WEMIX shuts bridges and DEX after $724K exploit on stablecoin migration

Editorial illustration for: WEMIX shuts bridges and DEX after $724K exploit on stablecoin migration

In brief

  • WEMIX shut down bridges and DEX trading after attackers drained $724,000 in USDC.e tokens via linked contract exploit
  • Second major incident in six months; February 2025 attack cost 8.65 million WEMIX tokens worth $6.2 million
  • Exploit occurred during WEMIX3.0 network transition from native WEMIX$ stablecoin to USDC.e

The Breach

WEMIX suspended both its bridge services and DEX trading, effectively freezing cross-chain movement and on-platform swaps. The attacker exploited a contract linked to WEMIX's infrastructure, moving the $724,000 in USDC.e tokens before the platform could respond.

This is not an isolated incident. The platform suffered a separate, much larger breach back in February 2025 that cost it over 8.65 million WEMIX tokens, worth approximately $6.2 million at the time. That earlier attack targeted the Play Bridge Vault, leaving investors shaken and platform credibility in question.

Why This Matters

WEMIX had been in the process of transitioning from its native WEMIX$ stablecoin to USDC.e on its WEMIX3.0 network, a migration that began around March to April 2026. Liquidity migrations are complex. They require rewriting or redeploying contracts, adjusting permissions, and reconfiguring how funds flow between wallets and pools. Each step introduces friction and, if mishandled, creates attack surface.

The latest exploit suggests at least one of those points was not adequately secured.

The February breach prompted a temporary service halt, a token buyback plan to stabilize the market, and a collaboration with blockchain security firm Theori to conduct forensic analysis. WEMIX CEO Kim Seok-Hwan oversaw that response. The platform eventually resumed operations, but the incident left a mark on investor confidence in the WEMIX ecosystem.

Now, six months later, another breach. The cumulative effect is corrosive. Trust isn't rebuilt by resuming service after an exploit—it's rebuilt by proving you've solved the underlying problem. Two breaches in half a year suggest WEMIX hasn't yet done that.