OceanAltOceanAlt
risk-events2026-07-272 min read

WEMIX Hit by Contract Exploit, Attacker Drains ~$724K in Assets

The attacker exploited a vulnerability in the stablecoin contract permissions to mint and swap approximately $724,000 in assets, with some funds already transferred to centralized exchanges.

OOceanAlt EditorialSource

Attack Details

On Sunday, July 26, at 09:17 UTC, WEMIX (a Korean Layer-1 blockchain) suffered a contract exploit. Initial investigations show that the attacker took control of the WEMIX$ stablecoin contract ownership, unauthorized minting approximately 5.23 million WEMIX$, which was then swapped for 30,736 WEMIX and 724,198.27 USDC.e.

The USDC.e was subsequently bridged to Ethereum and BNB Smart Chain, converted to ETH and USDT, and distributed across multiple addresses, with some funds already sent to centralized exchanges.

Platform Response

WEMIX has suspended all cross-chain bridges (including Chainlink CCIP and PLAY Bridge), trading on affected liquidity pools, and withdrawn liquidity provided by the foundation. Additionally, the WEMIX$ Module and PNIX DEX have been paused.

The team has flagged the attacker’s wallet and requested assistance from exchanges and stablecoin issuers to freeze assets. Some exchanges have already responded. The investigation is ongoing, and initial figures may change.

Security Takeaways

This incident once again highlights that permission management for stablecoin contracts is a core defense line for on-chain security. A single point of vulnerability can lead to large-scale migration and liquidation of on-chain assets.

Provenance & status

Byline
OceanAlt Editorial
First published
2026-07-27
Last updated
2026-08-01
Content type
Newsflash
Source material
View original ↗

Cite this piece

OceanAlt Editorial (2026). "WEMIX Hit by Contract Exploit, Attacker Drains ~$724K in Assets". OceanAlt. https://oceanalt.com/en/articles/flash-auto-ms2lgsmc-7 (accessed 2026-08-03)

This piece follows our editorial and fact-checking standards. Found an error? tell us — once verified, the correction will be published right here.