WEMIX Reportedly Suffers Another Breach as $5.2M in Stablecoins Are Minted
- WEMIX experienced a security breach allowing an attacker to mint $5.2 million worth of WEMIX$ stablecoins.
- The company is collaborating with security firms to trace the stolen assets and has suspended several services.
- Investigation is ongoing to determine how the attack compromised contract privileges and the potential for fund recovery.
The WEMIX ecosystem reportedly suffered another security breach on July 26 after an attacker gained control of administrator privileges linked to the WEMIX$ stablecoin contract.
The suspicious activity began at approximately 6:17 p.m. Korean time, according to a report from BloomingBit. The attacker allegedly used the compromised permissions to mint about 5,225,525 WEMIX$ without authorization. The newly created tokens had a nominal value of roughly $5.2 million.
The attacker then reportedly exchanged the tokens for approximately 30,736 WEMIX and 724,198 USDC.e. The USDC.e was transferred from WEMIX3.0 to Ethereum and BNB Chain before portions were converted into assets such as ETH and USDT.
Some of the funds also reached centralized cryptocurrency exchanges. WEMIX said it had contacted exchanges and stablecoin issuers to request freezes on wallets connected to the incident. The company is working with blockchain security firms to trace the remaining assets.
WEMIX temporarily suspended all bridges connected to WEMIX3.0, including Chainlink CCIP and the PLAY Bridge. The team also paused several liquidity pools, the WEMIX$ Module, the PNIX decentralized exchange, NFT trading, and blockchain features within some games.
In an official incident update, the team said investigators had not yet determined how the contract privileges were compromised. It added that the reported figures could change as the investigation continues.
The incident follows a separate February 2025 breach involving the Play Bridge Vault. That attack reportedly resulted in the unauthorized withdrawal of around 8.65 million WEMIX tokens.
The next update should clarify how the attacker obtained the contract permissions and how much of the converted funds can be recovered.
The industry has been riddled with crypto incidents of late, with new ones being reported almost daily now.
Just today, we covered the breach of Triple-A, a Singapore-based
