WEMIX Suspends Bridges and Liquidity Pools After $724K WEMIX$ Exploit
Key Takeaways
- •WEMIX said abnormal transactions began at 18:17 UTC+9 on July 26, 2026, after an attacker gained control of a contract tied to WEMIX$.
- •Investigators found that approximately 5,225,525 tokens were minted illegally and later exchanged for WEMIX and USDC.e.
- •The USDC.e was transferred from WEMIX to Ethereum and BNB Smart Chain, where it was sold for assets including ETH and USDT.
- •WEMIX temporarily suspended bridges, affected liquidity pools, several ecosystem services, NFT marketplace activity, and selected game-linked blockchain features.
- •The foundation has identified attacker wallets, requested freezes from exchanges and stablecoin issuers, and is auditing the compromised contract.

WEMIX said it has taken emergency action across its ecosystem after detecting a security incident involving its WEMIX$ stablecoin system on July 26. According to the blockchain team, the incident led to the unauthorized minting of more than 5.22 million WEMIX$ and the transfer of funds across multiple blockchains.
The response affects core infrastructure used for token transfers, decentralized exchange activity, NFT marketplace functions, and blockchain features connected to games in the WEMIX ecosystem.
WEMIX Reviews Unauthorized WEMIX$ Minting
In an official statement, WEMIX said abnormal transactions began at 18:17 (UTC+9) on July 26, 2026. Based on its initial analysis, an attacker gained control of one of the contracts connected to WEMIX$ and used it to mint additional tokens.
Investigators found that approximately 5,225,525 WEMIX was minted illegally. The attacker then exchanged the newly minted tokens for 30,736 WEMIX and about 724,198.27 USDC.e.
WEMIX said the USDC.e was then moved from the WEMIX blockchain to both Ethereum and BNB Smart Chain (BSC), where it was sold for assets including ETH and USDT. Investigators also confirmed that some of the funds reached centralized cryptocurrency exchanges.
The cross-chain movement is significant because bridge infrastructure can allow assets connected to an incident on one network to move quickly into other ecosystems, making freezes, tracing, and recovery efforts more time-sensitive.
The company said the findings remain preliminary and may change as forensic analysis continues.
Emergency Measures Implemented Across the Ecosystem
WEMIX said it activated several emergency protections throughout its blockchain ecosystem to contain the incident and prevent additional unauthorized transfers.
Bridges, Liquidity Pools, and Services Suspended
The team temporarily suspended all bridges connected to WEMIX3.0, including Chainlink CCIP and the PLAY Bridge. The measure was intended to stop further movement of assets linked to the incident.
The WEMIX Foundation also temporarily halted trading across affected liquidity pools, including WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$, and PLAY-WEMIX$. The foundation said it immediately withdrew its own liquidity from those pools to help contain the incident and reduce additional risk.
Liquidity pools are a key part of decentralized exchange markets because they allow users to swap tokens without a traditional order book. Suspending affected pools can limit further trading of assets tied to an exploit while investigators determine the scope of the compromise.
Liquidity supplied by the WEMIX Foundation was also removed from the affected pools.
Several ecosystem services were temporarily disabled, including the WEMIX$ Module, PNIX DEX, and related backend infrastructure. NFT marketplace trading and bidding functions were restricted, along with selected blockchain features integrated into games, while security reviews were carried out.
Asset Recovery Efforts Continue
WEMIX said it has identified the attacker’s wallet addresses and is actively monitoring the movement of funds across multiple blockchains.
Exchanges Asked to Freeze Suspicious Assets
The foundation said it has sent requests to several cryptocurrency exchanges and stablecoin issuers asking them to freeze assets and cooperate with the investigation. According to the latest update, some exchanges have already frozen addresses linked to the attacker.
WEMIX said it is also working to recover the compromised contract, complete an audit of that contract, and review related variants currently being developed elsewhere. The main objective is to determine how the attacker obtained control of the contract and whether additional vulnerabilities exist in the system.
Although some services remain partially suspended, WEMIX said protecting user assets and restoring ecosystem security are its top priorities. The company said it will provide further updates on investigation findings, recovery efforts, and long-term security improvements as the process continues.