WEMIX halts its network after a stablecoin minting breach
WEMIX confirmed that an attacker took control of the owner privileges on the contract behind its WEMIX$ stablecoin and used them to issue tokens without authorisation. Roughly 5,225,525 WEMIX$ were abnormally issued and converted into 30,736 WEMIX and 724,198.27 USDC.e. The company put the total exploit at $6.25 million.
The converted proceeds were bridged to Ethereum and BNB Chain, swapped into ETH and USDT and distributed, with some routed directly into centralised exchanges. WEMIX paused bridge functions and liquidity pools, then escalated to suspending bridges and trading across the network entirely. It has been contacting exchanges and stablecoin issuers to freeze the addresses involved, and says several have completed freezes.
A compromised owner key on a mintable stablecoin contract is not something auditing the contract would have caught: it behaved exactly as written, for whoever held the key.