WEMIX halts bridges after $6.25M stablecoin contract hack

WEMIX stablecoin hack forces network security shutdown

South Korean gaming publisher Wemade’s blockchain network WEMIX has suspended every bridge on its mainnet after an attacker seized owner privileges on the contract behind its dollar-pegged stablecoin, WEMIX$. The attacker minted 5,225,525 unbacked WEMIX$, swapped them into 30,736 WEMIX and 724,198.27 USDC.e, then bridged the proceeds to Ethereum and BNB Smart Chain. WEMIX confirmed the breach on the morning of July 27, roughly 15 hours after the first abnormal transactions hit the chain. Headline damage estimates run to about $6.25 million; the amount actually moved off the network sits closer to $724,000.

Contract owner privileges are the administrative rights that let a designated wallet mint, pause, or upgrade a smart contract, which means losing them hands an attacker the same powers the protocol team holds.

Key takeaways

  • The attack began at 09:17 UTC on July 26 when an unidentified party gained administrator control of the WEMIX$ stablecoin contract.
  • 5,225,525 WEMIX$ were minted without authorization and converted into 30,736 WEMIX and 724,198.27 USDC.e before being bridged out.
  • WEMIX halted all mainnet bridges, including Chainlink CCIP and the PLAY Bridge, paused its PNIX exchange, and withdrew foundation liquidity.
  • WEMIX$ has fallen roughly 98.9% over the past week, according to CoinGecko data.

Published: July 27, 2026, 09:30 UTC

How the attacker drained the stablecoin

The exploit did not target a pricing oracle or a lending formula. It targeted access control, the layer that decides who is allowed to touch a contract at all.

Once the attacker held owner rights, the minting step required no clever mechanics. The new tokens were routed through a decentralized exchange on the WEMIX3.0 mainnet and swapped for WEMIX and USDC.e, the bridged version of Circle’s USDC that circulates on the network. The USDC.e was then moved across bridges into Ethereum and BNB Smart Chain, where portions were converted into ETH and Tether’s USDT and split across several wallets. Some of those assets reached centralized exchanges.

WEMIX has identified the suspected attacker wallets and asked exchanges and stablecoin issuers to freeze linked addresses. It confirmed that several venues have done so, without naming them or disclosing how much value is frozen. The company said it may involve law enforcement if tracing produces evidence worth acting on, and warned that its preliminary loss figures could change.

On-chain analytics dashboard used to trace WEMIX stablecoin hack funds

The shutdown reaches deep into WEMIX’s gaming economy

WEMIX responded by taking most of its onchain economy offline rather than isolating the compromised contract.

All bridges into and out of WEMIX3.0 were suspended, including the Chainlink CCIP integration the company rolled out earlier this year and the PLAY Bridge connecting its gaming environment to external chains. Trading was frozen in the affected liquidity pools covering WEMIX-USDC.e, CROW-WEMIX$, TIPO-WEMIX$ and PLAY-WEMIX$ pairs, and the WEMIX Foundation pulled its own supplied liquidity. The WEMIX$ Module and PNIX were both paused. Blockchain features inside several games were restricted, and NFT marketplace trading on WEMIX PLAY was disabled pending a contract audit.

WEMIX$ lost its dollar peg during the sequence and is down about 98.9% on the week per CoinGecko data. The WEMIX token itself traded near $0.24 heading into the incident.

A second breach in 18 months

This is the second major security failure at WEMIX since February 2025, and the two incidents exploited different weaknesses.

In the earlier breach, attackers drained roughly 8.65 million WEMIX tokens, worth about $6.04 million at the time, from the Play Bridge Vault after compromising authentication keys tied to the Nile NFT platform’s monitoring system. Wemix Foundation CEO Kim Seok-hwan disclosed that incident four days after detection, a delay he later attributed to concerns about panic and further exploitation. South Korea’s major exchanges, coordinating through the Digital Asset Exchange Alliance, delisted WEMIX in June 2025.

Disclosure moved faster this time, at roughly 15 hours. The attack surface is more severe. Stolen operational credentials give an attacker access to a system; stolen contract ownership gives them the contract itself.

The timing compounds the problem. WEMIX completed its second halving on July 1 and secured a Kraken listing on July 8, opening the token to users in the United States, Canada, the United Kingdom and Australia. The company had also been winding down WEMIX$ in favor of USDC.e, having announced in March that WEMIX PLAY would switch its base currency. The compromised stablecoin was already scheduled for retirement.

What this means for the wider market

Contract ownership takeovers sit near the top of the DeFi risk stack because they collapse a protocol’s entire trust model in a single transaction.

The breach caps a punishing stretch for Web3 security. Losses across the sector topped $47 million in the preceding week, with AFX Trade, Wanchain and Verus among the affected platforms, and the Verus Ethereum Bridge drained for roughly $7.54 million on July 23. Industry trackers put 2026 losses past $1 billion across bridge exploits, oracle manipulation and key compromises. W3BN has covered similar patterns in a $35 million run of bridge attacks and Taiko’s layer-2 halt after a $1.7 million exploit.

For Korean regulators already scrutinizing privately issued stablecoins tied to consumer products, a game publisher losing control of its own dollar token is an uncomfortable data point, arriving alongside disputes over domestic stablecoin consortium plans.

WEMIX says it will publish further updates as the investigation proceeds, including any revision to the loss estimate and a timeline for restoring suspended services. It has not identified how the owner credentials were compromised, nor confirmed the final unrecovered total.

Frequently asked questions

How much did the WEMIX hack actually cost?

Reported figures differ. About $6.25 million covers the full abnormal issuance and movement of tokens, while roughly $724,000 in USDC.e was successfully bridged off the WEMIX3.0 network. WEMIX has said its preliminary numbers may change as tracing continues.

Are user funds on WEMIX safe?

WEMIX has not stated whether ordinary user balances were directly affected. It suspended bridges, liquidity pools, the PNIX exchange and NFT marketplace activity as a precaution, and has not published a full list of compromised contracts or transaction hashes.

What is USDC.e and why does it matter here?

USDC.e is a bridged version of Circle’s USD Coin that circulates on the WEMIX3.0 mainnet rather than being issued natively there. The attacker converted minted WEMIX$ into USDC.e because it could be moved across bridges to Ethereum and BNB Smart Chain, where value could be exited.

Has WEMIX been hacked before?

Yes. In February 2025, attackers drained about 8.65 million WEMIX tokens, then worth roughly $6.04 million, from the Play Bridge Vault using compromised authentication keys. The delayed disclosure of that incident contributed to South Korean exchanges delisting WEMIX in June 2025.

Staff Correspondent New York, NY

Alex Mitchell is a staff correspondent at Web3BusinessNews covering breaking news and daily developments across the cryptocurrency and blockchain landscape. With over five years of experience in financial journalism and digital asset reporting, Alex delivers fast, accurate coverage of market movements, protocol updates, and emerging trends shaping the Web3 ecosystem.

  • Cryptocurrency
  • Blockchain News
  • Digital Assets
  • Market Analysis
Share it :

Leave a Reply

Your email address will not be published. Required fields are marked *