WEMIX stablecoin breach exposes governance gaps in Korean gaming-chain tokens
An owner-key compromise let an attacker mint 5.23m WEMIX$ and move $724,198 across chains, reviving scrutiny of issuer controls.

South Korean gaming-blockchain operator WEMIX has frozen bridges and paused several core services after an attacker seized control of privileged owner permissions on the smart contract underpinning its stablecoin, WEMIX$, minting roughly 5.23 million tokens without authorisation.
The incident, disclosed by WEMIX and reported by crypto.news and TokenPost, again puts the governance controls surrounding privately issued stablecoins under scrutiny, at a moment when regulators across Asia and Europe are tightening supervision of exactly this kind of administrative “owner key” exposure.
Owner privileges compromised, tokens swapped and bridged
According to WEMIX’s official incident update, the attacker breached ownership control of the contract linked to WEMIX Dollar at around 9:17 UTC on 26 July (6:17pm local time in South Korea), and issued approximately 5,225,525 WEMIX$ without permission.
The minted tokens were then converted into 30,736 WEMIX and 724,198.27 USDC.e. The USDC.e was bridged to Ethereum and BNB Smart Chain and partly swapped into ETH and USDT before being dispersed across multiple addresses, with some funds reaching centralised exchanges, WEMIX said.
An earlier Korean media estimate had put the value of the abnormal issuance and transfers at roughly $6.25 million, a figure WEMIX’s later, more granular breakdown revised down. The company cautioned that its disclosed figures remain preliminary and may change as the investigation continues.
Bridges, liquidity pools and DEX paused pending review
WEMIX temporarily suspended all bridges connected to its WEMIX3.0 network, including Chainlink’s CCIP and the PLAY Bridge, and halted trading in affected liquidity pools while withdrawing foundation-provided liquidity. The WEMIX$ Module and the PNIX decentralised exchange were also paused as part of the containment effort, both sources reported.
The company said it has identified suspected attacker wallets and asked exchanges and stablecoin issuers to help freeze linked funds, adding that several exchanges have already frozen affected addresses. WEMIX has not named which exchanges cooperated, nor disclosed how much of the stolen value remains frozen, recoverable, or still under the attacker’s control.
Neither report indicates whether ordinary user balances were directly affected, and WEMIX has yet to publish a full list of compromised contracts, transaction hashes or confirmed recovery amounts — details that matter because the nominal value of tokens minted does not necessarily equal the sum an attacker ultimately extracts.
A second security lapse in as many years
The breach follows a bridge hack that struck WEMIX in 2025 and arrives just as the project has been expanding its USDC.e-based stablecoin services, underscoring the recurring exposure that privileged administrative access creates for projects layering stablecoin issuance onto gaming-focused blockchains.
For a market where South Korean regulators are actively drafting rules for fiat-backed tokens, the episode is likely to feed arguments that issuers of stablecoin-adjacent instruments need externally audited key-management and multisig controls, rather than single points of administrative failure. WEMIX said the root cause of the owner-privilege compromise remains under investigation alongside blockchain security firms.
Read more: Coupang-Woori won stablecoin trial hinges on Seoul’s unfinished fiat-token rules


