Key Points
- Unauthorized access to WEMIX$ stablecoin contract owner privileges occurred on July 26, enabling the minting of 5.23 million tokens.
- Stolen tokens were exchanged for 30,736 WEMIX and 724,198 USDC.e, then transferred across Ethereum and BNB Smart Chain.
- All WEMIX bridges, liquidity pools, PNIX exchange, and WEMIX$ Module operations were immediately suspended following the incident.
- Multiple cryptocurrency exchanges have frozen addresses connected to the breach after receiving emergency requests from WEMIX.
- This marks WEMIX’s second significant security incident since February 2025, when approximately $6 million was stolen from the network.
WEMIX, a blockchain gaming platform, disclosed on July 26 that unauthorized parties had successfully gained administrative control over its WEMIX$ stablecoin smart contract. The security incident was detected at around 9:17 UTC.
Exploiting this elevated access, the perpetrator created approximately 5.23 million WEMIX$ tokens through unauthorized minting operations. These illicitly generated tokens were subsequently exchanged for 30,736 WEMIX tokens and 724,198.27 USDC.e.
The stolen USDC.e was then transferred via bridge protocols to both Ethereum and BNB Smart Chain networks. Following the cross-chain transfers, portions of the funds were exchanged for Ether and Tether’s USDT, with the proceeds distributed among numerous wallet addresses.
A portion of the compromised assets eventually made its way to centralized cryptocurrency exchanges. WEMIX successfully traced the attacker’s wallet addresses and immediately reached out to both exchanges and stablecoin issuers with urgent freeze requests. The company has verified that multiple trading platforms have already locked the identified addresses.
However, WEMIX has not disclosed which specific exchanges took action or provided details on the exact amount of frozen or recovered funds.
Network-Wide Service Interruptions Implemented
Following the security incident, WEMIX immediately implemented emergency measures by shutting down all bridging infrastructure connected to the WEMIX3.0 ecosystem. This included suspending both Chainlink CCIP and the PLAY Bridge services.
All trading activity in impacted liquidity pools was frozen. WEMIX pulled foundation-backed liquidity from affected pools and disabled both the WEMIX$ Module and PNIX decentralized exchange platform while conducting a comprehensive audit of contract access permissions.
According to WEMIX’s statement, the investigation into how the owner-level privileges were compromised remains ongoing. The team cautioned that preliminary damage estimates may be adjusted as their cross-chain investigation progresses.
Market data from CoinGecko revealed that WEMIX$ plummeted to near its all-time low following news of the breach, experiencing a weekly price drop of approximately 98.9%. The collapse was triggered by the unauthorized token creation and subsequent rapid liquidation.
The timing of this breach is particularly unfortunate, as WEMIX had been actively transitioning away from WEMIX$ in favor of USDC.e throughout its gaming ecosystem and financial services. The company announced in March that WEMIX PLAY would migrate its primary currency from WEMIX$ to USDC.e, with the complete changeover planned for April.
Another Major Hack Within Two Years
This current security failure represents the second significant breach WEMIX has experienced in recent history. Back in February 2025, malicious actors successfully extracted roughly 8.6 million WEMIX tokens from the Play Bridge Vault, valued at approximately $6.04 million during the time of theft.
That previous incident generated substantial controversy due to WEMIX’s delayed disclosure, which came several days after the breach was initially discovered. In response, South Korea’s leading cryptocurrency exchanges—Upbit, Bithumb, Coinone, Korbit, and Gopax—took coordinated action to delist WEMIX tokens in June 2025.
This latest security incident occurred just as the project was nearing the eligibility window for seeking relisting on Korean domestic exchanges. WEMIX has not yet published a comprehensive post-mortem analysis, identified the origin of the credential compromise, or disclosed the final amount of unrecovered assets.



