WEMIX contract ownership compromised; the attacker transferred 724,198 USDC.e

WEMIX-8.06%
ETH3.71%
BNB0.52%
Key Takeaways
  • WEMIX contract ownership was compromised on July 27, 2026, enabling unauthorized issuance of 5.23 million tokens.
  • Attackers exchanged 5.23 million WEMIX for 724,198.27 USDC.e and bridged assets to Ethereum and BNB Smart Chain.
  • WEMIX suspended all bridging services, halted affected trading, and requested exchanges to freeze attacker wallet addresses.

WEMIX, a Layer-1 blockchain network, said that on July 27, the attacker compromised ownership of the contract associated with the WEMIX stablecoin, issued approximately 5.23 million WEMIX without authorization, and swapped them into 30,736 WEMIX and 724,198.27 USDC.e; these USDC.e were then bridged to Ethereum and BNB Smart Chain.

Attack execution process: 5.23 million WEMIX unauthorized issuance

According to WEMIX’s initial incident update, after the attacker compromised ownership of the WEMIX contract, it issued approximately 5.23 million WEMIX without authorization; the issued WEMIX was swapped into 30,736 WEMIX and 724,198.27 USDC.e. These USDC.e were then transferred to Ethereum and BNB Smart Chain via cross-chain bridges, then swapped into assets such as ETH and Tether USDT, and distributed across multiple addresses.

WEMIX said some of the funds have been deposited into centralized exchanges. The company identified the attacker’s wallet address and requested that relevant exchanges and stablecoin issuers freeze the assets.

WEMIX’s suspension service list and freeze assistance requests

After detecting this attack, WEMIX has suspended or taken the following 대응 measures:

All bridging services: Paused all bridging services connected to the WEMIX3.0 Layer-1 network, including Chainlink CCIP and PLAY Bridge

Trades involving affected liquidity pools: Suspended all trading activities involving the affected liquidity pools

Foundation liquidity: Withdrawn liquidity provided by the foundation

WEMIX modules: Suspended WEMIX-related module services

PNIX DEX: Suspended services of the PNIX decentralized exchange

Freeze request: Identified the attacker’s wallet address and requested that centralized exchanges and stablecoin issuers freeze related assets; some exchanges have already frozen the relevant addresses

FAQ

When did the abnormal transactions related to the WEMIX attack occur?

According to WEMIX’s initial incident update, the abnormal transactions occurred on July 27, 2026 (Sunday) at 9:17 UTC. Prior to that, WEMIX announced on July 26 that there were security issues with WEMIX and launched an investigation.

How much money did the attacker transfer in this incident?

The attacker issued approximately 5.23 million WEMIX without authorization and swapped them into 30,736 WEMIX and 724,198.27 USDC.e (about $724k). After USDC.e was bridged to Ethereum and BNB Smart Chain, it was further swapped into ETH and USDT and distributed across multiple addresses.

Has WEMIX recovered the stolen funds?

As of the time of this report, WEMIX has identified the attacker’s wallet address and requested that relevant exchanges and stablecoin issuers freeze the assets; some exchanges have already frozen the relevant addresses. The cause of the incident and the full impact are still under investigation. WEMIX said preliminary data may change, and the final outcome will be based on WEMIX’s official announcement.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments