South Korean gaming outfit Wemade’s WEMIX blockchain ecosystem has suffered its second major security incident in under two years. On Sunday 26th July, an attacker seized control of the smart contract governing its WEMIX$ stablecoin and minted roughly 5,225,000 tokens without authorization.
According to WEMIX’s own verified account, abnormal minting activity began around 9:17 UTC on Sunday. The attacker converted a portion of the illegitimately minted supply — approximately 30,700 tokens — into WEMIX and roughly $724,198 in USDC.e, then moved the funds across both Ethereum and BNB Chain toward exchanges.
WEMIX confirmed the breach publicly at 16:30 UTC, initially describing it as a “potential security breach” tied to compromised contract ownership.
By 01:20 UTC on Monday 27th July 27, the network had escalated its response, suspending bridges and trading and freezing affected services across the board. WEMIX PLAY — the ecosystem’s game storefront, marketplace, and token swap pool — was placed under maintenance shortly after.
A number of news sites have described this as a “$6.25 million” hack, a figure that represents the face value of the entire unauthorized token mint. More granular onchain breakdowns circulating since the incident put the realized theft closer to $724,198, suggesting that the bulk of the illegitimately minted supply may still be recoverable.
The news comes at a tricky time for Wemade, which is in the process of being taken over by a Chinese-backed investment group that hasn’t made its commitment to blockchain clear. However, it also recently got its WEMIX token listed on Kraken.