Morning Edition · Tuesday, July 28, 2026Published at 1:30 AM EDT · New York
Attackers seized control of the WEMIX dollar contract, minted tokens outside its reserve controls, and moved about six million dollars across Ethereum and BNB Chain before exchanges froze the addresses.

The WEMIX chain suspended its bridges, liquidity pools, exchange, and stablecoin module after an attacker gained control of the owner privileges on the WEMIX dollar contract and minted 5.23 million tokens outside the reserve controls that are supposed to keep the coin fully backed. The root cause was access-control compromise, not a flaw in the token logic. Whoever held the contract owner key could mint at will.
The attacker converted the newly minted stablecoins into roughly 30,736 WEMIX and 724,198 USDC.e, then moved the proceeds across Ethereum and BNB Smart Chain, with total losses estimated at five to six million dollars. WEMIX said it sent emergency requests to exchanges, several of which froze the associated addresses. This is the second significant breach of the network since early 2025, when a comparable amount was drained.
Separately, on-chain analysts identified 5,287 ETH draining into a single address following a quiet breach linked to custody provider Triple-A, though the source-wallet ownership and the access path remain unconfirmed. Rekt's running case files this week also logged smaller drains across AFX Trade, Ostium, BonkDAO, and Bonzo Finance, the routine background of decentralized finance (DeFi) losses that rarely draw individual attention.
The WEMIX episode is the recurring failure mode of a "fully backed" stablecoin. The backing is only as reliable as the key that governs issuance. A reserve held one-for-one means nothing if an administrator credential can create supply that the reserve never covered, and the immediate response, freezing the entire network, is the admission that decentralization was not the operative control here.
The attacker who moved the funds, and, in framing, critics who argue issuer-controlled "fully backed" stablecoins concentrate risk in a single administrator credential rather than in code.
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
Independent outlets confirm the 5.23 million mint and roughly 724,000 dollars bridged, but the attacker's identity and the exact access path remain unconfirmed and the total loss is a five-to-six-million-dollar estimate.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The exposed parties are holders of issuer-controlled stablecoins and any protocol that trusted WEMIX dollar as collateral, because unauthorized minting dilutes every honest holder and can break the peg the moment the tokens reach a market. The channel is access control. Privileged mint functions concentrate risk in a single credential, so the security of the money supply reduces to key management, not cryptography. A network-wide freeze protects reserves but also demonstrates that the operator, not code, is the final safeguard.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CryptoSlate · crypto.news · CryptoSlate (Triple-A)
Comments
0No comments yet.