
WEMIX confirmed that an attacker took control of owner privileges linked to its WEMIX$ stablecoin contract on July 26.
Summary
- Compromised owner privileges allowed an attacker to mint approximately 5.23 million new WEMIX$ without authorization.
- WEMIX suspended bridges, liquidity pools and related services while exchanges traced and froze suspect funds.
- The incident follows WEMIX’s 2025 bridge hack and comes during its transition toward USDC.e services.
The access allowed the attacker to create tokens without approval and move assets through several blockchain networks. An early Korean report valued the abnormal issuance and transfers at about $6.25 million. A later WEMIX update gave a more detailed figure of roughly 5.23 million WEMIX$ minted.
The company said the incident began at about 9:17 UTC, or 6:17 p.m. in South Korea. WEMIX identified suspected attacker wallets and asked exchanges and stablecoin issuers to help freeze the assets. It also started tracing the transactions with blockchain security companies. The cause of the owner-privilege compromise remains under investigation, and WEMIX warned that its initial figures may change.
Attacker converts minted WEMIX$ into other assets
According to WEMIX’s official incident update, the attacker issued about 5,225,525 WEMIX$ without permission. The attacker then converted the tokens into 30,736 WEMIX and 724,198.27 USDC.e. This official breakdown differs from the first $6.25 million estimate, which covered the wider abnormal issuance and movement reported on-chain.
The attacker bridged USDC.e to Ethereum and BNB Smart Chain before swapping parts of the funds into assets including ETH and USDT. Some assets also reached centralised exchanges. WEMIX said several exchanges had frozen linked addresses after receiving requests for help. However, the company has not named those exchanges or stated how much money remains frozen, recoverable or under attacker control.
The company has not said whether ordinary user balances were directly affected. It also has not published a full list of compromised contracts, transaction hashes or recovery amounts. Those details matter because the nominal value of tokens created does not equal the amount successfully converted and removed. WEMIX said its review now continues across several networks.
WEMIX suspends bridges and affected services
WEMIX temporarily stopped all bridges connected to the WEMIX3.0 network. The suspension covered Chainlink CCIP and the PLAY Bridge. The company also paused trading in affected liquidity pools, removed foundation-provided liquidity and stopped the WEMIX$ Module and PNIX decentralised exchange. These steps aimed to block additional transfers while the team reviewed contract permissions and related systems.
In its first notice, WEMIX said it had confirmed abnormal transactions and was “currently analysing the cause of the incident and taking emergency measures.” The company said it would publish more findings as investigators confirm them. It also asked users to rely on official channels instead of unverified posts. WEMIX may contact law enforcement agencies if tracing work identifies evidence that requires formal action.
Stablecoin loses peg during planned USDC.e transition
WEMIX$ was designed to track the U.S. dollar on the WEMIX3.0 network. CoinGecko data showed the stablecoin falling close to its recorded low after the breach, with a weekly decline of about 98.9%. The price move followed the unauthorised minting and rapid conversion of newly created tokens, although the final financial loss remains separate from the amount minted.
The incident came while WEMIX was already replacing WEMIX$ with USDC.e across its gaming and financial services. In March, the company announced that WEMIX PLAY would change its base currency from WEMIX$ to USDC.e. It scheduled the main service transition for April and began closing or reorganising older WEMIX$ pools. The breached contract therefore belonged to a stablecoin system already moving toward reduced use.
New breach follows the 2025 Play Bridge hack
The latest event follows a separate WEMIX security breach in February 2025. As crypto.news previously reported, attackers removed about 8.6 million WEMIX tokens, then worth roughly $6.04 million, from the Play Bridge Vault. WEMIX shut the affected server and reported the case to the Seoul Metropolitan Police Agency’s cyber investigation unit.
That earlier incident also led to criticism because WEMIX disclosed it several days after discovering the breach. South Korea’s major exchanges later delisted WEMIX in June 2025. As related crypto.news coverage noted, Upbit, Bithumb, Coinone, Korbit and Gopax coordinated the action through the Digital Asset Exchange Alliance. The new contract breach occurred as the project approached the period when a future domestic relisting application could become possible.
WEMIX has not released a final attack report, named the source of the stolen owner credentials or confirmed the total unrecovered loss. Its latest response focuses on wallet tracing, service suspensions, asset-freeze requests and contract analysis. Further notices are expected to clarify whether the attacker exploited code, obtained a private key or accessed an internal account with contract-control rights.

