
According to WEMIX reports, an attacker gained unauthorized control of owner privileges linked to the WEMIX$ stablecoin contract on July 26, 2025, beginning at approximately 9:17 UTC. The compromised owner privileges enabled the attacker to mint approximately 5.23 million new WEMIX$ without proper authorization. The incident resulted in $724,198.27 in USDC.e being moved across blockchain networks, with the attacker converting the minted tokens into 30,736 WEMIX and 724,198.27 USDC.e. An early Korean report had initially valued the abnormal issuance and transfers at about $6.25 million. Onchain investigator Specter flagged an address beginning 0xc921a66e during the first public tracing of the transactions, while WEMIX later identified additional wallets and requested freezes from centralized exchanges and stablecoin issuers.
WEMIX temporarily suspended all bridges connected to the WEMIX3.0 network, including the Chainlink CCIP and PLAY Bridge. The company paused trading in affected liquidity pools, removed foundation-provided liquidity, and stopped the WEMIX$ Module and PNIX decentralized exchange. Several exchanges froze linked addresses after receiving requests for assistance, though WEMIX has not disclosed which exchanges or the total amount frozen. The company has not confirmed whether ordinary user balances were directly affected and has not published a complete list of compromised contracts, transaction hashes, or recovery amounts. WEMIX brought in external security specialists and expanded the review to related contracts carrying similar administrative controls.
The attacker quickly shifted from contract exploitation to dispersing the stolen assets, increasing the challenge of fund recovery. After minting 5.23 million WEMIX$, the attacker converted the tokens into 30,736 WEMIX and 724,198.27 USDC.e. The funds then moved through Ethereum [ETH] and BNB Chain before reaching ETH, Tether [USDT], and other assets. This sequence reduced direct traceability and increased the risk of broader distribution across multiple platforms. WEMIX traced the attacker's wallets and secured cooperation from exchanges, with several already freezing linked addresses. However, each successful cross-chain transfer further reduces the chances of recovery.
WEMIX immediately disabled all active WEMIX3.0 Bridge functionality, disarmed select liquidity pools, and halted operation of other relevant functions to prevent future funds from being transferred. This enabled investigators to obtain additional time to follow the chain of transaction history and communicate directly with exchange operators who froze identified attacker-address accounts associated with stolen assets. The investigation remains active, and new findings may emerge. Investigators continue reviewing related contracts to uncover the attack path and close remaining security gaps. Technical safeguards may contain the immediate threat, but restoring confidence will require transparent communication, stronger security controls, and sustained ecosystem stability over time.