WEMIX contract ownership breach leads to $6.25 million token mint
Security & Exploits ·
Attackers seized owner-level control of the WEMIX smart contract and minted millions of dollars worth of tokens, sending the price down sharply within a day.
The South Korean blockchain gaming platform disclosed that its contract ownership had been compromised, allowing an unauthorized party to create roughly 5.22 million WEMIX tokens, valued at about $6.25 million, according to ChainCatcher. The breach was reported to have occurred on July 26, when the stolen owner privileges were used to mint and move the tokens, per WuBlockchain.
Following the mint, the attacker converted a portion of the tokens into roughly 30,736 WEMIX and about 724,198.27 USDC.e. The USDC.e was then bridged out to Ethereum and BSC, swapped into assets including ETH and USDT, with some funds subsequently deposited on centralized exchanges. WEMIX said it is tracking the attacker's wallet activity and has filed freeze requests with exchanges and stablecoin issuers in an effort to halt further movement of the funds.
The token's price fell 16.65% in the 24 hours following the disclosure, reflecting the market's reaction to the breach. WEMIX has not yet identified the root cause of the compromise and says it is working with external security experts to review the incident, alongside audits of related and similar contracts on its network.
The episode adds to a string of recent security and disclosure failures across the crypto industry. Thailand's SEC separately filed a criminal complaint against Bitkub over an alleged $47 million hack that was not disclosed to the public, according to Decrypt. Together, the incidents underscore ongoing concerns about smart contract security and transparency practices among exchanges and blockchain platforms, particularly those tied to gaming ecosystems.
Unresolved questions include how the attacker obtained owner-level access to the WEMIX contract, whether any of the exchange freeze requests will succeed in recovering funds, and whether the broader review of related contracts will surface additional vulnerabilities. WEMIX has not provided a timeline for completing its investigation or restoring confidence in the affected contract.