Hackers mint 5.23M WEMIX$; WEMIX3.0 services suspended
Attackers minted 5,225,525 WEMIX$ on July 26 after a contract owner account was compromised, prompting WEMIX to halt bridges, liquidity pools and several WEMIX3.0 services; losses remain unknown.
On July 26 WEMIX reported that a contract owner account was compromised, allowing attackers to mint 5,225,525 WEMIX$. The project detected abnormal transactions at 18:17 (UTC+9) / 09:17 UTC and immediately suspended bridges, liquidity pools and multiple services on its WEMIX3.0 network.
According to WEMIX’s documentation, WEMIX$ is intended to be 100% collateralized by USDC held in a Treasury and to be minted only through Authorized Mint Access granted to the DIOS stability protocol. The company reported that owner-level control was used to create tokens outside the protocol’s intended minting process, but it has not disclosed how that control was obtained or whether the attacker’s USDC.e originated from the Treasury.
WEMIX reported the 5,225,525 unauthorized WEMIX$ were converted into 30,736 units of the native WEMIX token and 724,198.27 USDC.e, the bridged stablecoin on WEMIX3.0. The converted USDC.e was bridged to Ethereum and BNB Smart Chain, swapped into assets including ETH and USDT, and distributed across multiple addresses. Some of those assets were later deposited at centralized exchanges.
As a containment measure, WEMIX suspended every bridge connected to WEMIX3.0, including its Chainlink CCIP route and the PLAY Bridge. Trading was halted in several liquidity pools, including WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$ and PLAY-WEMIX$. The WEMIX$ Module and the PNIX decentralized exchange were paused, blockchain-linked features in some games were restricted, and NFT marketplace trading and bidding were disabled. No timetable for restoring services has been provided.
WEMIX has not issued a final loss estimate or confirmed whether individual user balances were affected. The company noted that the nominal number of tokens minted does not itself establish a dollar loss. WEMIX reported that some centralized exchanges froze attacker-associated addresses after cooperation requests but did not quantify frozen amounts or identify the exchanges involved.
The incident follows WEMIX’s September 2025 plan to phase out WEMIX$ in favor of USDC.e while maintaining conversion capability through the WEMIX$ Module; that module is among the services currently suspended. The investigation is ongoing and further updates are expected as findings are confirmed.
Content on BlockPort is provided for informational purposes only and does not constitute financial guidance.
We strive to ensure the accuracy and relevance of the information we share, but we do not guarantee that all content is complete, error-free, or up to date. BlockPort disclaims any liability for losses, mistakes, or actions taken based on the material found on this site.
Always conduct your own research before making financial decisions and consider consulting with a licensed advisor.
For further details, please review our Terms of Use, Privacy Policy, and Disclaimer.








