July 27, 2026 ChainGPT

WEMIX Freezes Bridges After Owner-Key Breach Mints 5.23M WEMIX$; Cross-Chain Probe Underway

WEMIX Freezes Bridges After Owner-Key Breach Mints 5.23M WEMIX$; Cross-Chain Probe Underway
WEMIX freezes bridges after owner-key breach mints 5.23M WEMIX$ WEMIX has suspended key bridge services and frozen affected funds after an attacker abused owner-level privileges on the WEMIX$ stablecoin contract, minting approximately 5,225,525 WEMIX$ on July 26. The company says the attacker then moved funds across multiple chains and converted portions into other tokens, prompting an ongoing cross-chain investigation and requests to exchanges to freeze related wallets. What happened - Time: WEMIX says the incident began at about 09:17 UTC (18:17 local South Korea time) on July 26. - Exploit: An account with owner privileges on the WEMIX$ contract was used to mint tokens without authorization. - Amount minted: Official figures list roughly 5,225,525 WEMIX$ newly issued. - Conversion: The attacker converted those tokens into 30,736 WEMIX and 724,198.27 USDC.e, then bridged USDC.e to Ethereum and BNB Smart Chain and swapped parts into ETH, USDT and other assets. Some proceeds were sent to centralized exchanges. - Earlier estimates: A Korean report initially valued abnormal issuance and transfers at about $6.25 million; WEMIX’s breakdown focuses on the minted WEMIX$ and the on-chain conversions above. Immediate response - Bridges suspended: WEMIX temporarily stopped all bridges connected to the WEMIX3.0 network, including Chainlink CCIP and the PLAY Bridge. - Market and protocol actions: The team paused trading in affected liquidity pools, removed foundation-provided liquidity, and halted the WEMIX$ Module and the PNIX decentralized exchange to prevent further transfers. - Asset containment: WEMIX identified suspected attacker wallets, asked exchanges and stablecoin issuers to help freeze addresses, and began tracing transactions with blockchain security firms. Several exchanges reportedly froze linked addresses, but WEMIX has not named them or disclosed how much is currently frozen versus still controlled by the attacker. - Communication: The firm warned initial figures may change, urged users to rely on official channels, and said it may involve law enforcement if tracing uncovers evidence requiring formal action. Damage, uncertainty and context - Net loss vs. minted value: WEMIX noted that the nominal value of tokens minted is not the same as the amount successfully converted and withdrawn; it has not published a full list of compromised contracts, transaction hashes or recovered amounts. - Stablecoin impact: WEMIX$—a USD-pegged token on WEMIX3.0—plunged on market data platforms after the breach, with CoinGecko showing a weekly decline of roughly 98.9% as the unauthorized minting and conversions were executed. - Migration already underway: The breach comes while WEMIX had been transitioning services from WEMIX$ to USDC.e—WEMIX PLAY moved its base currency to USDC.e earlier in the year—and had been winding down older WEMIX$ liquidity. Relevant history - WEMIX experienced another security incident in February 2025 when attackers removed about 8.6 million WEMIX (roughly $6.04 million at the time) from the Play Bridge Vault. That breach led to server shutdowns, police involvement and criticism after delayed public disclosure. Major South Korean exchanges delisted WEMIX in June 2025 via a coordinated move by the Digital Asset Exchange Alliance. What’s next WEMIX has not yet released a final incident report, named how owner credentials were compromised, or confirmed the total unrecovered loss. The team says it will continue multi-chain tracing, contract permission reviews and cooperation with exchanges and investigators. Further official updates are expected as the probe confirms technical details and recovery results. Read more AI-generated news on: undefined/news