WEMIX says attacker moved about $724,000 after contract breach

cointelegraphPublished on 2026-07-27Last updated on 2026-07-27

Abstract

WEMIX reported a security breach where an attacker gained control of a contract linked to its WEMIX$ stablecoin, issuing approximately 5.23 million unauthorized tokens. These were converted into 30,736 WEMIX and 724,198.27 USDC.e. The attacker bridged the USDC.e to Ethereum and BNB Smart Chain, swapping for assets like Ether and USDT, and distributed them across multiple addresses, with some funds deposited into centralized exchanges. WEMIX has identified the attacker's wallets, requested freezes from exchanges and issuers, and confirmed some addresses have been frozen. In response, the company temporarily suspended all bridges to its WEMIX3.0 network, affected liquidity pool trading, and services like the WEMIX$ Module and PNIX DEX. The cause, full impact, and final figures are under investigation.

Layer-1 blockchain network WEMIX said an attacker moved about 724,000 in USDC.e tokens after compromising ownership of a contract linked to its WEMIX$ stablecoin and issuing tokens without authorization.

The abnormal transactions occurred on Sunday at 9:17 UTC, according to a preliminary incident update from WEMIX. The attacker issued about 5.23 million WEMIX$, which was converted into 30,736 WEMIX and 724,198.27 USDC.e. The USDC.e was then bridged to Ethereum and BNB Smart Chain before being exchanged for assets including Ether and Tether’s USDT and distributed across multiple addresses.

WEMIX said some of the funds were deposited into centralized exchanges. The company identified the attacker’s wallets and requested asset freezes and assistance from exchanges and stablecoin issuers, adding that some exchanges had already frozen addresses linked to the incident.

The company temporarily suspended all bridges connected to its layer-1 network, WEMIX3.0, including Chainlink CCIP and the PLAY Bridge. It also suspended trading in affected liquidity pools, withdrew foundation-provided liquidity, and paused services including the WEMIX$ Module and PNIX decentralized exchange.

WEMIX said the cause and full impact remain under investigation and warned that the preliminary figures could change.

Cointelegraph contacted WEMIX for additional information but did not receive an immediate response.

Related: DeFi TVL drops 39% in 2026 amid market downturn and record hack activity


Trending Cryptos

Related Questions

QWhat type of asset did the attacker primarily move after the contract breach?

AThe attacker moved about 724,000 USDC.e tokens.

QOn which day did the abnormal transactions from the attack occur?

AThe abnormal transactions occurred on Sunday.

QWhat action did WEMIX take regarding the bridges connected to its WEMIX3.0 network?

AWEMIX temporarily suspended all bridges connected to its WEMIX3.0 network.

QWhat did the company do after identifying the attacker's wallets?

AThe company requested asset freezes and assistance from exchanges and stablecoin issuers.

QAre the preliminary figures regarding the attack's impact considered final by WEMIX?

ANo, WEMIX warned that the preliminary figures could change as the full impact remains under investigation.

Related Reads

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of LAYER (LAYER) are presented below.

活动图片