Logo
My Crypto News AI

WEMIX Foundation Halts All Bridges After Attacker Mints $5.23 Million in Unauthorized Stablecoin

The WEMIX Foundation discovered a critical compromise of its WEMIX$ stablecoin minting authority on July 26, 2026, when attackers used stolen control of the contract to issue approximately 5.23 million WEMIX$ without authorization. The incident forced the foundation to temporarily suspend all bridges connecting WEMIX3.0 (the foundation's own blockchain) to other networks, halt trading in five liquidity pools, and disable multiple services including the WEMIX$ Module and PNIX decentralized exchange.

What Happened During the WEMIX$ Exploit?

The unauthorized minting occurred at 09:17 UTC on July 26, when the compromised ownership of the WEMIX$ contract was used to issue tokens and transfer bridged USD Coin (USDC.e) to external addresses. The attacker converted the 5.23 million WEMIX$ into 30,736 WEMIX tokens and 724,198 USDC.e, then moved the USDC.e across bridges to Ethereum and BNB Smart Chain, where it was swapped into other assets including Ether (ETH) and Tether (USDT) and partially deposited into centralized exchanges.

The WEMIX Foundation responded by taking immediate precautionary measures to contain the damage. As a result of the exploit, WEMIX$ crashed 99% in 24 hours, trading at $0.0099 by July 27, down from its previous price levels. The WEMIX token itself experienced significant volatility, trading as low as $0.18 on July 26 before recovering above $0.23 and settling around $0.2110 by July 27.

How Did the Foundation Respond to the Breach?

  • Bridge Suspension: All bridges to and from WEMIX3.0 were temporarily suspended to prevent further unauthorized token transfers across networks.
  • Liquidity Pool Halts: Trading was halted in five affected liquidity pools, including four WEMIX$ pairs, and the foundation withdrew its own liquidity from these pools.
  • Service Shutdowns: The WEMIX$ Module, PNIX decentralized exchange, and NFT marketplace trading and bidding were all disabled to prevent additional exploitation.
  • Attacker Tracking: The foundation identified the attacker's addresses and began tracking onchain flows, sending freeze requests to exchanges and stablecoin issuers, with some freezes already completed.

The WEMIX Foundation stated in its first public statement: "The WEMIX Team sincerely apologizes for the concern caused." The foundation noted that the cause and full scale of the compromise remain under investigation, with preliminary figures still being confirmed.

Is This Part of a Larger Pattern for WEMIX?

This exploit represents the second major security incident for WEMIX in less than 18 months. In February 2025, attackers drained approximately 8.65 million WEMIX from the PLAY Bridge Vault, a separate bridge mechanism unrelated to the WEMIX$ contract. That theft was disclosed several days after it occurred, and the delayed disclosure prompted four Korean exchanges to end WEMIX trading support, citing concerns about the credibility and security of Wemade, the South Korean game company behind the token.

The repeated breaches have significantly impacted WEMIX's market presence. The token now trades primarily outside South Korea, with the 10 most active trading pairs listed on non-Korean venues including Gate, XT.COM, Bybit, and Kraken. Additionally, WEMIX$ had already been dropped as the base currency of WEMIX PLAY, the foundation's blockchain gaming platform, which switched to USDC.e in April 2026 under an announced transition plan.

The July 26 incident underscores the ongoing vulnerability of bridge infrastructure in decentralized finance (DeFi). Bridges allow users to move cryptocurrency between different blockchains, but they require centralized control points that can become targets for attackers. The compromise of minting authority represents a particularly severe attack vector, as it allowed the attacker to create new tokens rather than simply stealing existing ones, making the exploit difficult to reverse or fully recover from.

For investors and users of WEMIX and WEMIX$, the incident raises questions about the foundation's security practices and its ability to protect user assets. The temporary suspension of bridges and services may prevent further losses, but it also locks users out of their funds and prevents normal trading activity until the foundation can restore confidence in the platform's security infrastructure.