top of page

MEXC Compensates a User in Full After a $340K API-Key Hack

1 day ago
3 min read
MEXC Compensates a User in Full After a $340K API-Key Hack

A MEXC user reported losing about $340,000 after an attacker retained an API key the exchange allegedly failed to revoke — and by 29 September MEXC had confirmed the loss and compensated the affected user in full.

What Happened

A MEXC user reported losing roughly $340,000 after an attacker — who reportedly bypassed KYC using an AI face-swap — retained an API key that MEXC allegedly did not revoke, even after helping the user recover the account.

By 29 September, MEXC confirmed the loss and said it had fully compensated the affected user. The incident highlights two rising threats at once: API-key mismanagement and AI-assisted identity fraud.

Why It Matters

API keys are the quiet back door of crypto exchanges: powerful, persistent, and easy to forget. An unrevoked key can drain an account long after the obvious breach is 'fixed', which is exactly what appears to have happened here.

The AI face-swap angle is the new wrinkle. As identity-verification defences are increasingly beaten by generative AI, exchanges' security models — and their KYC — are under fresh strain.

Marketing Minute's Take

The security failure is serious, but the response is the story. Fully compensating the user is a costly, reputation-protecting choice — and in a trust-based business like an exchange, that's often the right one.

How a company behaves after a failure shapes its brand more than the failure itself. MEXC turning a damaging incident into a demonstration of 'we make users whole' is textbook crisis management, whatever the underlying lapse.

What Businesses Should Do

Audit the boring security surfaces — API keys, tokens, standing permissions — not just the headline defences. The persistent, forgotten access path is where real losses happen.

And plan your failure response in advance. Customers forgive incidents; they rarely forgive a bad reaction. Deciding now how you'll make users whole is brand insurance you'll be glad you bought.

Quick FAQ

What happened at MEXC?

A user lost about $340,000 after an attacker retained an API key MEXC allegedly failed to revoke; the attacker reportedly bypassed KYC using an AI face-swap.

Did the user get their money back?

Yes — by 29 September MEXC confirmed the loss and said it had fully compensated the affected user.

What are the key lessons?

API keys and standing permissions are an underrated security risk, AI-assisted identity fraud is a growing threat, and a strong post-incident response protects trust.

The breach is serious, but the response is the story. In a trust-based business, fully compensating the user is costly and correct — because how you behave after a failure shapes your brand far more than the failure itself. Plan that response before you need it. — Daniel Nikolla, Founder of Merx Marketing

Customers forgive incidents, not bad reactions — decide now how you'll make users whole, and audit the boring access paths attackers actually use.

Have you audited the forgotten API keys and standing permissions that could quietly drain an account long after a breach looks 'fixed'?

If you would like to know more about this topic, please contact us on danieln@merxmarketing.co.uk

Sources: crypto.news, Crypto Times and Crypto Economy.

Related reading

Written by Daniel Nikolla, Founder of Merx Marketing Ltd and Marketing Minute

Comments


bottom of page
Website by Merx Marketing
Share

⚡ Stay ahead in a minute

The biggest UK marketing stories — and what they mean for your business — every week.

Get the Weekly Digest →
Enter