Hackers used administrator privileges of a smart contract and minted approximately 5,225,525 unbacked $WEMIX tokens worth about $5.22 million. The freshly issued tokens were then passed through a decentralized exchange and swapped for 30,736 $WEMIX and 724,198.27 $USDC.e — this is a version of the stablecoin $USDC circulating on the mainnet of the WEMIX3.0 project.
Then the attackers withdrew the $USDC.e to the Ethereum network and the BNB Smart Chain. There, the funds were converted into ETH and USDT and distributed across numerous wallets. Representatives of $WEMIX reported that some of these assets were later sent to centralized exchanges. The total damage from the hack is estimated at $6.25 million.
$WEMIX has disabled almost all of its services, suspended the operation of all bridges connecting the WEMIX3.0 mainnet to external blockchains. In addition, trading in the affected liquidity pools has been frozen, including for the pairs $WEMIX–$USDC.e, $WEMIX–$WEMIX, CROW–$WEMIX, TIPO–$WEMIX$ and PLAY–$WEMIX$. On the $WEMIX PLAY platform, trading and staking on the $NFT marketplace have been disabled.

The platform is now trying to get exchanges to freeze the withdrawn assets. The WEMIX stablecoin lost its peg to the dollar, falling by 98% to $0.01.
In February of last year, attackers withdrew approximately $8.65 million worth of $WEMIX from the Play Bridge vault — at that time, the token's value was about $6.15 million. The incident was related to the compromise of authentication keys used for monitoring the $NFT platform Nile. According to the investigation, the hackers spent nearly two months in the system before withdrawing the funds.
end-content




