WEMIX has suspended bridges connected to WEMIX3.0 after discovering that a contract related to WEMIX$was compromised, leading to the unauthorized issuance of approximately 5,225,525 WEMIX$. According to an announcement on July 27, 2026, the abnormal transaction occurred at 18:17 UTC+9, causing assets to be converted into 30,736 WEMIX and 724,198.27 USDC.e before being moved out of the ecosystem via cross-chain routes.
The Incident
WEMIX stated that the abnormal transaction was recorded at 18:17 on July 26, 2026 Korean time (UTC+9), after ownership rights of a contract related to WEMIX$ were compromised. These rights were subsequently used to issue WEMIX$ unauthorizedly and transfer USDC.e out of the ecosystem.
According to preliminary data from WEMIX, the attacker abnormally minted approximately 5.23 million WEMIX$. This amount of tokens was later converted into 30,736 WEMIX and 724,198.27 USDC.e, before the USDC.e portion was further moved through cross-chain routes. WEMIX noted that these figures were recorded during the initial phase of the investigation and may change as the review process completes.
Update on WEMIX$ Security Issue and Response Measures
The abnormal transactions involving WEMIX$ and have taken immediate emergency measures to protect user assets and prevent further impact. Investigation and asset tracking are actively underway.
Full Announcement:… pic.twitter.com/PHcAdB0uAw
— WEMIX (@WemixNetwork) July 26, 2026
WEMIX has not described this incident as a direct attack on the bridges. According to information released by the project, the core issue lay in the contract related to WEMIX$, while halting the bridges was an emergency measure to restrict the flow of funds from continuing to move to other networks or further impacting liquidity within the ecosystem.
Cross-Chain Fund Movement
The USDC.e portion was subsequently transferred to Ethereum and BNB Smart Chain via cross-chain routes used by the ecosystem, including Chainlink CCIP and PLAY Bridge, according to WEMIX’s description.
From networks outside WEMIX3.0, the assets continued to be swapped into ETH and USDT, then dispersed across multiple addresses. WEMIX stated that a portion of the assets had been deposited into centralized exchanges, making freezing efforts dependent on the degree of coordination between the project, exchanges, and stablecoin issuers.
To date, WEMIX stated that they have identified addresses related to the attacker and are continuing to track on-chain fund flows. The project has not yet disclosed a full list of wallets, the amount of assets frozen, or the portion of assets still outside control.
WEMIX’s Response
WEMIX suspended all bridges connected to WEMIX3.0, including Chainlink CCIP and PLAY Bridge, as an initial reaction upon detecting the incident. This move aimed to restrict the asset flow from continuing to leave the ecosystem while the team investigates the incident.
Liquidity pools related to WEMIX$ were also placed in a suspended state. WEMIX stated that trading in affected pools was halted, and liquidity provided by the WEMIX Foundation was withdrawn to reduce the risk of further loss.
WEMIX also temporarily suspended several services within the ecosystem during the security review. The WEMIX$ Module and PNIX DEX were suspended, while certain in-game blockchain functions, NFT trading, and bidding activities on the marketplace were also restricted.
Outside the ecosystem, WEMIX said it has contacted exchanges and stablecoin issuers to request freezing related assets. The project stated that some exchanges have executed freezes, but did not specify how many assets these measures have helped freeze.
Broader Implications
The incident occurred while WEMIX remains a blockchain ecosystem linked to gaming, NFTs, and on-chain financial services. According to CoinGecko, WEMIX traded around $0.2115-$0.2116 on July 27, with a 24-hour range from $0.1829 to $0.2387. The token’s market capitalization stood at around $105.4 million, FDV around $118.2 million, and 24-hour trading volume reached approximately $2.55 million.

WEMIX price chart (4h). Source: TradingView
A notable point is that this incident relates to control rights of the WEMIX contract. When owner/admin rights are compromised, the attacker can issue tokens unauthorizedly and utilize ecosystem liquidity to convert assets, causing potential damage to spread faster than a typical transactional exploit.
WEMIX’s suspension of bridges, liquidity pools, certain WEMIX PLAY functions, and activities on the NFT marketplace may affect asset withdrawals, swaps, NFT trading, or interactions with in-game blockchain content. The reopening of these services will depend on the security review process for related contracts, bridges, and pools.
What Remains Unclear
WEMIX has yet to publish a full technical root cause of the incident. The current announcement only confirms that ownership rights of the contract related to WEMIX$ were compromised, but does not state how the attacker obtained these rights or whether the incident involves private keys, contract configuration, or internal operational processes.
The possibility of asset recovery also remains unclear. WEMIX said some exchanges have frozen related addresses, but has not disclosed the amount of assets frozen, exchange names, or wallet lists. The timing for reopening bridges, liquidity pools, and services such as PNIX DEX, WEMIX$ Module, or the NFT marketplace has also not been determined.







