WEMIX says public smart contract flaw, not key leak, caused WEMIX$ security incident

WEMIX says public smart contract flaw, not key leak, caused WEMIX$ security incident

N
News Editor
2026-07-30 10:53:00
WEMIX has released a fresh update on the WEMIX$ security incident, saying the breach stemmed from a vulnerability in publicly visible on-chain smart contracts rather than an intrusion into internal systems or a leak of administrator private keys. According to the company, ownership of two contracts, DIOS and AMA, was transferred to an unauthorized third party on July 26. DIOS is designed to help maintain WEMIX$ price stability, while AMA supports 1:1 exchanges between WEMIX$ and collateral assets. WEMIX said the attacker deployed a malicious contract in a single transaction, took control of both contracts, and then carried out nine rounds of flash loans and swap transactions. The result was the unauthorized minting of 5,225,524.9997 WEMIX$. The attacker then moved roughly 723,244 USDC.e and 34,752 WEMIX. WEMIX said transactions involving game tokens linked to WEMIX$ are still under review, and more details will be shared once the scope of impact and compensation amount are confirmed. The team has revoked WEMIX$ minting authority, identified the attacker’s address, asked exchanges that received the funds to blacklist it, and filed a formal report with law enforcement. Earlier reports said the funds had been bridged to Ethereum and BSC.

WEMIX has published a cause analysis and response update on the WEMIX$ security incident, saying that on July 26 the ownership of two smart contracts was transferred to an unauthorized third party. The company said the case did not involve a breach of WEMIX internal systems or a leak of administrator private keys.

Two contracts were taken over without authorization

The affected contracts were DIOS and AMA. WEMIX said DIOS is intended to maintain the price stability of WEMIX$, while AMA is meant to exchange WEMIX$ for collateral assets on a 1:1 basis.

According to the update, the attacker deployed a malicious contract in a single transaction, gained control of both contracts, and carried out nine rounds of flash loan and swap transactions. That led to the unauthorized minting of 5,225,524.9997 WEMIX$.

Attack method and fund movements

WEMIX said the incident came from a vulnerability in publicly exposed on-chain smart contracts. The attacker then transferred out about 723,244 USDC.e and 34,752 WEMIX.

The team is still analyzing transactions involving game tokens associated with WEMIX$. It said more details will be released after the scope of the impact and the compensation amount are confirmed.

Steps taken after the incident

To prevent any further minting, WEMIX$ minting authority has been revoked. WEMIX said the attacker’s address has been identified, and exchanges that received the funds have been asked to blacklist it.

The team also said it has submitted a formal report to relevant law enforcement authorities, and the investigation is ongoing.

Earlier reports said that after the WEMIX contract ownership compromise, more than 5.22 million WEMIX were minted and the funds had already been bridged to Ethereum and BSC.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
660

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.