WEMIX confirmed that an attacker took management of proprietor privileges linked to its WEMIX$ stablecoin contract on July 26.
Abstract
- Compromised proprietor privileges allowed an attacker to mint roughly 5.23 million new WEMIX$ with out authorization.
- WEMIX suspended bridges, liquidity swimming pools and associated companies whereas exchanges traced and froze suspect funds.
- The incident follows WEMIX’s 2025 bridge hack and comes throughout its transition towards USDC.e companies.
The entry allowed the attacker to create tokens with out approval and transfer property by way of a number of blockchain networks. An early Korean report valued the irregular issuance and transfers at about $6.25 million. A later WEMIX replace gave a extra detailed determine of roughly 5.23 million WEMIX$ minted.
The corporate stated the incident started at about 9:17 UTC, or 6:17 p.m. in South Korea. WEMIX recognized suspected attacker wallets and requested exchanges and stablecoin issuers to assist freeze the property. It additionally began tracing the transactions with blockchain safety firms. The reason for the owner-privilege compromise stays beneath investigation, and WEMIX warned that its preliminary figures could change.
Attacker converts minted WEMIX$ into different property
Based on WEMIX’s official incident replace, the attacker issued about 5,225,525 WEMIX$ with out permission. The attacker then transformed the tokens into 30,736 WEMIX and 724,198.27 USDC.e. This official breakdown differs from the primary $6.25 million estimate, which coated the broader irregular issuance and motion reported on-chain.
The attacker bridged USDC.e to Ethereum and BNB Sensible Chain earlier than swapping elements of the funds into property together with ETH and USDT. Some property additionally reached centralised exchanges. WEMIX stated a number of exchanges had frozen linked addresses after receiving requests for assist. Nonetheless, the corporate has not named these exchanges or acknowledged how a lot cash stays frozen, recoverable or beneath attacker management.
The corporate has not stated whether or not extraordinary person balances have been instantly affected. It additionally has not printed a full listing of compromised contracts, transaction hashes or restoration quantities. These particulars matter as a result of the nominal worth of tokens created doesn’t equal the quantity efficiently transformed and eliminated. WEMIX stated its evaluate now continues throughout a number of networks.
WEMIX suspends bridges and affected companies
WEMIX briefly stopped all bridges linked to the WEMIX3.0 community. The suspension coated Chainlink CCIP and the PLAY Bridge. The corporate additionally paused buying and selling in affected liquidity swimming pools, eliminated foundation-provided liquidity and stopped the WEMIX$ Module and PNIX decentralised trade. These steps aimed to dam extra transfers whereas the group reviewed contract permissions and associated programs.
In its first discover, WEMIX stated it had confirmed irregular transactions and was “at the moment analysing the reason for the incident and taking emergency measures.” The corporate stated it might publish extra findings as investigators affirm them. It additionally requested customers to depend on official channels as an alternative of unverified posts. WEMIX could contact legislation enforcement businesses if tracing work identifies proof that requires formal motion.
Stablecoin loses peg throughout deliberate USDC.e transition
WEMIX$ was designed to trace the U.S. greenback on the WEMIX3.0 community. CoinGecko information confirmed the stablecoin falling near its recorded low after the breach, with a weekly decline of about 98.9%. The worth transfer adopted the unauthorised minting and speedy conversion of newly created tokens, though the ultimate monetary loss stays separate from the quantity minted.
The incident got here whereas WEMIX was already changing WEMIX$ with USDC.e throughout its gaming and monetary companies. In March, the corporate introduced that WEMIX PLAY would change its base foreign money from WEMIX$ to USDC.e. It scheduled the principle service transition for April and started closing or reorganising older WEMIX$ swimming pools. The breached contract due to this fact belonged to a stablecoin system already shifting towards lowered use.
New breach follows the 2025 Play Bridge hack
The newest occasion follows a separate WEMIX safety breach in February 2025. As crypto.information beforehand reported, attackers eliminated about 8.6 million WEMIX tokens, then price roughly $6.04 million, from the Play Bridge Vault. WEMIX shut the affected server and reported the case to the Seoul Metropolitan Police Company’s cyber investigation unit.
That earlier incident additionally led to criticism as a result of WEMIX disclosed it a number of days after discovering the breach. South Korea’s main exchanges later delisted WEMIX in June 2025. As associated crypto.information protection famous, Upbit, Bithumb, Coinone, Korbit and Gopax coordinated the motion by way of the Digital Asset Change Alliance. The brand new contract breach occurred because the undertaking approached the interval when a future home relisting software might turn into attainable.
WEMIX has not launched a remaining assault report, named the supply of the stolen proprietor credentials or confirmed the whole unrecovered loss. Its newest response focuses on pockets tracing, service suspensions, asset-freeze requests and contract evaluation. Additional notices are anticipated to make clear whether or not the attacker exploited code, obtained a non-public key or accessed an inside account with contract-control rights.


