected, and user funds are still protected. The incident falls within the coverage of the user protection fund, which currently holds over $464 million.Bitget mentioned that customer account balances remain accurate, and deposits and transactions continue to operate normally. As a precautionary measure, withdrawals have been temporarily suspended to allow the team to complete a thorough security review. The company has identified and flagged the relevant transfer addresses, formally contacted law enforcement agencies and on-chain security partners, and will restore withdrawals as soon as safety is confirmed, providing subsequent updates through official channels while refraining from speculating on the attack path during the investigation.
app_icon
ChainCatcher Building the Web3 world with innovations.