In Brief:
- Wemade’s WEMIX ecosystem experienced a major security breach last Sunday, leading to unauthorized minting of over 5 million stablecoins.
- The attacker converted some of the minted tokens into WEMIX and about $724,198 in USDC.e, with funds transferred to exchanges.
- Wemade suspended trading and services while investigating; the incident occurs during a significant transition to new ownership.
Security breach hits WEMIX
Wemade’s WEMIX blockchain ecosystem faced a serious security incident on July 26 when an attacker gained control of the smart contract for the WEMIX$ stablecoin, minting approximately 5,225,000 tokens without authorization.
The abnormal minting activity was first detected at 9:17 UTC. The attacker successfully converted about 30,700 of these tokens into WEMIX and approximately $724,198 in USDC.e before transferring the funds across Ethereum and BNB Chain toward exchanges.
WEMIX acknowledged the breach at 16:30 UTC, initially categorizing it as a potential security issue related to compromised contract ownership. By 01:20 UTC on July 27, Wemade had escalated its efforts, suspending bridges and trading while freezing services throughout the network. WEMIX PLAY, the ecosystem’s game storefront and marketplace, went under maintenance shortly thereafter.
While some outlets reported the hack’s total value as $6.25 million based on the face value of the minted tokens, on-chain analyses indicate the realized theft is closer to $724,198, suggesting most of the minted tokens could still be recoverable.
This incident arises as Wemade undergoes a transition to new ownership involving a Chinese investment group, leaving uncertainties about the future direction of its blockchain initiatives. Recently, the WEMIX token was listed on Kraken, marking a significant development for the ecosystem.