WEMIX stablecoin breach: 5.2M tokens minted illegally, network frozen
In brief
- 5.23 million WEMIX$ tokens minted illegally via compromised contract ownership on July 26
- WEMIX suspended bridges, liquidity pools, NFT trading, and blockchain gaming services
- Attackers converted stolen tokens to ETH, USDT, and USDC.e before freezes activated
- WEMIX has not disclosed compromise route, final losses, or user impact details
- September 2025 plan to phase out WEMIX$ in favor of USDC.e announced
How the breach unfolded
The abnormal transactions began at 18:17 on July 26 (UTC+9), or 09:17 UTC, after an attacker gained control of a WEMIX$-related contract. WEMIX has not disclosed the exact route by which the contract ownership was compromised, leaving a key question unanswered: how did an owner-level access fail?
The 5,225,525 unauthorized WEMIX$ was converted into 30,736 units of the network's native WEMIX token and 724,198.27 USDC.e. That USDC.e was then bridged to Ethereum and BNB Smart Chain, swapped into assets including ETH and USDT, and distributed among multiple addresses. Some of the attacker's assets were later deposited at centralized exchanges.
Response and ongoing unknowns
WEMIX suspended every bridge connected to and from WEMIX3.0, including its Chainlink CCIP route and PLAY Bridge. The announcement did not attribute the compromise to Chainlink or report a CCIP failure. Trading in multiple pools—WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$ and PLAY-WEMIX$—was halted, and the WEMIX$ Module and PNIX DEX were paused.
Blockchain-linked features in some games were restricted, and NFT marketplace trading and bidding were disabled. Some exchanges froze attacker-associated addresses after receiving cooperation requests from WEMIX, but WEMIX has not issued a final loss estimate or identified the exchanges involved.
The damage report remains incomplete. WEMIX did not quantify the frozen amounts or state whether individual user balances suffered losses. The team had not provided a reopening timetable for suspended services at the time of the initial incident update.
What comes next
In September 2025, WEMIX announced it would phase WEMIX$ out in favor of USDC.e while continuing conversions through the WEMIX$ Module. This shift sidesteps the core problem: the stablecoin's 100% collateralization claim was supposed to rest on USDC held in a Treasury, but access controls failed catastrophically. The unresolved cause, final impact, frozen amounts and potential user losses leave the scope of the incident dependent on the company's next findings.
Frequently asked questions
What is WEMIX$ and how is it supposed to work?
WEMIX$ is a stablecoin on the WEMIX3.0 network, described in the whitepaper as 100% collateralized by USDC held in a Treasury. Minting is supposed to be accessible only through Authorized Mint Access, granted solely to the DIOS stability protocol. The breach exposed that owner-level control could override these safeguards.
How did the attacker mint 5.2 million tokens?
Compromised ownership of a WEMIX$-related contract enabled the attacker to mint approximately 5.23 million tokens without authorization on July 26, 2025. WEMIX has not disclosed the exact route by which the contract ownership was compromised.
What did WEMIX do in response?
WEMIX suspended all bridges (including Chainlink CCIP and PLAY Bridge), halted trading in multiple liquidity pools, paused the WEMIX$ Module and PNIX DEX, restricted blockchain features in games, and disabled NFT marketplace trading. Some exchanges froze attacker-associated addresses after WEMIX cooperation requests.
What happened to the stolen tokens?
The 5,225,525 unauthorized WEMIX$ was converted into 30,736 WEMIX tokens and 724,198.27 USDC.e. The USDC.e was bridged to Ethereum and BNB Smart Chain, swapped into ETH and USDT, and distributed across multiple addresses. Some assets were deposited at centralized exchanges before freezes took effect.


