TLDR
- An attacker gained owner-level control of a WEMIX$ stablecoin contract on July 26 and minted 5.23 million tokens without authorization.
- The minted tokens were converted into 30,736 WEMIX and 724,198 USDC.e before being bridged to Ethereum and BNB Smart Chain.
- WEMIX suspended all bridges, liquidity pools, and related services including the PNIX exchange and WEMIX$ Module.
- Several exchanges froze linked addresses after WEMIX requested emergency assistance.
- The breach comes just over a year after a 2025 hack that cost WEMIX roughly $6 million and led to delistings on major South Korean exchanges.
On July 26, blockchain gaming network WEMIX confirmed that an attacker had taken control of owner privileges linked to its WEMIX$ stablecoin contract. The breach began at approximately 9:17 UTC.
JUST IN: WEMIX suspends bridge services and wemix-token:native trading after an attacker exploited a linked smart contract, stealing approximately $724,000. The network has frozen affected funds and paused key services while the investigation continues. pic.twitter.com/2KUPwTgOd3
— EyeWhales (@EyeWhales) July 27, 2026
The attacker used the compromised access to mint around 5.23 million WEMIX$ tokens without any authorization. Those tokens were then converted into 30,736 WEMIX and 724,198.27 USDC.e.
The USDC.e was bridged across to Ethereum and BNB Smart Chain. From there, portions were swapped into Ether and Tether’s USDT and spread across multiple wallet addresses.
Some of the stolen assets reached centralized exchanges. WEMIX identified the attacker’s wallets and contacted exchanges and stablecoin issuers, requesting asset freezes. The company confirmed that several exchanges had already frozen linked addresses.
WEMIX has not named those exchanges or stated how much of the funds have been frozen or recovered.
Services Suspended Across the Network
In response to the attack, WEMIX temporarily halted all bridges connected to its WEMIX3.0 network. That suspension included Chainlink CCIP and the PLAY Bridge.
Trading in affected liquidity pools was also paused. The company withdrew foundation-provided liquidity and stopped the WEMIX$ Module and PNIX decentralized exchange while it reviewed contract permissions.
WEMIX said the cause of the owner-privilege compromise is still under investigation. The company warned that early figures could change as the review continues across multiple networks.
CoinGecko data showed WEMIX$ falling close to its recorded low after the breach, with a weekly decline of around 98.9%. This followed the unauthorized minting and rapid conversion of the newly created tokens.
The breach occurred while WEMIX was already in the process of replacing WEMIX$ with USDC.e across its gaming and financial services. In March, the company had announced that WEMIX PLAY would switch its base currency from WEMIX$ to USDC.e, with the main transition scheduled for April.
Second Major Security Breach in Under Two Years
This latest incident is not WEMIX’s first serious security breach. In February 2025, attackers drained approximately 8.6 million WEMIX tokens, worth around $6.04 million at the time, from the Play Bridge Vault.
That earlier hack drew criticism because WEMIX disclosed it several days after discovering the breach. South Korea’s major exchanges, including Upbit, Bithumb, Coinone, Korbit, and Gopax, coordinated a delisting of WEMIX in June 2025.
The new breach happened as the project was approaching the point where it could apply for relisting on domestic exchanges. WEMIX has not yet released a full attack report, named the source of the compromised credentials, or confirmed the total unrecovered loss.







