Blockchain ecosystem WEMIX suffered a severe security incident where an attacker gained unauthorized access to the admin/owner permissions governing the WEMIX$ stablecoin smart contracts.

Armed with privileged owner access, the exploiter executed an illegal minting call, generating approximately 5.22 million unbacked WEMIX$ stablecoins out of thin air. The attacker immediately liquidated the fake supply by swapping the unbacked tokens into legitimate assets—primarily native WEMIX and wrapped USDC (USDC.e)—and bridging them across chains before team operations could pause the bridge. Total losses stand at ~$6.25 million.

The Pipeline to Crypto Theft

This exploit highlights the single most catastrophic vector in Web3 infrastructure: Privileged Owner Account / Private Key Compromise.