South Korean gaming giant Wemade’s blockchain arm WEMIX has been hit by another major security breach, its second in less than 18 months, after an attacker seized ownership of a smart contract linked to its dollar-pegged stablecoin WEMIX$ and made off with roughly $6.25 million worth of digital assets.
The Layer 1 blockchain network, which powers a global Web3 gaming ecosystem built by the Korean-listed publisher behind MIR4 and Night Crows, confirmed the incident in an official statement posted on the morning of July 27, roughly 15 hours after the abnormal transactions were first detected on-chain.
What Went Wrong
According to WEMIX, the exploit began at 18:17 KST on July 26 (09:17 UTC), when an unidentified attacker gained administrator privileges over a contract tied to the WEMIX$ stablecoin. Using those privileges, the attacker minted approximately 5,225,525 WEMIX$ out of thin air, an issuance worth around $5.22 million at par.
The freshly minted tokens were then routed through a decentralized exchange (DEX) and swapped into 30,736 WEMIX and 724,198.27 USDC.e, the bridged version of Circle’s USDC that circulates on the WEMIX3.0 mainnet.
From there, the attacker moved the USDC.e off WEMIX3.0 through bridges into Ethereum and the BNB Smart Chain, where the funds were swapped into a mix of ETH and Tether’s USDT and scattered across multiple wallets. WEMIX has confirmed that a portion of these assets was subsequently deposited into centralized exchanges, adding a layer of urgency to the recovery effort.
Based on assets actually siphoned externally, the immediate damage sits at roughly 724,000inUSDC.e.IncludingtheunauthorisedWEMIX724,000 in USDC.e. Including the unauthorised WEMIX 724,000inUSDC.e.IncludingtheunauthorisedWEMIX issuance that briefly hit circulation, the headline figure comes closer to $6.25 million.
Emergency Shutdown Across the Ecosystem
Within hours of detecting the abnormal transactions, WEMIX pulled a wide range of services offline in what is effectively a full defensive lockdown of its blockchain economy.
All bridges connecting to and from the WEMIX3.0 mainnet have been temporarily suspended, including the recently integrated Chainlink CCIP and the PLAY Bridge that moves assets between the WEMIX gaming environment and external chains. Trading in the affected liquidity pools has also been frozen, covering the WEMIX-USDC.e, WEMIX-WEMIX, CROW-WEMIX, CROW-WEMIX, CROW-WEMIX, TIPO-WEMIX$ and PLAY-WEMIX$ pairs, and the WEMIX Foundation has withdrawn all of its own provided liquidity.
On the service side, the WEMIX$ Module and PNIX DEX, the network’s in-house decentralized exchange, have both been paused along with their backend systems. Blockchain-integrated features inside several games have been proactively restricted, and NFT marketplace trading and bidding on the WEMIX PLAY platform have been disabled while the team runs a broader contract audit.
Chasing the Money
WEMIX says it has identified the wallets used in the attack and is actively tracking fund flows on-chain. The foundation has formally requested asset freezes and cooperation from several global exchanges and stablecoin issuers, and confirmed that some venues have already frozen addresses linked to the incident. If tracing efforts fail, the company has flagged the possibility of escalating the matter to law enforcement.
The foundation added that a comprehensive inspection of all related contracts and structurally similar contracts is underway, and warned that the preliminary figures could shift as investigators piece together the full picture.
A Second Hit for WEMIX After the 2025 Bridge Exploit
This is not the first time the WEMIX ecosystem has been forced into damage control mode. In February 2025, attackers drained roughly 8.65 million WEMIX tokens, worth around $6.1 to $6.2 million at the time, from the platform’s Play Bridge Vault. That earlier incident was traced back to compromised authentication keys used for monitoring the Nile NFT platform, with investigators believing the attacker had spent nearly two months inside the system before withdrawing funds.
The handling of that hack drew as much scrutiny as the hack itself. Wemix Foundation CEO Kim Seok-hwan disclosed the breach four days after it was detected, a delay he later said was intended to prevent panic and further exploitation while the team assessed the damage. The controversy contributed to the Digital Asset eXchange Alliance (DAXA), the joint body of South Korea’s major crypto exchanges, moving to end trading support for WEMIX, which sent the token tumbling more than 60% in a single session.
Today’s exploit represents a fundamentally different attack surface. Where the 2025 breach exploited stolen operational credentials, the latest incident targeted contract ownership itself, one of the most sensitive access controls in any smart contract system. Losing owner privileges effectively hands an attacker the keys to mint, upgrade or drain, depending on how the contract is written.
Timing Could Not Be Worse
The breach lands at a delicate moment for Wemade’s blockchain push. On July 1, WEMIX completed its second halving event, cutting the block reward as part of its long-term supply schedule.
A week later, on July 8, the token secured a marquee listing on Kraken, opening it up to retail and institutional users across the United States, Canada, the United Kingdom and Australia in what the company described as a pivotal moment for global liquidity. Around the same time, WEMIX rolled out Chainlink CCIP integration as part of a broader cross-chain interoperability push.
Wemade had also signaled that WEMIX PLAY was gradually moving away from WEMIX$ in favor of USDC.e, suggesting the compromised stablecoin was already on a slow sunset track.
That has not softened the blow. WEMIX$ has faced repeated depeg episodes in the past, and the loss of ownership control over its contract is likely to reopen questions about the soundness of privately issued, game-linked stablecoins more broadly, a category Korean regulators have been watching closely.
Part of a Rough Stretch for Web3 Security
The WEMIX exploit adds to what has already been a punishing week for the sector. The Crypto Times reported earlier this week that crypto losses topped $47 million in a single week, with AFX Trade, Wanchain and Verus among the platforms hit. The Verus Ethereum Bridge alone was drained for roughly $7.54 million on July 23, the second time the same import path has been abused in just over two months.
Zooming out, 2026 is shaping up to be one of the worst years on record for DeFi security, with more than $1 billion already lost across bridge exploits, oracle manipulation and compromised keys, according to industry trackers. Contract ownership takeovers, which are exactly the vector suspected here, sit at the top of the risk pile because they collapse the entire trust model of a protocol in a single transaction.
What Comes Next
WEMIX has said further updates will follow as the investigation progresses, including any revisions to the loss estimate and a decision on when suspended services can be safely restored. The token was trading around $0.24 in the lead-up to the incident, with the market impact of the breach still filtering through as Asian trading resumes.
For a network that has spent the last year rebuilding trust after the 2025 bridge hack, and that just secured its most significant western exchange listing to date, the fallout from this second, fundamentally deeper breach may prove harder to contain than the technical response itself.
Also Read: Triple-A Hot Wallets Drained of $9.3M Across TRON, Ethereum, TON & Solana
