
Unauthorized WEMIX$ minting exposed a breach of owner-level contract control, while the project suspended bridges, pools, game-linked functions and NFT services without giving a reopening timetable.
Wemade said compromised owner-level control tied to a WEMIX$-related contract allowed about 5,225,525 WEMIX$ to be minted without authorization beginning at 18:17 on July 26 (UTC+9), prompting a broad shutdown of bridges, liquidity pools and several WEMIX3.0 services. The project’s whitepaper says WEMIX$ is 100% collateralized by USDC in a Treasury and that minting should be limited to Authorized Mint Access granted only to the DIOS stability protocol, indicating the incident bypassed the stablecoin’s intended 1:1 issuance design. WEMIX said the unauthorized tokens were converted into 30,736 WEMIX and 724,198.27 USDC.e. It said the USDC.e was bridged to Ethereum and BNB Smart Chain, swapped into assets including ETH and USDT, and distributed across multiple addresses, with some assets later deposited at centralized exchanges. The company said some exchanges froze attacker-linked addresses after receiving cooperation requests, but it has not disclosed frozen amounts, a final loss estimate, the exchanges involved, or whether users suffered direct losses. As part of its response, WEMIX suspended every bridge connected to and from WEMIX3.0, including its Chainlink CCIP route and PLAY Bridge, while halting trading in the WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$ and PLAY-WEMIX$ pools. It also paused the WEMIX$ Module and PNIX DEX, restricted blockchain-linked features in some games, and disabled NFT marketplace trading and bidding. The disruption also affects a transition announced in September 2025 to phase out WEMIX$ in favor of USDC.e while continuing conversions through the WEMIX$ Module, which remains suspended. Separately, Bitget said it would suspend WEMIX Mainnet deposits and withdrawals from 2026-07-26 19:51 (UTC+8) for wallet maintenance, with resumption to be announced later.