Loading IndicatorLoading Indicator

Wemix Hit by $5.2 Million Hack, Cause Still Unknown 23 Hours Later

Source
Korea Economic Daily

Summary

  • Wemade said the WEMIX ecosystem suffered a hack worth about $5.2 million and a compromise of administrator privileges.
  • Wemade said it is tracking the unauthorized minting of WEMIX$ and the movement of funds, while asking global cryptocurrency exchanges to freeze related assets.
  • The renewed security breach could add pressure to a relisting on domestic exchanges, efforts to restore confidence in the WEMIX ecosystem, and the sustainability of its blockchain business.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator

A hack worth about $5.2 million hit Wemade’s WEMIX ecosystem, and the company still had not determined how administrator privileges were compromised as of 5 p.m. on July 27, about 23 hours after the attack. The breach comes about a year after WEMIX was delisted from South Korean exchanges following an earlier hack and criticism over a delayed disclosure, putting Wemade’s response system back under scrutiny.

Source: WEMIX website notice
Source: WEMIX website notice

The incident occurred at about 6:17 p.m. on July 26, Wemade said on July 27. An initial investigation found that administrator privileges for the smart contract tied to WEMIX$, the ecosystem’s stablecoin, had been compromised. WEMIX later posted another notice saying it would provide follow-up findings, but did not explain how the administrator account was breached.

On-chain analyst Spector first disclosed the suspicious transactions. WEMIX formally acknowledged the security incident on its website at about 10 p.m. on July 26, roughly four hours after the transactions were flagged.

The attacker used the stolen privileges to mint about 5,225,525 WEMIX$ without authorization, worth about $5.2 million. The company’s investigation found that some of the illicitly minted tokens were swapped into WEMIX and USDC.e, transferred to Ethereum and BNB Chain, and dispersed across multiple wallets.

Wemade is tracking the attacker’s wallets and the movement of funds. It also asked global cryptocurrency exchanges and stablecoin issuers to freeze the related assets. To prevent further damage, the company halted the bridge linking WEMIX 3.0 with external blockchains. It also temporarily restricted blockchain and non-fungible token functions for its decentralized exchange, liquidity pools and some games.

WEMIX was also hacked in February 2025, when about 8.65 million WEMIX tokens were abnormally withdrawn from the Play Bridge Vault. Damage at the time was estimated at about $6.1 million. WEMIX was later delisted from domestic won-denominated exchanges in June 2025 after the company drew criticism for disclosing the incident about four days later.

Wemade has said it replaced authentication keys, overhauled security systems and underwent reviews by outside specialist firms after the earlier incident. But with core administrator privileges compromised again about a year later, questions are resurfacing over whether those security measures worked.

The latest incident could also hurt WEMIX’s push to relist on domestic exchanges. The large-scale breach comes as Chairman Park Kwan-ho seeks to sell management control, adding pressure to restore confidence in the WEMIX ecosystem and raising fresh questions about the sustainability of the company’s blockchain business.

A Wemade official said the company took initial steps immediately after detecting abnormal transactions to prevent the damage from spreading. The investigation is continuing, and any additional findings will be announced in a follow-up notice, the official added.

Yoo Ji-hee, Hankyung.com reporter keephee@hankyung.com

#Hacking
Korea Economic Daily

Korea Economic Daily

hankyung@bloomingbit.ioThe Korea Economic Daily Global is a digital media where latest news on Korean companies, industries, and financial markets.

What do you think about this news?








PiCK News






Hashtag News