{"id":35499,"date":"2026-07-27T05:57:17","date_gmt":"2026-07-27T05:57:17","guid":{"rendered":"https:\/\/bitunikey.com\/news\/wemix-freezes-bridges-after-owner-key-breach-mints-5-23m-wemix\/"},"modified":"2026-07-27T05:57:33","modified_gmt":"2026-07-27T05:57:33","slug":"wemix-freezes-bridges-after-owner-key-breach-mints-5-23m-wemix","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/wemix-freezes-bridges-after-owner-key-breach-mints-5-23m-wemix\/","title":{"rendered":"WEMIX freezes bridges after owner-key breach mints 5.23M WEMIX$"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">WEMIX confirmed that an attacker took control of owner privileges linked to its WEMIX$ stablecoin contract on July 26. <\/p>\n<div id=\"cn-block-summary-block_b16ca869dd44b54b622c0a8860da2f12\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Compromised owner privileges allowed an attacker to mint approximately 5.23 million new WEMIX$ without authorization.<\/li>\n<li>WEMIX suspended bridges, liquidity pools and related services while exchanges traced and froze suspect funds.<\/li>\n<li>The incident follows WEMIX\u2019s 2025 bridge hack and comes during its transition toward USDC.e services.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>The access allowed the attacker to create tokens without approval and move assets through several blockchain networks. An early Korean report valued the abnormal issuance and transfers at about $6.25 million. A later WEMIX update gave a more detailed figure of roughly 5.23 million WEMIX$ minted.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">JUST IN: WEMIX suspends bridge services and wemix-token:native trading after an attacker exploited a linked smart contract, stealing approximately $724,000. The network has frozen affected funds and paused key services while the investigation continues. <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/2KUPwTgOd3\">pic.twitter.com\/2KUPwTgOd3<\/a><\/p>\n<p>\u2014 EyeWhales (@EyeWhales) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/EyeWhales\/status\/2081551839452111229?ref_src=twsrc%5Etfw\">July 27, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The company said the incident began at about 9:17 UTC, or 6:17 p.m. in South Korea. WEMIX identified suspected attacker wallets and asked exchanges and stablecoin issuers to help freeze the assets. It also started tracing the transactions with blockchain security companies. The cause of the owner-privilege compromise remains under investigation, and WEMIX warned that its initial figures may change.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>Attacker converts minted WEMIX$ into other assets<\/strong><\/h2>\n<p>According to WEMIX\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/wemix.com\/news\/update-on-the-wemix-security-issue-and-response-measures-06359e6f2a8e\" target=\"_blank\" rel=\"nofollow\">official<\/a> incident update, the attacker issued about 5,225,525 WEMIX$ without permission. The attacker then converted the tokens into 30,736 WEMIX and 724,198.27 USDC.e. This official breakdown differs from the first $6.25 million estimate, which covered the wider abnormal issuance and movement reported on-chain.<\/p>\n<p>The attacker bridged USDC.e to Ethereum and BNB Smart Chain before swapping parts of the funds into assets including ETH and USDT. Some assets also reached centralised exchanges. WEMIX said several exchanges had frozen linked addresses after receiving requests for help. However, the company has not named those exchanges or stated how much money remains frozen, recoverable or under attacker control.<\/p>\n<p>The company has not said whether ordinary user balances were directly affected. It also has not published a full list of compromised contracts, transaction hashes or recovery amounts. Those details matter because the nominal value of tokens created does not equal the amount successfully converted and removed. WEMIX said its review now continues across several networks.<\/p>\n<h2 class=\"wp-block-heading\"><strong>WEMIX suspends bridges and affected services<\/strong><\/h2>\n<p>WEMIX temporarily stopped all bridges connected to the WEMIX3.0 network. The suspension covered Chainlink CCIP and the PLAY Bridge. The company also paused trading in affected liquidity pools, removed foundation-provided liquidity and stopped the WEMIX$ Module and PNIX decentralised exchange. These steps aimed to block additional transfers while the team reviewed contract permissions and related systems.<\/p>\n<p>In its first notice, WEMIX said it had confirmed abnormal transactions and was <strong>\u201ccurrently analysing the cause of the incident and taking emergency measures.\u201d<\/strong> The company said it would publish more findings as investigators confirm them. It also asked users to rely on official channels instead of unverified posts. WEMIX may contact law enforcement agencies if tracing work identifies evidence that requires formal action.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Stablecoin loses peg during planned USDC.e transition<\/strong><\/h2>\n<p>WEMIX$ was designed to track the U.S. dollar on the WEMIX3.0 network. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.coingecko.com\/en\/coins\/wemix-dollar\" target=\"_blank\" rel=\"nofollow\">CoinGecko data<\/a> showed the stablecoin falling close to its recorded low after the breach, with a weekly decline of about 98.9%. The price move followed the unauthorised minting and rapid conversion of newly created tokens, although the final financial loss remains separate from the amount minted.<\/p>\n<p>The incident came while WEMIX was already replacing WEMIX$ with USDC.e across its gaming and financial services. In March, the company <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.wemix.com\/news\/advance-notice-of-termination-of-wemix-support-on-wemix-play-and-transition-to-usdce-da4dc058ebda\" target=\"_blank\" rel=\"nofollow\">announced<\/a> that WEMIX PLAY would change its base currency from WEMIX$ to USDC.e. It scheduled the main service transition for April and began closing or reorganising older WEMIX$ pools. The breached contract therefore belonged to a stablecoin system already moving toward reduced use.<\/p>\n<h2 class=\"wp-block-heading\"><strong>New breach follows the 2025 Play Bridge hack<\/strong><\/h2>\n<p>The latest event follows a separate WEMIX security breach in February 2025. As crypto.news previously reported, attackers removed about 8.6 million WEMIX tokens, then worth roughly $6.04 million, from the Play Bridge Vault. WEMIX shut the affected server and reported the case to the Seoul Metropolitan Police Agency\u2019s cyber investigation unit.<\/p>\n<p>That earlier incident also led to criticism because WEMIX disclosed it several days after discovering the breach. South Korea\u2019s major exchanges later delisted WEMIX in June 2025. As related crypto.news coverage noted, Upbit, Bithumb, Coinone, Korbit and Gopax coordinated the action through the Digital Asset Exchange Alliance. The new contract breach occurred as the project approached the period when a future domestic relisting application could become possible.<\/p>\n<p>WEMIX has not released a final attack report, named the source of the stolen owner credentials or confirmed the total unrecovered loss. Its latest response focuses on wallet tracing, service suspensions, asset-freeze requests and contract analysis. Further notices are expected to clarify whether the attacker exploited code, obtained a private key or accessed an internal account with contract-control rights.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WEMIX confirmed that an attacker took control of owner privileges linked to its WEMIX$ stablecoin contract on July 26. Summary Compromised owner privileges allowed an attacker to mint approximately 5.23&hellip;<\/p>\n","protected":false},"author":1,"featured_media":30647,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-35499","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35499","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=35499"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35499\/revisions"}],"predecessor-version":[{"id":35500,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35499\/revisions\/35500"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/30647"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=35499"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=35499"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=35499"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}