TLDR
- An attacker gained holder-level control of the $WEMIX stablecoin contract on July 26 and minted 5.23 million tokens without authorization.
- The tokens were converted into 30,736 WEMIX and 724,198 USDC.e before being linked to Ethereum and the BNB Smart Chain.
- WEMIX has suspended all bridges, liquidity pools and related services including the PNIX exchange and the $WEMIX module.
- Several exchanges froze linked addresses after WEMIX requested emergency assistance.
- The hack comes just over a year after the 2025 hack that cost WEMIX nearly $6 million and led to the delisting of major South Korean exchanges.
On July 26, the WEMIX blockchain gaming network confirmed that an attacker had taken control of owner privileges associated with its $WEMIX stable contract. The hack began at approximately 9:17 UTC.
JUST IN: WEMIX suspends bridging services and wemix-token:native trading after an attacker exploited a linked smart contract, stealing approximately $724,000. The network has frozen the affected funds and temporarily halted key services while the investigation continues. pic.twitter.com/2KUPwTgOd3
– EyeWhales (@EyeWhales) July 27, 2026
The attacker used compromised access to around 5.23 million $WEMIX tokens without any authorization. These tokens were then converted into 30,736 WEMIX and 724,198.27 USDC.e.
USDC.e is connected to Ethereum And BNB Smart Chain. From there, the shards were swapped into USDT for Ether and Tether and spread across multiple wallet addresses.
Some of the stolen assets reached central exchanges. WEMIX identified the attacker’s wallets and contacted exchanges and stablecoin issuers, requesting a freeze of assets. The company confirmed that several exchanges have already frozen linked addresses.
WEMIX did not name those exchanges or mention the amount of funds that were frozen or recovered.
Services are suspended across the network
In response to the attack, WEMIX temporarily suspended all bridges connected to its WEMIX3.0 network. This comment included Chain link CCIP and PLAY BRIDGE.
Trading has also been temporarily halted in the affected liquidity pools. The company withdrew liquidity provided by the institution and suspended the $WEMIX unit and the decentralized PNIX exchange while contract permissions were reviewed.
WEMIX said the reason for the waiver of the owner’s lien remains under investigation. The company cautioned that early numbers may change as review continues across multiple networks.
CoinGecko data showed that $WEMIX fell near its lowest levels recorded after the hack, with a weekly decline of about 98.9%. This came after unauthorized minting and rapid conversion of newly created tokens.
The hack occurred while WEMIX was already in the process of replacing $WEMIX with USDC.e via its gaming and financial services. In March, the company announced that WEMIX PLAY would change its base currency from $WEMIX to USDC.e, with the major transition scheduled to take place in April.
The second major security breach in less than two years
This latest incident is not WEMIX’s first serious security breach. In February 2025, attackers drained approximately 8.6 million WEMIX tokens, worth approximately $6.04 million at the time, from the Play Bridge Vault.
This previous hack attracted criticism because WEMIX disclosed it several days after the hack was discovered. Major exchanges in South Korea, including Upbit, Bithumb, Coinone, Korbit, and Gopax, coordinated the delisting of WEMIX in June 2025.
The new violation occurred when the project was approaching the point at which it could apply to relist on local exchanges. WEMIX has not yet issued a full report on the attack, identified the source of the compromised credentials, or confirmed the total unrecovered loss.








