Korean WEMIX contract hacked, the full process of a $724k stablecoin cross-chain escape

WEMIX infrastructure contract hacked, attackers stole ownership; after unleashing 5.23 million WEMIX$ in a short time, they swapped across two chains into multiple assets. A total of $724k in stablecoins has already flowed to multiple wallets.
(Background: Breaking News | Sui ecosystem DeFi protocol AftermathFi hacked! $1.1 million USDC drained in 36 minutes)
(Background addition: DeFi Security Column | Breaking down Cream.Finance “ERC-777 reentrancy attack”, hackers profited $18.8 million)

Table of contents

Toggle

  • Attack timeline: 9:17 UTC triggered a release of 5.23 million stablecoins
  • Full shutdown: bridge, liquidity pools, and all DEX trading halted
  • DeFi contract security proves fragile again

South Korea’s WEMIX first-layer blockchain network suffered a contract attack on Sunday. The attackers stole ownership of a contract tied to the WEMIX$ stablecoin. In a short period, they unleashed 5.23 million WEMIX$ and swapped across chains for USDC.e with a value of $724k; the funds were then distributed across multiple wallets.

Attack timeline: 9:17 UTC triggered a release of 5.23 million stablecoins

According to WEMIX’s initial incident update, abnormal transactions occurred on Sunday at 9:17 UTC. The attackers first unleashed roughly 5.23 million WEMIX$ stablecoins on the WEMIX chain, then converted 30,736 of them into WEMIX’s native token, while the remainder was swapped for 724,198.27 USDC.e.

This USDC.e was then bridged to Ethereum and BNB Smart Chain, and exchanged into various assets including Ether (ETH) and Tether’s USDT, before ultimately being distributed to multiple addresses.

Full shutdown: bridge, liquidity pools, and all DEX trading halted

WEMIX announced it was temporarily suspending all bridge services connected to its Layer-1 network WEMIX 3.0, including Chainlink CCIP and PLAY Bridge. Affected liquidity pool transactions were also halted. The foundation withdrew the provided liquidity, and services such as the WEMIX$ Module and PNIX decentralized exchange also went offline.

WEMIX said some funds had been deposited with centralized exchanges. The company identified the attacker’s wallet addresses and requested freezes of assets with exchanges and stablecoin issuers; some exchanges have already executed freezes on the related addresses.

DeFi contract security proves fragile again

WEMIX stated that the reason for the attack and the full impact are still under investigation, and the preliminary figures may be adjusted as the investigation progresses. This also echoes a 2026 DeFi market trend: according to statistics, this year’s total value locked (TVL) in DeFi has fallen by 39%. Multiple hacking incidents have kept security concerns for crypto networks in the spotlight.

This incident also highlights a basic truth for Layer-1 blockchain networks: transfers of contract ownership often go unnoticed quietly on-chain until funds begin moving. For DeFi ecosystems that rely on cross-chain bridges and stablecoins, the cascading effects of contract vulnerabilities are far more alarming than losses from a single protocol.

WEMIX-7.30%
SUI-0.73%
USDC0.00%
ETH4.65%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned