WEMIX, a Layer-1 blockchain network, said that on July 27, the attacker compromised ownership of the contract associated with the WEMIX stablecoin, issued approximately 5.23 million WEMIX without authorization, and swapped them into 30,736 WEMIX and 724,198.27 USDC.e; these USDC.e were then bridged to Ethereum and BNB Smart Chain.
Attack execution process: 5.23 million WEMIX unauthorized issuance
According to WEMIX’s initial incident update, after the attacker compromised ownership of the WEMIX contract, it issued approximately 5.23 million WEMIX without authorization; the issued WEMIX was swapped into 30,736 WEMIX and 724,198.27 USDC.e. These USDC.e were then transferred to Ethereum and BNB Smart Chain via cross-chain bridges, then swapped into assets such as ETH and Tether USDT, and distributed across multiple addresses.
WEMIX said some of the funds have been deposited into centralized exchanges. The company identified the attacker’s wallet address and requested that relevant exchanges and stablecoin issuers freeze the assets.
WEMIX’s suspension service list and freeze assistance requests
After detecting this attack, WEMIX has suspended or taken the following 대응 measures:
All bridging services: Paused all bridging services connected to the WEMIX3.0 Layer-1 network, including Chainlink CCIP and PLAY Bridge
Trades involving affected liquidity pools: Suspended all trading activities involving the affected liquidity pools
Foundation liquidity: Withdrawn liquidity provided by the foundation
WEMIX modules: Suspended WEMIX-related module services
PNIX DEX: Suspended services of the PNIX decentralized exchange
Freeze request: Identified the attacker’s wallet address and requested that centralized exchanges and stablecoin issuers freeze related assets; some exchanges have already frozen the relevant addresses
FAQ
When did the abnormal transactions related to the WEMIX attack occur?
According to WEMIX’s initial incident update, the abnormal transactions occurred on July 27, 2026 (Sunday) at 9:17 UTC. Prior to that, WEMIX announced on July 26 that there were security issues with WEMIX and launched an investigation.
How much money did the attacker transfer in this incident?
The attacker issued approximately 5.23 million WEMIX without authorization and swapped them into 30,736 WEMIX and 724,198.27 USDC.e (about $724k). After USDC.e was bridged to Ethereum and BNB Smart Chain, it was further swapped into ETH and USDT and distributed across multiple addresses.
Has WEMIX recovered the stolen funds?
As of the time of this report, WEMIX has identified the attacker’s wallet address and requested that relevant exchanges and stablecoin issuers freeze the assets; some exchanges have already frozen the relevant addresses. The cause of the incident and the full impact are still under investigation. WEMIX said preliminary data may change, and the final outcome will be based on WEMIX’s official announcement.