WEMIX$ Contract Breach Mints 5.23M Tokens As Funds Move Across Chains


WEMIX suspended bridges and decentralised trading services after an attacker seized ownership control of a contract tied to its WEMIX$ stablecoin and minted 5,225,525 tokens without authorisation.

The abnormal transactions began at 09:17 UTC on July 26. The attacker converted the unbacked WEMIX$ issuance into 30,736 WEMIX and 724,198.27 USDC.e, then moved the USDC.e through bridges to Ethereum and BNB Smart Chain. The funds were exchanged for ETH and USDT, distributed across several addresses and partly deposited into centralised exchanges.

The $5.23 million figure reflects the face value of the unauthorised stablecoin mint at WEMIX$’s intended dollar price. The confirmed conversion produced a substantially smaller pool of liquid assets before WEMIX halted the affected infrastructure.

WEMIX had already begun replacing WEMIX$ with USDC.e across its gaming and DeFi services, withdrawing foundation liquidity and ending support for several WEMIX$ pools during an April transition.

Bridges And Liquidity Pools Suspended

All bridges connected to WEMIX3.0 were temporarily suspended, including Chainlink CCIP and the PLAY Bridge. Trading stopped in affected liquidity pools, foundation-supplied liquidity was withdrawn and services including the WEMIX$ Module and PNIX decentralised exchange were paused.

Onchain investigator Specter flagged an address beginning 0xc921a66e during the first public tracing of the transactions. WEMIX later identified additional wallets and requested freezes from centralised exchanges and stablecoin issuers. Some addresses had already been restricted while recovery efforts continued.

The exact route used to obtain contract ownership remains under investigation. WEMIX brought in external security specialists and expanded the review to related contracts carrying similar administrative controls.

Second Major WEMIX Breach In 17 Months

The contract takeover follows the February 2025 PLAY Bridge exploit, when stolen authentication credentials allowed 8,654,860 WEMIX, then worth about $6.1 million, to be withdrawn from a bridge vault.

The WEMIX breach followed a more than $9.7 million multichain drain from wallets linked to Triple-A, where assets moved from TRON, Ethereum, Polygon and Arbitrum before being consolidated into 5,227 ETH. A malicious bridge import also released $7.54 million from the Verus Ethereum Bridge, while an earlier signature flaw allowed 515 million NIGHT to leave Wanchain’s Cardano bridge treasury.

WEMIX3.0 bridges, affected liquidity pools, the WEMIX$ Module and PNIX remained suspended while the ownership compromise and final asset movements were reviewed.