On July 26, an attacker exploited owner privileges tied to WEMIX$ stablecoin, minting roughly 5.23 million tokens without approval. This breach triggered the immediate suspension of bridges, liquidity pools, and other services connected to the WEMIX3.0 network.
The unauthorized creation of tokens allowed the attacker to convert and transfer assets across multiple blockchains, including Ethereum and BNB Smart Chain. Initial reports from South Korea estimated the value of these illicit moves at about $6.25 million, while WEMIX’s official update refined that figure to approximately 5,225,525 WEMIX$ minted.
The malicious actor then swapped parts of these tokens into 30,736 WEMIX and 724,198.27 USDC.e, moving funds through decentralized and centralized exchanges. Several exchanges responded by freezing wallets linked to the theft after WEMIX requested assistance. However, the full extent of frozen assets and recoverability remains undisclosed.
The incident began around 9:17 UTC (6:17 p.m. South Korea time), and WEMIX is now collaborating with blockchain security firms to trace the transactions. The root cause behind the owner key compromise is still under investigation, and the company cautioned that the numbers might change as they continue their review.
In response to the attack, WEMIX has paused trading on related liquidity pools and halted bridges including Chainlink CCIP and PLAY Bridge. The firm has not revealed if ordinary user balances suffered direct losses or detailed which contracts were compromised. The sudden freeze follows a previous bridge hack in 2025 and coincides with WEMIX's ongoing transition to USDC.e services.



