Compromised owner contract just let hackers print 5.2 million WEMIX stablecoins out of thin air, forcing a complete network freeze
The WEMIX crew stated compromised possession of a contract tied to its WEMIX$ stablecoin enabled roughly 5.23 million tokens to be minted with out authorization, prompting it to droop bridges, liquidity swimming pools, and a number of other companies on the WEMIX3.0 network.
Contract-owner breach examined WEMIX$’s 1:1 design
The WEMIX3.0 whitepaper describes WEMIX$ as 100% collateralized by USDC held in a Treasury and says its provide ought to stay equal to the Treasury’s USDC quantity. It additionally says minting is accessible solely via Authorized Mint Access, which is granted solely to the DIOS stability protocol.
WEMIX’s preliminary incident update stated the irregular transactions started at 18:17 on July 26 (UTC+9), or 09:17 UTC, after possession of a WEMIX$-related contract was compromised.
Taken collectively, the 2 paperwork present that owner-level management was used to provide tokens exterior the whitepaper’s meant minting path. WEMIX has not disclosed the precise route by which that management was compromised, and its replace doesn’t set up that the USDC.e later moved by the attacker got here immediately from the Treasury.
WEMIX stated the 5,225,525 unauthorized WEMIX$ was transformed into 30,736 models of the network’s native WEMIX token and 724,198.27 USDC.e, the bridged stablecoin used on WEMIX3.0. The firm particularly stated the transformed USDC.e was bridged to Ethereum and BNB Smart Chain, swapped into property together with ETH and USDT, and distributed amongst a number of addresses. Some of these property had been later deposited at centralized exchanges.
The nominal quantity of tokens minted doesn’t set up a $5.23 million loss. WEMIX has not issued a remaining loss estimate or recognized the exchanges concerned. It stated some exchanges froze attacker-associated addresses after receiving cooperation requests, however didn’t quantify the frozen quantities or state whether or not particular person person balances suffered losses.
Containment reached bridges, buying and selling, video games and NFTs
WEMIX’s July 26 response listed each bridge related to and from WEMIX3.0 as suspended, together with its Chainlink CCIP route and PLAY Bridge. The announcement didn’t attribute the compromise to Chainlink or report a CCIP failure.
The replace additionally listed buying and selling within the WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$ and PLAY-WEMIX$ swimming pools as halted. The WEMIX$ Module and PNIX DEX had been paused, blockchain-linked options in some video games had been restricted, and NFT market buying and selling and bidding had been disabled.
The disruption adopted WEMIX’s September 2025 announcement that it will section WEMIX$ out in favor of USDC.e whereas persevering with conversions via the WEMIX$ Module. That module was among the many companies listed as suspended within the July 26 incident replace.
WEMIX had not offered a reopening timetable in that replace. The unresolved trigger, remaining affect, frozen quantities and potential person losses depart the scope of the incident depending on the corporate’s subsequent findings.
The submit Compromised owner contract just let hackers print 5.2 million WEMIX stablecoins out of thin air, forcing a complete network freeze appeared first on CryptoSlate.
