crypto.news and Crypto Economy give different dates and times for when the attacker’s API key was created during the MEXC $340K withdrawal incident.
crypto.news and Crypto Economy give different dates and times for when the attacker’s API key was created during the MEXC $340K withdrawal incident.
The initial unauthorized account reset began early on September 25 when Shuang Fei received an email stating that an application had been made to change the account’s linked email and remove Google Authenticator… At 05:05:42, an API was created, according to the user’s account.
the wallet had previously been hacked on September 24, which MEXC detected, froze and partially reversed… What the exchange did not revoke was an API key the attacker created at 21:05:42 on that same day, just 83 seconds after their second login into the compromised account.
What would settle it: MEXC’s internal security logs or the account’s API key creation record disclosed by the exchange.
Treat the amount stolen, the settlement, and the 24-hour withdrawal lock timeline as established across both reports; the exact date and time the attacker’s API key was created remains unresolved and should not be cited as settled until MEXC or the user publishes the underlying account/API logs.
Treat the amount stolen, the settlement, and the 24-hour withdrawal lock timeline as established across both reports; the exact date and time the attacker’s API key was created remains unresolved and should not be cited as settled until MEXC or the user publishes the underlying account/API logs.
Original source: AltcoinGordon
Syndicated coverage. Originally reported by altcoingordon.com.