|

Compromised owner contract just let hackers print 5.2 million WEMIX stablecoins out of thin air, forcing a complete network freeze

Humanity Protocol hack turns one laptop breach into an identity-token crisis

The WEMIX crew stated compromised possession of a contract tied to its WEMIX$ stablecoin enabled roughly 5.23 million tokens to be minted with out authorization, prompting it to droop bridges, liquidity swimming pools, and a number of other companies on the WEMIX3.0 network.

Contract-owner breach examined WEMIX$’s 1:1 design

The WEMIX3.0 whitepaper describes WEMIX$ as 100% collateralized by USDC held in a Treasury and says its provide ought to stay equal to the Treasury’s USDC quantity. It additionally says minting is accessible solely via Authorized Mint Access, which is granted solely to the DIOS stability protocol.

WEMIX’s preliminary incident update stated the irregular transactions started at 18:17 on July 26 (UTC+9), or 09:17 UTC, after possession of a WEMIX$-related contract was compromised.

Taken collectively, the 2 paperwork present that owner-level management was used to provide tokens exterior the whitepaper’s meant minting path. WEMIX has not disclosed the precise route by which that management was compromised, and its replace doesn’t set up that the USDC.e later moved by the attacker got here immediately from the Treasury.

Humanity Protocol hack turns one laptop breach into an identity-token crisis
Related Reading

Humanity Protocol hack turns one laptop breach into an identity-token crisis

A $36 million H exploit shows how one custody failure can threaten a project built around digital identity trust.
Jun 10, 2026
·
Liam ‘Akiba’ Wright

WEMIX stated the 5,225,525 unauthorized WEMIX$ was transformed into 30,736 models of the network’s native WEMIX token and 724,198.27 USDC.e, the bridged stablecoin used on WEMIX3.0. The firm particularly stated the transformed USDC.e was bridged to Ethereum and BNB Smart Chain, swapped into property together with ETH and USDT, and distributed amongst a number of addresses. Some of these property had been later deposited at centralized exchanges.

The nominal quantity of tokens minted doesn’t set up a $5.23 million loss. WEMIX has not issued a remaining loss estimate or recognized the exchanges concerned. It stated some exchanges froze attacker-associated addresses after receiving cooperation requests, however didn’t quantify the frozen quantities or state whether or not particular person person balances suffered losses.

Polkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on Ethereum
Related Reading

Polkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on Ethereum

A proof replay bug let the attacker mint over $1 billion DOT tokens on Ethereum, yet shallow DOT pools capped the cashout near $240,000.
Apr 13, 2026
·
Oluwapelumi Adejumo

Containment reached bridges, buying and selling, video games and NFTs

WEMIX’s July 26 response listed each bridge related to and from WEMIX3.0 as suspended, together with its Chainlink CCIP route and PLAY Bridge. The announcement didn’t attribute the compromise to Chainlink or report a CCIP failure.

Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk
Related Reading

Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk

The incident forced users to confront the part of rollup security that usually stays invisible: whether they can still withdraw when the bridge layer breaks.
Jun 23, 2026
·
Liam ‘Akiba’ Wright

The replace additionally listed buying and selling within the WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$ and PLAY-WEMIX$ swimming pools as halted. The WEMIX$ Module and PNIX DEX had been paused, blockchain-linked options in some video games had been restricted, and NFT market buying and selling and bidding had been disabled.

The disruption adopted WEMIX’s September 2025 announcement that it will section WEMIX$ out in favor of USDC.e whereas persevering with conversions via the WEMIX$ Module. That module was among the many companies listed as suspended within the July 26 incident replace.

WEMIX had not offered a reopening timetable in that replace. The unresolved trigger, remaining affect, frozen quantities and potential person losses depart the scope of the incident depending on the corporate’s subsequent findings.

The submit Compromised owner contract just let hackers print 5.2 million WEMIX stablecoins out of thin air, forcing a complete network freeze appeared first on CryptoSlate.

Similar Posts