Monday, July 27, 2026

WEMIX Smart Contract Compromised, $6.25M in Tokens Illegally Minted

Neon-lit scene of a cracked WEMIX contract interface, glowing admin keys spill from a vault as tokens spiral upward.

WEMIX has confirmed a security breach involving ownership privileges for contracts linked to WEMIX$, allowing an attacker to issue approximately 5,225,525 tokens without authorization. The abnormal transactions began on July 26, 2026, at 18:17 Korea Standard Time.

The incident resulted from compromised administrative control rather than a confirmed flaw in WEMIX3.0’s consensus or cryptography. The project is still investigating how the ownership privileges were obtained and has not published a complete root-cause analysis.

Administrative Privileges Bypassed Supply Controls

The attacker used the compromised authority to execute issuance and conversion functions that appeared valid to the contracts. This allowed new WEMIX$ supply to enter the system without the standard authorization expected under the stablecoin’s operating framework.

WEMIX reported that the unauthorized tokens were converted into approximately 30,736 WEMIX and 724,198.27 USDC.e. Part of the USDC.e was then bridged to Ethereum and BNB Chain, exchanged into assets including ETH and USDT, and distributed across multiple addresses.

Those figures make an important distinction: the 5.225 million WEMIX$ issuance does not establish a realized $6.25 million loss. The final financial impact will depend on conversion proceeds, remaining unauthorized supply, frozen assets and any capital ultimately recovered.

The breach highlights the concentration of risk created by smart contract owner privileges. A contract can operate exactly as programmed while still producing unauthorized outcomes when an attacker gains control of the account permitted to mint, upgrade or administer it.

WEMIX Suspends Services and Traces Funds

WEMIX said it has identified attacker-linked wallets and requested assistance from exchanges and stablecoin issuers. Some addresses have already been submitted for freezing as the project tracks funds across WEMIX3.0, Ethereum and BNB Chain.

The response also included temporary suspension of bridges and affected ecosystem services to prevent additional movement. WEMIX is reviewing related contracts with internal teams and external security specialists while assessing whether similar administrative exposure exists elsewhere.

The project has not yet disclosed whether the compromise originated from stolen keys, internal access or another operational failure. Compensation plans, restoration timing and the final status of the unauthorized tokens also remain unresolved.

The incident represents an administrative-key and contract-control failure rather than a confirmed compromise of the WEMIX3.0 base network. The next critical disclosures will be the root cause, final loss reconciliation, contract remediation, recovered assets and any changes to WEMIX’s ownership and minting controls.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.