NewsCryptoWEMIX Suspends Bridges After Owner-Key Breach Mints 5.23 Million WEMIX$

WEMIX Suspends Bridges After Owner-Key Breach Mints 5.23 Million WEMIX$

Author: crypto.news·

Key Takeaways

  • •WEMIX reported that the attacker issued about 5,225,525 WEMIX$ after compromising owner privileges on the stablecoin contract.
  • •The attacker converted the tokens into 30,736 WEMIX and 724,198.27 USDC.e before moving assets across multiple networks.
  • •WEMIX halted WEMIX3.0 bridges, affected liquidity pools, the WEMIX$ Module and the PNIX decentralized exchange during its investigation.
  • •Several exchanges froze linked addresses after WEMIX requested assistance, but the company has not disclosed the frozen or recoverable amount.
  • •The incident follows a separate 2025 Play Bridge Vault breach in which about 8.6 million WEMIX tokens were removed.
WEMIX Suspends Bridges After Owner-Key Breach Mints 5.23 Million WEMIX$

WEMIX confirmed that an attacker gained control of owner privileges tied to its WEMIX$ stablecoin contract on July 26, enabling the unauthorized minting of about 5.23 million WEMIX$.

The company suspended bridges, liquidity pools and related services after the breach, while exchanges worked to trace and freeze suspected funds. The incident comes after WEMIX’s 2025 bridge hack and during the project’s ongoing transition from WEMIX$ toward USDC.e services.

The compromised access allowed the attacker to create tokens without approval and move assets across multiple blockchain networks. Owner privileges are high-level smart contract permissions that can control functions such as minting or pausing, which makes their compromise especially sensitive for token systems. An early Korean report estimated the abnormal issuance and transfers at about $6.25 million. A later WEMIX update provided a more specific figure of roughly 5.23 million WEMIX$ minted.

JUST IN: WEMIX suspends bridge services and wemix-token:native trading after an attacker exploited a linked smart contract, stealing approximately $724,000. The network has frozen affected funds and paused key services while the investigation continues. pic.twitter.com/2KUPwTgOd3 — EyeWhales (@EyeWhales) July 27, 2026

JUST IN: WEMIX suspends bridge services and wemix-token:native trading after an attacker exploited a linked smart contract, stealing approximately $724,000. The network has frozen affected funds and paused key services while the investigation continues. pic.twitter.com/2KUPwTgOd3

WEMIX said the incident began at about 9:17 UTC, or 6:17 p.m. in South Korea. The company identified suspected attacker wallets and asked exchanges and stablecoin issuers to help freeze the assets. It also began tracing transactions with blockchain security companies. The cause of the owner-privilege compromise remains under investigation, and WEMIX cautioned that its initial figures may change.

Attacker converts minted WEMIX$ into other assets

According to WEMIX’s official incident update, the attacker issued about 5,225,525 WEMIX$ without authorization. The attacker then converted the tokens into 30,736 WEMIX and 724,198.27 USDC.e. That official breakdown differs from the first $6.25 million estimate, which covered broader abnormal issuance and on-chain movement.

The attacker bridged USDC.e to Ethereum and BNB Smart Chain before swapping portions of the funds into assets including ETH and USDT. Some assets also reached centralized exchanges. WEMIX said several exchanges froze linked addresses after receiving assistance requests, but the company has not named those exchanges or disclosed how much money remains frozen, recoverable or under the attacker’s control.

WEMIX has not said whether ordinary user balances were directly affected. It has also not published a full list of compromised contracts, transaction hashes or recovery amounts. Those details remain important because the nominal value of the tokens created is not the same as the amount successfully converted and removed. In cross-chain incidents, funds can move through bridge contracts, decentralized exchanges and centralized platforms within a short period, so investigators often separate minted supply, swapped assets and frozen balances when calculating losses. WEMIX said its review is continuing across several networks.

WEMIX suspends bridges and affected services

WEMIX temporarily halted all bridges connected to the WEMIX3.0 network. The suspension included Chainlink CCIP and the PLAY Bridge. The company also paused trading in affected liquidity pools, removed foundation-provided liquidity and stopped the WEMIX$ Module and the PNIX decentralized exchange.

The measures were intended to block additional transfers while the team reviewed contract permissions and related systems. In its first notice, WEMIX said it had confirmed abnormal transactions and was “currently analysing the cause of the incident and taking emergency measures.”

The company said it would release additional findings as investigators confirm them. It also urged users to rely on official channels rather than unverified posts. WEMIX may contact law enforcement agencies if tracing work identifies evidence requiring formal action.

Stablecoin loses peg during planned USDC.e transition

WEMIX$ was designed to track the U.S. dollar on the WEMIX3.0 network. CoinGecko data showed the stablecoin trading close to its recorded low after the breach, with a weekly decline of about 98.9%. The decline followed the unauthorized minting and rapid conversion of newly created tokens, though the final financial loss remains separate from the total amount minted.

The incident occurred while WEMIX was already replacing WEMIX$ with USDC.e across its gaming and financial services. In March, the company announced that WEMIX PLAY would change its base currency from WEMIX$ to USDC.e. It scheduled the main service transition for April and began closing or reorganizing older WEMIX$ pools. The breached contract therefore belonged to a stablecoin system that was already moving toward reduced use.

New breach follows 2025 Play Bridge hack

The latest incident follows a separate WEMIX security breach in February 2025. As crypto.news previously reported, attackers removed about 8.6 million WEMIX tokens, then worth roughly $6.04 million, from the Play Bridge Vault. WEMIX shut down the affected server and reported the case to the Seoul Metropolitan Police Agency’s cyber investigation unit.

That earlier incident also drew criticism because WEMIX disclosed it several days after discovering the breach. South Korea’s major exchanges later delisted WEMIX in June 2025. As related crypto.news coverage noted, Upbit, Bithumb, Coinone, Korbit and Gopax coordinated the action through the Digital Asset Exchange Alliance. The new contract breach occurred as the project approached the period when a future domestic relisting application could become possible.

WEMIX has not released a final attack report, identified the source of the stolen owner credentials or confirmed the total unrecovered loss. Its latest response is focused on wallet tracing, service suspensions, asset-freeze requests and contract analysis. Further notices are expected to clarify whether the attacker exploited code, obtained a private key or accessed an internal account with contract-control rights.