Wemix Team, the operator of Wemix, said it has confirmed that a flaw in an initialize function in a proxy-structure contract caused the takeover of contract authority for Wemix dollar (WEMIX$) that occurred on July 26.
Initialize function re-execution allowed, enabling hacking; cause identified.
Wemix Team said that at 6:17 p.m. on July 26, administrator authority in two smart contracts was transferred to a third party. One was DIOS, a contract that keeps the price of Wemix dollar stable. The other was AMA, a contract that exchanges Wemix dollar 1 to 1 with collateral assets.
The attacker deployed an attack contract within a single transaction. After obtaining authority over the two contracts, the attacker repeated flash loans and swaps nine times to illegitimately mint 5,225,524.9997 Wemix dollars.
Wemix Team explained that the incident was not due to an intrusion into internal systems or leakage of an administrator's private key. It said the attack used a flaw in a smart contract 공개ed on the blockchain.
DIOS and AMA were designed at initial deployment with a proxy structure that allows the logic to be replaced later. Under this structure, the initialize function is run once immediately after deployment to register the owner address. At the time of deployment in October 2022, the initialize function ran normally only once, and administrator authority was set correctly.
The problem arose during a third upgrade in November 2022. A code change at the time altered the condition limiting execution of the initialize function. It was changed from allowing only the first execution to allowing up to a second execution. There was no separate access control restriction on this second initialize call. As a result, a vulnerability remained that allowed anyone to call the function directly and register a new administrator address.
Wemix Team said the contracts were developed and deployed by an outsourced developer. It said it is currently checking whether the work followed normal procedures. DIOS and AMA were contracts that were not being used under a plan to end Wemix dollar. It was assessed that the attacker targeted the vulnerability in these unused contracts.
The attacker called the second initialize function and changed the administrator addresses of the two contracts to an attack contract that the attacker created. The attacker then granted itself authority to call minting and exchange functions. It also changed the addresses that receive minting proceeds and fees to its own. The attacker then alternately called AMA's exchange function and DIOS's price-adjustment minting logic to illegitimately mint Wemix dollars. Wemix Team said it has limits on providing details because the matter is under investigation. It added it will share specific information after the investigation ends.
The scale of damage confirmed so far, based on assets transferred externally, is 723,244.4936 USDC.e and 34,752.3199 WEMIX. Wemix Team said indications related to Wemix dollar were also confirmed in some game tokens. It said it is analyzing related transactions and will provide additional information when the scale of damage and compensation is finalized.
Reported to investigative authorities, tracing funds; services to resume in stages.
Wemix Team said it first detected the incident when abnormal movements in game token prices were caught by internal monitoring. It then identified the attacker's address and asked exchanges to blacklist it. It also reclaimed Wemix dollar minting authority to block additional issuance.
It reclaimed liquidity supplied by the foundation and temporarily suspended liquidity pool trading related to Wemix dollar and USDC.e. With cooperation from Chainlink, it also halted the CCIP bridge and Play Bridge. It also suspended the Wemix dollar exchange module and the PNIX DEX service. It also blocked blockchain content in games and bidding on the NFT marketplace.
During this process, some overseas exchanges temporarily suspended WEMIX deposits and withdrawals as a preventive measure. Wemix Team said it is discussing resumption by providing materials confirming safety.
Wemix Team said it formally reported the case to investigative authorities at 1 p.m. on July 28. The investigation is currently under way. It said it is cooperating by providing on-chain analysis materials it secured to investigators. It asked exchanges and stablecoin issuers that received the funds to freeze them. Some addresses have already been frozen. It said it is continuously monitoring addresses with remaining funds. It said it is also working to recover the funds, including through international cooperation.
Wemix Team said it is conducting a comprehensive inspection of all contracts currently in operation as well as all contracts deployed in the past. It added it will take measures to prevent the illegitimately minted Wemix dollars from having a negative impact on the ecosystem.
Services will resume sequentially, starting with services that do not use Wemix dollars, centered on games. Blockchain content for Legend of Ymir, which has little association with Wemix dollars, is scheduled to resume within the day. It said it will provide additional notice once detailed resumption plans are finalized.