WEMIX has confirmed that an attacker compromised a smart contract linked to its WEMIX$ stablecoin and siphoned off roughly $724,000 in stablecoin liquidity in an incident that unfolded early Sunday morning. According to the project, the breach occurred at 9:17 UTC on July 26, when the attacker gained unauthorized control over the contract and minted 5.23 million WEMIX$ tokens without approval.
The attacker then converted the improperly issued tokens, moving 30,736 WEMIX and 724,198.27 USDC.e out of the affected contract. From there, the stolen USDC.e was bridged across chains, landing on both Ethereum and BNB Smart Chain, where it was swapped into Ether and Tether before being scattered across a network of separate wallets. Some of the funds have since turned up in deposits to centralized exchanges, according to WEMIX's account of the incident.
Emergency Shutdown Across WEMIX3.0
WEMIX moved quickly to contain the fallout. The team suspended every bridge connecting to its WEMIX3.0 network, including both Chainlink's CCIP integration and the project's own PLAY Bridge, cutting off routes the attacker might have used to move funds further. Trading in liquidity pools tied to the affected contract was halted, and the foundation withdrew its own liquidity from those pools to limit further exposure.
Beyond the bridges and pools, WEMIX paused two additional pieces of its ecosystem as a precaution: the WEMIX$ Module itself and PNIX, the project's decentralized exchange. Taken together, the response amounts to a near-total freeze of the token's on-chain infrastructure while engineers work through the aftermath.
Investigation Still Open
WEMIX has been cautious about drawing firm conclusions this early. In its public statement, the team said "the cause and full impact remain under investigation," adding that the preliminary figures released so far could still change as the review continues. That caveat leaves open the possibility that the final tally of stolen or exposed funds ends up higher or lower than the initial $724,000 estimate.
Related: Crypto Weekly Movers: BEAT Rallies 50% as DEXE Craters on DeFi Hacks
On the recovery side, WEMIX said it has identified wallet addresses tied to the attacker and has already reached out to exchanges and stablecoin issuers to request asset freezes. The company indicated that some exchanges have moved to freeze linked addresses, though it stopped short of naming which platforms complied or disclosing how much of the stolen total, if any, has been recovered so far.
What Happens Next
For now, users of WEMIX3.0 are locked out of bridging, liquidity trading, and the WEMIX$ Module until the team completes its review. Gaming-focused blockchain projects like WEMIX have increasingly become exploit targets as they bridge tokens across multiple networks, and this incident adds to a string of contract-level breaches hitting the sector this year. WEMIX has not yet given a timeline for restoring the suspended services.