WEMIX says contract-owner compromise minted 5.2 million WEMIX$ during July attack
The project’s root-cause update says two contracts were transferred to an unauthorized party, while bridges and liquidity pools were suspended as exchanges tracked the stolen assets.
WEMIX says an attacker gained control of two contracts tied to its WEMIX$ stablecoin on July 26, then used flash loans and swaps to mint about 5.23 million tokens without authorization. The project’s July 30 root-cause update says the contracts were transferred to an unauthorized party in a single transaction. The incident did not involve a compromise of WEMIX’s internal systems or the exposure of an administrator’s private key, according to the update.
The disclosure changes the description of the failure from a suspected owner-key breach to a more specific contract-ownership compromise. WEMIX says the attacker took control of DIOS, which was designed to help stabilize WEMIX$, and AMA, which handled redemptions against collateral assets. The attacker then deployed a malicious contract and executed nine cycles of flash loans and swaps.
The loss was not only newly minted tokens
WEMIX’s latest figures put the confirmed external transfers at 723,244.4936 USDC.e and 34,752.3199 WEMIX. The project says the attacker also minted 5,225,524.9997 WEMIX$, but those figures are not interchangeable: the minted stablecoin was used inside the exploit path, while the USDC.e and WEMIX amounts describe assets that left the affected system.
The project initially said roughly 30,736 WEMIX and 724,198.27 USDC.e had been converted and moved externally. The later root-cause update revised the confirmed amounts, a reminder that incident totals can change as teams reconcile transactions and distinguish issuance from realized losses.
Bridges and pools were paused
WEMIX says it revoked the WEMIX$ minting authority, withdrew foundation liquidity from affected pools and asked exchanges to freeze addresses that received the assets. Bridges connected to WEMIX3.0, including Chainlink CCIP and the PLAY Bridge, were suspended while the response continued. The project also said it filed a report with law enforcement on July 28.
The on-chain impact remains a live operational question. A security tracker lists the event among 2026 incidents, while WEMIX says it is still analyzing game-token transactions and the scope of compensation. The official update does not state that all losses have been recovered or give a date for full service resumption. For users, the important distinction is between the compromised contracts and the wider WEMIX3.0 network: the disclosure identifies a contract-control failure, not a consensus failure or a break in the chain’s base protocol.