WEMIX$ Contract Authority Compromise
What happened
On July 26, 2026, compromised authority over a WEMIX$-related contract enabled unauthorized minting. WEMIX reported that 5,225,525 WEMIX$ was converted into 30,736 WEMIX and 724,198.27 USDC.e. The approximately $737,000 loss estimate represents extracted assets; nominal minted tokens are not an additional loss.
Compromised contract authority enabled unauthorized WEMIX$ issuance. The initial compromise mechanism is not established by the cited project notice.
Case & protocol details
How it happened
WEMIX confirmed unauthorized use of contract-owner authority, minting, swaps and outward transfers. It paused bridges and affected services and requested asset freezes. The initial entry point remained under investigation in the cited notice; the evidence does not establish whether a leaked key or another mechanism enabled the compromise.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- analysis WEMIX: preliminary impact and response measures wemix.com
- analysis Website reference x.com
- analysis Website reference x.com
- analysis WEMIX$ Security Incident Findings and Response Update wemix.com
- analysis WEMIX says attacker moved about $724K after contract breach cointelegraph.com
- analysis DeFiLlama: $737,000 WEMIX.FI Lend estimate defillama.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.