WEMIX Smart Contract Breach Hits $6.25M - Second Hack in Five Months

Something went badly wrong inside WEMIX’s smart contract infrastructure on July 26. An attacker quietly seized owner-level privileges over the WEMIX$ stablecoin contract — and by the time the team caught on, roughly $6.25 million worth of tokens had already been minted and moved. This wasn’t a wallet compromise or a phishing attack on an ordinary user. It was a direct hit on the protocol’s own privileged access layer, the kind of vulnerability that sits much closer to the engine room than most blockchain security incidents.
Key takeaways
- On July 26, an attacker obtained owner privileges on the WEMIX$ stablecoin contract and minted 5.23 million WEMIX$, stealing approximately $6.25 million.
- The stolen tokens were converted into 30,736 WEMIX and 724,198.27 USDC.e, then dispersed across Ethereum and BNB Chain.
- WEMIX disabled the WEMIX3.0 Bridge and liquidity pools as immediate containment measures, while exchanges froze several attacker-linked addresses.
- Cross-chain dispersal of funds significantly complicates traceability and reduces recovery prospects.
- This is WEMIX’s second major security incident, following a separate breach in February 2025 that drained approximately $6.1–$6.2 million from the Play Bridge Vault.
WEMIX Suffers $6.25 Million Smart Contract Breach
The WEMIX smart contract breach disclosed on July 26 struck at a part of the system that most users never think about: privileged contract ownership. The attacker didn’t need to crack any user wallets. Instead, they obtained owner-level access to the WEMIX$ stablecoin contract — a position that came with the ability to mint and transfer tokens freely.
… Continue reading the full article at the original source below.


