WEMIX suspends bridges after attacker moves $724,000 from compromised contract
The WEMIX layer-1 blockchain network suspended its bridges and other services after an attacker compromised a contract linked to its WEMIX$ stablecoin. The attacker issued 5.23 million unauthorized WEMIX$ and moved 724,198 USDC.e (worth ~$724k) to other chains. WEMIX has requested that centralized exchanges freeze the attacker's wallets, some of which have complied. The full impact is still under investigation.
Contract compromise details
▪The attacker issued approximately 5.23 million unauthorized WEMIX$ tokens.
▪The breach occurred on July 26, 2026, at 9:17 UTC, according to a preliminary update from WEMIX.
▪An attacker compromised ownership of a contract linked to the WEMIX$ stablecoin, enabling unauthorized token issuance.
Attacker fund movements
▪The unauthorized WEMIX$ was converted into 30,736 WEMIX and 724,198.27 USDC.e.
▪An attacker moved 724,198.27 USDC.e, valued at about $724,000, from a compromised WEMIX contract.
▪The bridged funds were exchanged for other assets, including Ether and Tether's USDT, and distributed across multiple addresses.
▪The stolen USDC.e was bridged to the Ethereum and BNB Smart Chain networks.
WEMIX service suspensions
▪WEMIX temporarily suspended all bridges connected to its WEMIX3.0 layer-1 network, including Chainlink CCIP and the PLAY Bridge.
▪WEMIX suspended trading in affected liquidity pools and withdrew liquidity provided by its foundation.
▪WEMIX paused services including its WEMIX$ Module and the PNIX decentralized exchange.
Exchange cooperation requests
▪Some centralized exchanges have already frozen wallet addresses linked to the incident.
▪WEMIX identified the attacker's wallets and requested asset freezes from exchanges and stablecoin issuers.
Ongoing investigation status
▪WEMIX warned that the preliminary figures related to the incident could change.
▪The cause and full impact of the breach remain under investigation by WEMIX.
Story comments
Loading comments…