A Stolen Owner Key Mints 5.23M WEMIX$

An attacker took owner privileges on the WEMIX$ smart contract on Sunday and used them to mint millions of tokens that nobody had bought. The WEMIX Foundation shut the network's bridges within hours. The unauthorised mint ran at about 09:17 UTC, 18:17 in Seoul, and the size of it depends on who counted: crypto.news reported 5.23 million WEMIX$, while The Crypto Times put the figure at about 5.22 million. The dollar loss is no firmer. Most coverage framed it as about $6.25 million, a Korean report the same week said $5.2 million, and we could not establish which figure supersedes which. WEMIX$ fell close to a record low, down roughly 98.9% on the week.
What an owner key can do
Many token contracts keep an owner address, a single account with administrative powers written into the code at deployment, normally including the right to mint new units. Where the contract sets no supply cap, that right is effectively unlimited. Whoever controls the key can create tokens at will, and the chain treats them as genuine, because by the contract's own rules they are. That puts an owner-key compromise in a different class from a stolen user wallet. A drained wallet costs its owner whatever was in it; the supply of the asset is unchanged and every other holder is untouched. A stolen owner key attacks the accounting of the asset itself: new units appear against no deposit, and everyone holding the token or supplying it to a liquidity pool carries the dilution. For an asset meant to hold a fixed value, as WEMIX$ was, the arithmetic breaks the moment the mint clears.
724,198 USDC.e across two chains
The reporting traced the minted supply into 724,198.27 USDC.e and 30,736 WEMIX, bridged from there to Ethereum and BNB Smart Chain, swapped into ETH, USDT and other assets, and partly sent on to centralised exchanges. Each hop makes recovery harder. A bridge moves value out of the reach of the issuing network's own controls, and a swap into a widely held asset breaks the link between the stolen units and what the attacker now holds. Speed is the other problem, since value tends to be dispersed within minutes once keys are in the wrong hands, well before an operator can convene a response.
Bridges down, exchanges asked to freeze
WEMIX suspended all WEMIX3.0 bridges within hours, including Chainlink's CCIP and the PLAY Bridge, paused the affected liquidity pools and pulled foundation-supplied liquidity, halted the WEMIX$ Module and the PNIX decentralised exchange, and disabled NFT marketplace functions. The foundation said it had identified the wallets used and had asked several global exchanges and stablecoin issuers to freeze assets, with some complying. What it did not say is how the owner key was obtained. It gave no account of the compromise and no description of how the privilege was held or by how many signers. Whether the key was recovered or rotated went unaddressed. It also published no figure for holder losses and no compensation position, and set no timetable for restoring the halted services. Several of the month's larger losses have come from compromised keys and development tooling rather than from flaws in contract logic, and the missing detail here is precisely the part that would tell holders which of the two this was.
A second breach in eighteen months
This was the second major breach of WEMIX in eighteen months. In February 2025, attackers drained 8.65 million WEMIX, worth about $6.1 million to $6.2 million, using authentication keys taken from the Play Bridge Vault, and a roughly 60% price decline followed. The timing was awkward operationally too. The incident came weeks after a Kraken listing on 8 July and the network's second halving on 1 July, and in the middle of a planned migration from WEMIX$ to USDC.e for gaming services, a migration that now has to proceed with the bridges it depends on switched off. The open questions start with how the owner key was taken and how much of the bridged value the freeze requests actually caught. Beyond that sits what the foundation will change about contract privileges before it turns the network's transfer paths back on.