Wemix Hack
What happened
On 28 February 2025 attackers drained about 8.65 million WEMIX (roughly $6.2 million) from the WEMIX Foundation's Play Bridge Vault, the service that moves WEMIX to other networks. They got in with a stolen authentication key for the service monitoring system of NILE, WEMIX's NFT platform, and prepared for about two months before sending abnormal withdrawal transactions. Of 15 withdrawal attempts, 13 succeeded, and the tokens were sold on exchanges outside South Korea.
The foundation shut down the affected servers and filed a complaint with the Seoul police cyber investigation unit on the day of the attack, but only disclosed the hack on 3-4 March. CEO Kim Seok-hwan denied a cover-up and said an early announcement risked further attacks and market panic. WEMIX fell from about $0.70 on 27 February to $0.42 on 4 March. No recovery of the stolen tokens was reported.
How it happened
- The attackers stole an authentication key for the service monitoring system of NILE, WEMIX's NFT platform. Halborn reports that a developer had allegedly uploaded the credentials to a shared repository.
- They spent about two months preparing inside the system.
- On 28 February 2025 they created abnormal withdrawal transactions from the Play Bridge Vault: 15 attempts, 13 of which succeeded, taking about 8.65 million WEMIX.
- The stolen WEMIX was sold on exchanges outside South Korea.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis Wemix denies cover-up amid delayed $6.2M bridge hack announcement cointelegraph.com
- analysis WEMIX suffered a hacker attack at the end of February panews.io
- analysis Explained: The Wemix Hack (March 2025) halborn.com
- analysis Wemix Foundation bridge hacked for $6.2 million web3isgoinggreat.com
- analysis wemix.com page wemix.com wemix.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.