Logo
My Crypto News AI

Two Major Crypto Hacks in Hours: Garden Finance and WEMIX Hit by Database and Contract Exploits

Two major cryptocurrency platforms were hit by security breaches within hours on July 27, 2026, resulting in combined losses exceeding $6.7 million and forcing both services offline. Garden Finance, a cross-chain bridge protocol, lost approximately $450,000 worth of Tether (USDT) after an independent solver's off-chain database was compromised. Hours later, WEMIX, a South Korean gaming blockchain, suffered a $6.25 million exploit when an attacker gained administrative control over its stablecoin smart contract. The back-to-back incidents underscore a critical shift in how cryptocurrency platforms are being targeted: attackers are increasingly focusing on operational infrastructure and contract ownership rather than exploiting code vulnerabilities alone.

What Happened to Garden Finance?

Garden Finance suspended services after discovering that an attacker had breached the off-chain database belonging to one of its independent solvers, which are third-party operators that facilitate transactions on the protocol. The attacker inserted false transaction records into the database, causing the compromised solver to send funds for swap transactions without actually receiving counterparty funds in return.

The protocol's smart contracts and core infrastructure were not directly compromised, and no user funds were lost or exposed to risk. The $450,000 in stolen USDT belonged to the affected solver, not to end users. Garden Finance said it is working with security firms zeroShadow, Quantstamp, and Blockaid to trace and recover the stolen funds across Ethereum, Base, Arbitrum, and BNB Chain. The company has not provided a timeline for resuming services pending completion of its security review.

This is the second time Garden Finance has suffered a similar incident. In October 2025, one solver's operating environment was compromised, resulting in approximately $11.4 million in losses. Like the current breach, that incident did not directly affect the protocol's smart contracts or user funds.

How Did WEMIX Lose $6.25 Million?

WEMIX's breach followed a fundamentally different attack vector. An unidentified attacker gained administrator privileges over a smart contract tied to WEMIX$, the network's dollar-pegged stablecoin, at 18:17 Korean Standard Time on July 26 (09:17 UTC). Using those privileges, the attacker minted approximately 5.2 million WEMIX$ tokens out of thin air, worth around $5.22 million at par value.

The freshly minted tokens were then swapped through a decentralized exchange into 30,736 WEMIX tokens and 724,198 units of USDC.e, a bridged version of Circle's USDC stablecoin. The attacker then moved the USDC.e off the WEMIX blockchain through bridges to Ethereum and BNB Smart Chain, where the funds were converted into Ethereum and Tether's USDT and scattered across multiple wallets. Some assets were deposited into centralized exchanges, prompting WEMIX to urgently request asset freezes from global exchanges and stablecoin issuers.

Within hours of detecting the abnormal transactions, WEMIX pulled a comprehensive defensive lockdown of its blockchain economy. All bridges connecting to and from the WEMIX network were suspended, including the recently integrated Chainlink CCIP cross-chain interoperability service. Trading in affected liquidity pools was frozen, the WEMIX$ stablecoin module and PNIX decentralized exchange were paused, and NFT marketplace trading on the WEMIX PLAY platform was disabled.

Why These Breaches Matter: A Pattern of Operational Vulnerabilities

Both incidents reveal a troubling trend in cryptocurrency security: attackers are increasingly bypassing smart contract code to target the operational infrastructure and administrative controls that govern protocols. Garden Finance's breach exploited off-chain database access, while WEMIX's breach centered on stolen contract ownership privileges. Neither attack required finding a flaw in the underlying smart contract code.

WEMIX's situation is particularly acute because this is the second major security incident in less than 18 months. In February 2025, attackers drained approximately 8.65 million WEMIX tokens, worth around $6.1 to $6.2 million at the time, from the platform's Play Bridge Vault. That breach was traced to compromised authentication keys used for monitoring the Nile NFT platform, with investigators believing the attacker had spent nearly two months inside the system before withdrawing funds. The handling of that hack drew significant scrutiny; WEMIX Foundation CEO Kim Seok-hwan disclosed the breach four days after it was detected, a delay he said was intended to prevent panic. The controversy contributed to South Korea's Digital Asset eXchange Alliance moving to end trading support for WEMIX, which sent the token tumbling more than 60% in a single trading session.

How to Understand the Security Risks in Modern DeFi Protocols

  • Off-Chain Infrastructure Risk: Protocols that rely on independent operators or solvers to facilitate transactions create a distributed attack surface. If any single operator's database or systems are compromised, attackers can manipulate transaction records without directly touching the blockchain.
  • Contract Ownership Vulnerabilities: Smart contracts that grant administrative privileges to mint tokens, upgrade code, or drain funds represent a single point of failure. Losing control of these privileges effectively hands an attacker the keys to the entire protocol.
  • Operational Security Failures: Both breaches stemmed from compromised credentials and access controls rather than code exploits, highlighting that human operational security is often the weakest link in blockchain infrastructure.

The timing of WEMIX's breach is particularly unfortunate. On July 1, WEMIX completed its second halving event, cutting block rewards as part of its long-term supply schedule. A week later, on July 8, the token secured a marquee listing on Kraken, opening it to retail and institutional users across the United States, Canada, the United Kingdom, and Australia. Around the same time, WEMIX rolled out Chainlink CCIP integration as part of a broader cross-chain interoperability push. The loss of ownership control over the WEMIX$ stablecoin contract is likely to reopen questions about the soundness of privately issued, game-linked stablecoins, a category South Korean regulators have been watching closely.

WEMIX has identified the wallets used in the attack and is actively tracking fund flows on-chain. The foundation has formally requested cooperation from global exchanges and stablecoin issuers, and confirmed that some venues have already frozen addresses linked to the incident. If tracing efforts fail, the company has flagged the possibility of escalating the matter to law enforcement. A comprehensive inspection of all related contracts and structurally similar contracts is underway, though the preliminary loss figures could shift as investigators piece together the full picture.

Both platforms have committed to resuming services only after completing thorough security reviews, but neither has provided a specific timeline. For WEMIX, the breach lands at a critical moment for the network's credibility and its recent push into Western markets. For Garden Finance, the incident marks a pattern of operational vulnerabilities that will likely prompt deeper scrutiny of how independent solvers are vetted and monitored.