Morning Edition · Tuesday, July 28, 2026Published at 1:41 AM EDT · New York
Attackers seized administrative control of the stablecoin's contract, minted tokens outside its stated full-reserve backing, and converted part of the minted tokens before bridges were suspended.

The WEMIX blockchain, a South Korean gaming network, halted all bridges, liquidity pools, and its dollar-pegged stablecoin module after an attacker gained control of the contract's owner privileges and minted 5.23 million WEMIX$ tokens that had no reserve backing. The abnormal issuance was detected around 9:17 a.m. UTC on July 26.
The root cause was access-control compromise, not a flaw in the token's economic design. Whoever held or stole the administrative key could mint tokens freely, bypassing the full-reserve controls WEMIX advertises for the stablecoin. The attacker converted part of the minted supply into roughly 30,736 WEMIX and 724,198 USDC.e, then moved funds across Ethereum and BNB Smart Chain, according to the network's disclosure. WEMIX sent emergency requests to multiple exchanges, several of which froze the linked addresses.
This is WEMIX's second major security incident since early 2025, when roughly $6 million was stolen. The recurrence points to the same weakness that has produced many of this year's large losses: privileged keys that concentrate the power to mint or move funds in a single point of failure. A stablecoin's claim to full backing is only as credible as the controls on who can call its mint function.
Framing the loss as a stolen administrative key rather than a design flaw protects WEMIX's stablecoin model and aids rival chains marketing stronger key management, while short sellers of WEMIX benefit from the disruption.
The event is corroborated by multiple independent outlets including Korea's Seoul Economic Daily, but who obtained the owner key, whether an insider or external attacker, and the final recoverable loss remain unconfirmed.
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Unauthorized-mint exploits keep proving that the largest crypto risk is often administrative, not cryptographic. Holders of WEMIX$ and users bridged into the network are exposed directly, because minting unbacked tokens dilutes the peg and freezing the network locks their funds until controls are restored. The channel is trust in the issuer's key management: a stablecoin marketed as fully reserved fails the moment one compromised key can create supply the reserves do not cover.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CryptoSlate · crypto.news
Comments
0No comments yet.