A Stolen Owner Key Mints 5.23M WEMIX$

An attacker seized owner privileges over the WEMIX$ smart contract on Sunday and used them to mint millions of tokens that nobody had bought, forcing the WEMIX Foundation to shut the network's bridges within hours. The unauthorised mint ran at about 09:17 UTC, 18:17 in Seoul. Accounts of the amount differ slightly: crypto.news reported 5.23 million WEMIX$, while The Crypto Times put it at about 5.22 million. The loss was framed as about $6.25 million in most coverage and as $5.2 million in a Korean report the same week. WEMIX$ fell close to a record low, down roughly 98.9% on the week.
The Privilege: What an Owner Key Can Do
Many token contracts keep an owner address — a single account granted administrative powers written into the code at deployment, which normally include the right to mint new units. Where the contract sets no supply cap, that right is effectively unlimited: whoever controls the key can create tokens at will, and the chain treats them as genuine, because by the contract's own rules they are. That makes an owner-key compromise a different class of event from a stolen user wallet. A drained wallet costs its owner whatever was in it, but the supply of the asset is unchanged and every other holder is untouched. A stolen owner key attacks the accounting of the asset itself: new units appear against no deposit, and the dilution is carried by everyone holding the token or supplying it to a liquidity pool. For an asset meant to hold a fixed value, as WEMIX$ was, the arithmetic breaks the moment the mint clears.
The Route: 724,198 USDC.e Across Two Chains
The minted supply was converted into 724,198.27 USDC.e and 30,736 WEMIX, then bridged to Ethereum and BNB Smart Chain, swapped into ETH, USDT and other assets, and partly sent on to centralised exchanges, according to the reporting. Each hop makes recovery harder: a bridge moves value out of the reach of the issuing network's own controls, and a swap into a widely held asset breaks the link between the stolen units and what the attacker now holds. Speed is the other problem, since value tends to be dispersed within minutes once keys are in the wrong hands, well before an operator can convene a response.
The Response: Bridges Down, Exchanges Asked to Freeze
WEMIX suspended all WEMIX3.0 bridges within hours, including Chainlink's CCIP and the PLAY Bridge, paused the affected liquidity pools and pulled foundation-supplied liquidity, halted the WEMIX$ Module and the PNIX decentralised exchange, and disabled NFT marketplace functions. The foundation said it had identified the wallets used and had asked several global exchanges and stablecoin issuers to freeze assets, with some complying. What it did not say was how the owner key was obtained: no account of the compromise, no description of how the privilege was held or by how many signers, and no statement on whether the key was recovered or rotated. It also published no figure for holder losses, no compensation position and no timetable for restoring the halted services. Several of the month's larger losses have come from compromised keys and development tooling rather than from flaws in contract logic, and the missing detail here is precisely the part that would tell holders which of the two this was.
Still Unresolved: A Second Breach in Eighteen Months
This was the second major breach of WEMIX in eighteen months. In February 2025, attackers drained 8.65 million WEMIX, worth about $6.1 million to $6.2 million, using authentication keys taken from the Play Bridge Vault; a roughly 60% price decline followed. The latest incident also arrived at an awkward moment operationally, weeks after a Kraken listing on 8 July and the network's second halving on 1 July, and in the middle of a planned migration from WEMIX$ to USDC.e for gaming services — a migration that now has to proceed with the bridges it depends on switched off. The open questions are how the owner key was taken, how much of the bridged value the freeze requests actually caught, and what changes to contract privileges the foundation will make before it turns the network's transfer paths back on.