WEMIX Protocol Hit with $6.25M Exploit, Attacker Issues Unauthorized Tokens
The WEMIX protocol has suffered a significant exploit, resulting in the loss of approximately $6.25 million. On July 26 at 18:17 UTC+9, an abnormal transaction occurred, compromising the owner authority and contract related to WEMIX. This gave the attacker the ability to issue WEMIX without authorization and drain USDC.e from the protocol.
The attacker swapped the assets into ETH and USDT, moved funds across wallets, and sent part of it to centralized exchanges as the investigation continues. The total damage currently stands at approximately $6.25 million, equivalent to around 8.7 billion KRW.
The WEMIX team quickly contained the issue by suspending internal and external bridges, Chainlink CCIP suspension, and temporarily taking the PLAY Bridge offline. Liquidity pool trading for WEMIX-USDC.e, WEMIX-WEMIX$, and several other pairs was halted, and the foundation-supplied liquidity was preemptively recovered.