Loading market data...

WEMIX$ Stablecoin Exploited for 5.2M Tokens, Bridges Suspended

WEMIX$ Stablecoin Exploited for 5.2M Tokens, Bridges Suspended

A vulnerability in the WEMIX$ stablecoin contract allowed an attacker to mint 5.225 million tokens on July 26, 2026. The unauthorized minting used an owner-level control outside the intended minting path, according to WEMIX. The attacker then converted the tokens into 30,736 WEMIX and 724,198.27 USDC.e, bridged them to Ethereum and BNB Smart Chain, swapped into ETH and USDT, and distributed funds to multiple addresses — some of which landed on centralized exchanges.

What got shut down

WEMIX responded by suspending all bridges, including Chainlink CCIP and the PLAY Bridge. It also halted liquidity pools tied to WEMIX$ — WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$, and PLAY-WEMIX$. The WEMIX$ Module, PNIX DEX, game features, and NFT marketplace trading and bidding were all paused. No reopening date has been given.

The collateral question

WEMIX$ is supposed to be 100% collateralized by USDC in a Treasury, with minting restricted to the DIOS stability protocol via Authorized Mint Access. The exploit bypassed that system entirely, using owner-level control. WEMIX hasn't disclosed the exact route of compromise. The company had announced a plan in September 2025 to phase out WEMIX$ in favor of USDC.e, but the WEMIX$ Module — used for conversions — was still live and is now suspended.

What's still unknown

WEMIX hasn't released a final loss estimate, named the exchanges that received attacker deposits, or said how much was frozen by those exchanges. The attacker's addresses were flagged and some funds may have been frozen, but no numbers have been confirmed. The timeline for reopening any of the suspended services also remains unclear.