Key Highlights
- A malicious actor seized owner-level access to WEMIX$ stablecoin smart contract on July 26, creating 5.23 million unauthorized tokens.
- Stolen tokens were exchanged for 30,736 WEMIX and 724,198 USDC.e, then transferred to Ethereum and BNB Smart Chain networks.
- All bridge operations, liquidity pools, and associated platforms including PNIX exchange and WEMIX$ Module were immediately halted.
- Multiple cryptocurrency exchanges implemented freezes on identified addresses following urgent requests from WEMIX.
- This security incident follows a February 2025 attack that resulted in approximately $6 million in losses and triggered delistings across South Korean trading platforms.
The WEMIX blockchain gaming platform disclosed on July 26 that a malicious actor had successfully compromised owner-level permissions associated with its WEMIX$ stablecoin smart contract. The security incident commenced around 9:17 UTC.
Leveraging the unauthorized access, the perpetrator fabricated approximately 5.23 million WEMIX$ tokens through illegitimate minting operations. These freshly created tokens were subsequently exchanged for 30,736 WEMIX tokens and 724,198.27 USDC.e.
The USDC.e holdings were transferred via bridge protocols to Ethereum and BNB Smart Chain networks. Following the transfers, segments of the stolen assets were converted into Ether and Tether’s USDT, then dispersed among numerous wallet addresses.
A portion of the compromised assets made their way to centralized trading platforms. WEMIX tracked the perpetrator’s wallet addresses and reached out to exchanges and stablecoin providers, requesting immediate freezing of associated funds. The organization confirmed that multiple trading platforms have successfully frozen addresses connected to the breach.
WEMIX has withheld information regarding which specific exchanges took action or disclosed the quantity of funds that have been frozen or reclaimed.
Network-Wide Service Interruptions Implemented
Following the security compromise, WEMIX enacted immediate suspensions across all bridging mechanisms connected to the WEMIX3.0 infrastructure. These emergency measures encompassed Chainlink CCIP and the PLAY Bridge protocols.
Operations within impacted liquidity pools were similarly suspended. The organization removed foundation-supplied liquidity and disabled both the WEMIX$ Module and PNIX decentralized exchange platform during its examination of contract authorization structures.
WEMIX stated that investigators are still determining how the owner-privilege breach occurred. The team cautioned that preliminary damage assessments may be revised as their cross-network analysis progresses.
According to CoinGecko tracking data, WEMIX$ plummeted near its all-time low following the exploit, registering approximately a 98.9% weekly decrease. This dramatic decline resulted from the unauthorized token creation and swift conversion activities.
The attack materialized during WEMIX’s ongoing migration away from WEMIX$ toward USDC.e throughout its gaming and financial product ecosystem. The company had announced in March that WEMIX PLAY would transition its primary currency from WEMIX$ to USDC.e, with full implementation planned for April.
WEMIX’s Second Critical Security Failure Within Two Years
This current security breach represents the second significant attack on WEMIX infrastructure. During February 2025, malicious actors successfully extracted roughly 8.6 million WEMIX tokens from the Play Bridge Vault, valued at approximately $6.04 million during the incident.
That previous compromise generated substantial backlash as WEMIX delayed public disclosure for multiple days following breach detection. South Korea’s leading cryptocurrency exchanges, including Upbit, Bithumb, Coinone, Korbit, and Gopax, executed a coordinated WEMIX delisting in June 2025.
This latest security failure occurred as the project neared eligibility for potential relisting applications on domestic Korean exchanges. WEMIX has yet to publish a comprehensive incident analysis, identify the origin of the compromised administrative credentials, or verify the final amount of unrecovered losses.





