Administrator rights to the contract for Wemix Dollar (WEMIX$), a stablecoin in the WEMIX ecosystem, were stolen, leading to the abnormal minting of about 5.22 million WEMIX$.
Contract administrator rights can control key functions such as adjusting token supply and are typically granted only to a small number of designated addresses. The attacker used the rights to abnormally mint large amounts of WEMIX$ and then converted them into WEMIX and USDC.e, and is believed to have moved some assets to external networks and centralized exchanges.
To prevent the damage from spreading, the Wemix team halted Wemix 3.0 internal and external bridges and related liquidity pool trading, and blocked some Wemix Play services and blockchain-linked content. It also tracked the attacker’s wallet and fund flows and asked global exchanges and stablecoin issuers to freeze assets.
In initial findings released by the Wemix team on the 27th, the abnormal transaction occurred at 6:17 p.m. on the 26th. The attacker stole owner rights for a WEMIX$-related contract and minted about 5,225,525 WEMIX$.
The abnormally minted WEMIX$ was later converted into 30,736 WEMIX and 724,198.27 USDC.e. USDC.e is an asset that moves the Ethereum-based stablecoin USDC so it can be used on other blockchains. A bridge is a channel that connects different blockchains so assets can be moved between them. The converted USDC.e moved through the bridge to Ethereum and Binance Smart Chain (BSC) and was then exchanged and dispersed into assets such as ether (ETH) and tether (USDT). Some assets were confirmed to have flowed into centralized exchanges.
The Wemix team is identifying and tracking the attacker’s wallet address and on-chain fund flows. It also asked multiple global exchanges and stablecoin issuers to freeze assets and cooperate with the investigation, and some exchanges have completed freezes on attacker-related addresses.
The exact attack path and cause have not yet been confirmed. The Wemix team said the responsible department and external experts are jointly verifying the facts, and it is also conducting a full inspection of contracts that are identical to or related to the affected contract. The disclosed minting volume and amount moved out are also initial figures and may change depending on the results of further investigation.
Bridge, liquidity pool halted to block further fund movements
The Wemix team prioritised steps to prevent further movement of stolen assets and the spread of damage. It suspended Chainlink’s Cross-Chain Interoperability Protocol (CCIP), which connects Wemix 3.0 with external networks, and temporarily closed the Wemix Play bridge. CCIP is Chainlink’s connection protocol that standardises data and asset transfers between different blockchains.
It also halted liquidity pool trading between WEMIX and USDC.e and between WEMIX and WEMIX$, as well as liquidity pools between WEMIX$ and CROW, TIPO and PLAY. A liquidity pool is a trading mechanism that enables token swaps using funds deposited by users. The steps were aimed at blocking further swaps of abnormally minted WEMIX$ and preventing damage from spreading. Liquidity supplied by the foundation was proactively withdrawn to prevent further damage.
In services, it suspended WEMIX$-related modules and related services including Phoenix DEX (PNIX DEX), as well as backend systems. PNIX DEX is a decentralised exchange (DEX) where users trade directly without a central operator. It inspected and blocked some blockchain-linked content in certain games and also blocked trading and bidding functions on the non-fungible token (NFT) market.
After the security incident, Wemix Play said it halted operation of its web shop, marketplace and game token swap pool from 11:30 p.m. on the 26th until further notice to check the service environment and improve stability. During the inspection period, token lists are not provided, limiting the ability to check some balance information.
The Wemix team said it confirmed signs that WEMIX$ contract ownership had been stolen when it first announced the possibility of a security incident. It later confirmed abnormal minting and the outflow of external assets during the investigation and expanded the scope of bridge, trading and service blocks.
Mainnet block delay a week earlier, no confirmed link to hacking
Before the incident, the Wemix 3.0 mainnet had a problem on the 19th in which block production was delayed for about 1 hour and 33 minutes. Block production is the process of recording new transactions on the network, and delays can disrupt transaction processing on the network.
Block production was delayed after block number 118,207,418 at 3:07 p.m. The Wemix team completed an emergency recovery at 4:40 p.m. and resumed block production. The block production speed normalised at 6:16 p.m. the same day.
The Wemix team explained the cause was a temporary network delay that created a mismatch between consensus information shared by nodes and the actual latest state. Nodes refer to servers that jointly operate a blockchain network, and if shared information differs among them, there is a risk that incorrect transaction records could be written. Wemix 3.0 is designed to stop block production and wait when such inconsistencies are detected, and it said the protective mechanism functioned normally this time, causing the delay.
The Wemix team said there was no incorrect data recording or user asset damage at the time. On the 21st it deployed an update to improve information querying and processing so expired information would not be used in the consensus process, and from the 22nd it upgraded validation nodes in sequence.
So far, the Wemix team has not identified a link between the two issues. As the exact attack path and cause of the WEMIX$ incident are under investigation, it said further confirmation is needed on whether there is any connection.
The Wemix team said it is continuing to investigate the exact attack path and the scale of damage and will disclose details in follow-up notices as measures to resolve the situation and protect the ecosystem are specified.
A Wemade official said, "As soon as we recognised the abnormal transaction, we took initial measures to prevent the damage from spreading, and we are continuing the investigation." The official added, "We will promptly provide guidance through follow-up notices on any additional confirmed details."