NewsCryptoWEMIX, Garden Finance Security Incidents Add to Record 2026 Crypto Breaches

WEMIX, Garden Finance Security Incidents Add to Record 2026 Crypto Breaches

Author: BeInCrypto·

Key Takeaways

  • •WEMIX said about 5,225,525 WEMIX$ were issued without authorization after ownership of a related contract was compromised.
  • •The unauthorized WEMIX$ was converted into WEMIX and USDC.e, bridged to Ethereum and BSC, and later exchanged for assets including ETH and USDT.
  • •WEMIX temporarily suspended all bridges connected to WEMIX3.0, along with Chainlink CCIP and PLAY Bridge.
  • •Garden Finance took its application offline after detecting unusual activity, while Blockaid reported roughly $450,000 in USDT drained across Ethereum, Base, Arbitrum and BSC.
  • •TRM Labs recorded 207 crypto hacks in H1 2026, while reported losses declined to about $972 million from roughly $2.3 billion in H1 2025.
WEMIX, Garden Finance Security Incidents Add to Record 2026 Crypto Breaches

WEMIX and Garden Finance disclosed separate security incidents over the weekend, adding to a year in which crypto attack counts have reached record levels even as total losses have fallen from 2025.

WEMIX said ownership of a WEMIX$-related contract was compromised, leading to unauthorized issuance. Garden Finance, meanwhile, took its application offline after detecting unusual activity and said it was conducting a full investigation.

The incidents underscore two recurring pressure points for decentralized applications: smart-contract permissions that can affect token supply, and cross-chain infrastructure that can move assets quickly across networks once an exploit begins.

WEMIX Reports Unauthorized WEMIX$ Issuance

WEMIX reported abnormal transactions on the evening of July 26. According to the platform’s official update, about 5,225,525 WEMIX$ were issued without authorization.

The unauthorized supply was converted into 30,736 WEMIX and 724,198.27 USDC.e. The assets then moved through bridges to Ethereum and BSC before being converted into other assets, including Ether (ETH) and Tether (USDT).

WEMIX said some of the assets reached centralized exchanges. The company said it has requested that exchanges and stablecoin issuers freeze wallets connected to the attacker. Such requests are a common post-incident response when assets touch centralized venues or issuers with the ability to restrict specific wallets.

“All bridges connected to and from WEMIX3.0 have been suspended temporarily. Chainlink CCIP has been suspended, and the PLAY Bridge has also been temporarily suspended,” the platform said.

The company said the cause of the incident remains under investigation and that the figures may change as the review continues.

Garden Finance Takes App Offline

Separately, Blockaid flagged an exploit involving Garden Finance. At the time of its alert, the firm said about $450,000 in USDT had been drained across Ethereum, Base, Arbitrum (ARB), and BSC.

Garden Finance addressed the incident in an X post on July 26, saying:

“we identified unusual activity on garden today and are looking into it. the app is temporarily offline while we complete a full investigation. we'll share updates as soon as we have more information.”

Taking an application offline can limit additional user interaction while teams review contracts, transaction paths, and affected assets, though Garden Finance had not provided further details in the cited update.

Crypto Hacks Reach Record Count in 2026

The incidents come as crypto security firms report a sharp rise in the number of attacks this year. TRM Labs recorded 207 hacks in the first half of 2026, more than double the 83 logged during the same period a year earlier. The firm said the total was the highest it had recorded in any six-month period.

However, total losses moved in the opposite direction. TRM Labs said roughly $972 million was stolen in H1 2026, compared with about $2.3 billion in H1 2025.

The figures point to a split between attack frequency and attack severity. More incidents have occurred, while the largest losses have remained concentrated among a smaller number of high-value targets, including KelpDAO and Drift Protocol.

Last week showed a similar pattern. Lookonchain counted three attacks totaling $35.55 million, involving AFX Trade, the Verus Ethereum bridge, and B2 Network.