WEMIX investigates July 26 abnormal minting after smart contract takeover

The project said an attacker exploited a publicly known on-chain vulnerability to seize two contracts and illicitly mint 5.2255 million WEMIX in flash-loan-driven transactions.

USDC
WEMIX

Summary

WEMIX said a July 26 incident that led to abnormal token minting was caused by the unauthorized transfer of ownership of two smart contracts, DIOS and AMA, to a third party that then deployed a malicious contract and executed nine rounds of flash loans and swap transactions. The project said 5.2255 million WEMIX were illicitly minted in the attack. It added that the incident did not stem from a breach of its internal systems or administrator private keys, but from the exploitation of a publicly known on-chain smart contract vulnerability. Earlier disclosures had described the event as an administrator privilege compromise and said some leaked assets had been frozen, with 723,244 USDC.e and 34,752 WEMIX identified as transferred out. WEMIX had also said it took measures involving related contracts and bridges to prevent further losses and would provide more details after damage and compensation are finalized.

Terms & Concepts
  • smart contracts: Self-executing blockchain programs that manage assets or functions based on coded rules.
  • flash loans: Uncollateralized crypto loans that are borrowed and repaid within a single blockchain transaction.
  • minted: Created as new tokens on a blockchain.