Key Points
- A cybercriminal seized owner-level access to WEMIX$ stablecoin smart contract on July 26, illegally creating 5.23 million tokens.
- Stolen tokens were swapped for 30,736 WEMIX coins and 724,198 USDC.e, then transferred to Ethereum and BNB Smart Chain networks.
- All bridge services, liquidity pools, PNIX exchange, and WEMIX$ Module operations were immediately suspended by the platform.
- Multiple cryptocurrency exchanges implemented address freezes following emergency requests from WEMIX officials.
- This security incident follows another devastating attack in 2025 that resulted in approximately $6 million in losses and triggered delistings from South Korea’s leading crypto platforms.
The WEMIX blockchain gaming platform revealed on July 26 that an unauthorized party had successfully obtained administrative privileges for its WEMIX$ stablecoin smart contract. The security compromise was detected starting at roughly 9:17 UTC.
Using the hijacked administrative rights, the perpetrator generated approximately 5.23 million WEMIX$ tokens through unauthorized minting operations. These illegally created tokens were subsequently exchanged for 30,736 WEMIX coins and 724,198.27 USDC.e.
The USDC.e funds were then transferred via blockchain bridges to Ethereum and BNB Smart Chain networks. Following these transfers, the attacker converted segments of the stolen cryptocurrency into Ether and Tether’s USDT, distributing the proceeds among numerous wallet addresses.
A portion of the compromised assets eventually arrived at centralized cryptocurrency platforms. After identifying the malicious wallets, WEMIX immediately contacted exchange operators and stablecoin providers to request emergency freezing of affected assets. According to the company’s statement, multiple exchanges have already implemented freezes on connected wallet addresses.
The organization has not disclosed which specific exchanges participated in the freeze or revealed the exact amount of funds successfully frozen or retrieved.
Platform Operations Halted Following Attack
Following the security breach, WEMIX implemented an immediate shutdown of all bridge infrastructure connecting to its WEMIX3.0 blockchain network. This emergency suspension affected Chainlink CCIP and the PLAY Bridge services.
All trading activity in compromised liquidity pools was immediately frozen. The organization removed foundation-backed liquidity and suspended both the WEMIX$ Module and PNIX decentralized exchange platform while conducting a comprehensive audit of contract authorization settings.
According to WEMIX officials, investigators are still working to determine how the owner-privilege breach occurred. The team cautioned that preliminary damage estimates may be revised as the investigation expands across various blockchain networks.
Market data from CoinGecko indicated WEMIX$ plummeted near its all-time low following the exploit, experiencing a devastating weekly drop of approximately 98.9%. This collapse directly resulted from the unauthorized token creation and immediate liquidation of the freshly minted supply.
The timing of this breach is particularly significant as WEMIX had been actively transitioning away from WEMIX$ toward USDC.e throughout its gaming ecosystem and financial infrastructure. Earlier in March, the organization announced that WEMIX PLAY would migrate its primary currency from WEMIX$ to USDC.e, with full implementation targeted for April.
Latest Attack Marks Second Critical Vulnerability Exploitation
This recent security failure represents the second major breach affecting WEMIX infrastructure within a two-year period. During February 2025, malicious actors successfully extracted roughly 8.6 million WEMIX tokens, valued at approximately $6.04 million, from the Play Bridge Vault system.
The previous incident generated substantial controversy when WEMIX delayed public disclosure for multiple days after initially detecting the compromise. South Korea’s prominent cryptocurrency exchangesāUpbit, Bithumb, Coinone, Korbit, and Gopaxācollectively removed WEMIX from their trading platforms in June 2025.
This second breach occurred just as the project was nearing eligibility to submit relisting applications with domestic Korean exchanges. WEMIX has yet to publish a comprehensive incident analysis, identify the origin of the compromised administrative credentials, or officially confirm the final amount of unrecovered losses.


