Skip to main content
Sign in

Audit log

Every state-changing event for WEMIX Stablecoin Admin Exploit (July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-29 12:10:20Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    5GQByRLRS38m…EHdfTAHFsha256 → base58
    verifying row…
    canonical bytes (21927 B) ▸
    {"actor":"system:backfill","investigation_id":"aba08fcb-d56b-4a19-893d-d374145adcc1","kind":"publish","page_slug":"wemix-stablecoin-admin-exploit-july-2026","published_at":"2026-07-29T12:10:20.539Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"WEMIX Stablecoin Admin Exploit (July 2026)","sections":[{"content":"On July 26, 2026 at approximately 18:17 KST (09:17 UTC), an unidentified attacker gained administrative or owner-level control over a smart contract governing the WEMIX Dollar (WEMIX$) stablecoin on the WEMIX3.0 mainnet. Using those privileges, the attacker minted approximately 5,225,525 WEMIX$ tokens without corresponding reserve assets — representing roughly $5.22 million at the intended one-dollar peg. The attacker then swapped the minted tokens on a decentralized exchange, obtaining approximately 30,736 WEMIX tokens and 724,198.27 USDC.e. The USDC.e was bridged from the WEMIX3.0 network to Ethereum and BNB Smart Chain, converted into ETH and USDT, and dispersed across multiple wallets including deposits on centralized exchanges. The broader headline damage was estimated at approximately $6.25 million when accounting for both the unauthorized minting and the externally moved assets. WEMIX publicly acknowledged the incident approximately 15 hours after it began, on July 27, 2026.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"WEMIX Hacked Again: $6.25M Stablecoin Exploit Forces Network Shutdown - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/wemix-hacked-again-6-25m-stablecoin-exploit-forces-network-shutdown/"},{"credibility":2,"name":"WEMIX$ Hack Explained: 5.23M Tokens Minted and $724K Moved Across Chains - KuCoin Blog","type":"news_article","url":"https://www.kucoin.com/blog/wemix-dollar-hack-unauthorized-mint-explained"},{"credibility":2,"name":"WEMIX Confirms Admin Privilege Breach Led To $5.2M Abnormal Stablecoin Minting - BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/wemix-admin-breach-stablecoin-issuance/"}]},{"content":"The exploit was not a conventional smart contract code vulnerability but rather a privileged access breach — an attacker seizing owner-level administrative rights over the WEMIX$ contract. Contract ownership in Solidity-based systems typically grants the holder unrestricted ability to call restricted functions, including minting unbacked tokens, which collapsed the stablecoin's reserve-backed trust model in a single transaction. WEMIX stated that 'the cause of the owner-privilege compromise remains under investigation.' The exact mechanism — whether a stolen private key, compromised signing infrastructure, multisignature failure, internal account breach, or an upgrade mechanism exploit — had not been confirmed in public disclosures as of the time of reporting. One contextual factor noted by analysts was that WEMIX had been transitioning from its native WEMIX$ stablecoin to USDC.e on its WEMIX3.0 network beginning around March-April 2026; this migration required rewriting or redeploying contracts, adjusting permissions, and reconfiguring fund flows, which may have introduced new attack surfaces. WEMIX did not publish a full technical post-mortem in the immediate aftermath of the incident.","heading":"Attack Vector and Technical Analysis","severity":"critical","sources":[{"credibility":2,"name":"WEMIX freezes bridges after owner-key breach mints 5.23M WEMIX$ - Crypto.news","type":"news_article","url":"https://crypto.news/wemix-freezes-bridges-after-owner-key-breach-mints-5-23m-wemix/"},{"credibility":2,"name":"WEMIX suspends bridges and trading after $724K breach - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/wemix-suspends-bridges-724k-breach/"},{"credibility":2,"name":"WEMIX$ Hack Explained: 5.23M Tokens Minted and $724K Moved Across Chains - KuCoin Blog","type":"news_article","url":"https://www.kucoin.com/blog/wemix-dollar-hack-unauthorized-mint-explained"}]},{"content":"The confirmed externally moved sum was approximately $724,198.27 in USDC.e, which was bridged from WEMIX3.0 to Ethereum and BNB Smart Chain and converted into ETH, USDT, and other assets before being dispersed across multiple wallets. The 5,225,525 WEMIX$ tokens minted without authorization had a theoretical value of approximately $5.22 million at peg; however, the rapid conversion into liquid assets deflated the market value of the circulating WEMIX$ supply. The 30,736 WEMIX tokens obtained by the attacker carried additional market value. Total damage estimates ranged from approximately $5.2 million (externally realized losses) to $6.25 million (inclusive of the broader unauthorized issuance). Following the incident, Wemixfi's total value locked (TVL) fell by approximately 66% as a direct result of WEMIX's emergency liquidity withdrawal and trading suspension. WEMIX stated it had 'identified the wallets used in the attack' but did not publicly disclose specific wallet addresses or on-chain transaction hashes in the initial disclosure period.","heading":"Funds Lost and Asset Movement","severity":"critical","sources":[{"credibility":2,"name":"WEMIX Suffers $6.25M Smart Contract Exploit, Funds Dispersed Across Chains - KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/wemix-suffers-6-25m-smart-contract-exploit-funds-dispersed-across-chains"},{"credibility":2,"name":"WEMIX Confirms Admin Privilege Breach Led To $5.2M Abnormal Stablecoin Minting - BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/wemix-admin-breach-stablecoin-issuance/"},{"credibility":2,"name":"Korea's First Game-Company Stablecoin Hit by Security Breach - Seoul Economic Daily","type":"news_article","url":"https://en.sedaily.com/finance/2026/07/27/koreas-first-game-company-stablecoin-hit-by-security-breach"}]},{"content":"WEMIX and its parent company Wemade responded to the July 2026 exploit by suspending all WEMIX3.0 bridge functionality (including Chainlink CCIP and PLAY Bridge), freezing affected liquidity pools, halting the WEMIX$ conversion module, disabling the PNIX decentralized exchange, and suspending NFT trading on the platform. The foundation preemptively withdrew its own liquidity from DeFi protocols to limit further exposure. WEMIX contacted global cryptocurrency exchanges and stablecoin issuers requesting asset freezes on wallets linked to the attacker. The company stated it would cooperate with law enforcement if warranted and indicated that additional technical findings would be published as investigators confirmed them. WEMADE also announced a freeze of assets in relation to the incident. As of the initial reporting period, no complete incident post-mortem or confirmed recovery of funds had been publicly disclosed.","heading":"WEMIX and Wemade Response","severity":"high","sources":[{"credibility":2,"name":"WEMIX Hacked Again: $6.25M Stablecoin Exploit Forces Network Shutdown - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/wemix-hacked-again-6-25m-stablecoin-exploit-forces-network-shutdown/"},{"credibility":2,"name":"WEMADE Freezes Assets Following WEMIX Hacking Incident - Inven Global","type":"news_article","url":"https://www.invenglobal.com/articles/24179/wemade-freezes-assets-following-wemix-hacking-incident"},{"credibility":2,"name":"WEMIX Halts Services After Stablecoin Smart Contract Hack - Castle Crypto","type":"news_article","url":"https://castlecrypto.gg/news/wemix-halts-services-after-stablecoin-smart-contract-hack/"}]},{"content":"As of available reporting, no specific individual, group, or nation-state actor had been attributed responsibility for the July 2026 WEMIX exploit. WEMIX stated it had identified attacker-associated wallets but did not publish them. No blockchain forensics firm had publicly linked the wallets to a known threat actor. The attacker's methodology — seizing contract owner privileges and dispersing funds across multiple chains and wallets — is consistent with techniques used by sophisticated DeFi actors including North Korea-affiliated groups such as Lazarus, though no such attribution was made in available sources. The incident remained under active investigation.","heading":"Attribution","severity":"high","sources":[{"credibility":2,"name":"WEMIX freezes bridges after owner-key breach mints 5.23M WEMIX$ - Crypto.news","type":"news_article","url":"https://crypto.news/wemix-freezes-bridges-after-owner-key-breach-mints-5-23m-wemix/"},{"credibility":2,"name":"Wemix Hit by $5.2 Million Hack, Cause Still Unknown 23 Hours Later - Bloomingbit","type":"news_article","url":"https://en.bloomingbit.io/feed/news/117070"}]},{"content":"The July 2026 exploit was the second major security breach for WEMIX in under 18 months. In February 2025, attackers drained approximately 8.65 million WEMIX tokens from the Play Bridge Vault, worth roughly $6.1 to $6.2 million at the time. The root cause was the theft of authentication keys that had been uploaded to a shared developer repository for convenient access. Wemade delayed public disclosure of that incident by approximately four days, claiming it did not initially know the breach vector and feared that a public announcement could trigger follow-on attacks or cause a market crash. This disclosure delay drew regulatory criticism. The two incidents suggest a recurring failure in credential and access-key management across both operational infrastructure and smart contract ownership layers, despite stated remediation efforts following the 2025 breach.","heading":"Prior Security Incidents and Pattern of Breaches","severity":"critical","sources":[{"credibility":2,"name":"Explained: The Wemix Hack (March 2025) - Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-wemix-hack-march-2025"},{"credibility":2,"name":"WEMIX Hacked Again: $6.25M Stablecoin Exploit Forces Network Shutdown - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/wemix-hacked-again-6-25m-stablecoin-exploit-forces-network-shutdown/"},{"credibility":2,"name":"WEMIX Faces Delisting After $6.2M Hack, Regulatory Scrutiny - Ainvest","type":"news_article","url":"https://www.ainvest.com/news/wemix-faces-delisting-6-2m-hack-regulatory-scrutiny-2504/"}]},{"content":"WEMIX has faced significant regulatory consequences in South Korea stemming from its prior breach and disclosure failures. The Digital Asset eXchange Alliance (DAXA) — comprising South Korea's five major exchanges Upbit, Bithumb, Korbit, Coinone, and Gopax — announced in 2025 that it would halt trading of the WEMIX token, effective June 2, 2025. DAXA cited discrepancies between the reported and actual circulation volumes of WEMIX tokens and Wemade's failure to adequately disclose outstanding token counts to enable user due diligence. Wemade challenged the delisting in court; a Seoul court upheld DAXA's decision, stating transparency is necessary in the nascent digital asset industry. The WEMIX token briefly plunged over 60% on the delisting news before partially recovering. The July 2026 stablecoin exploit compounded this credibility damage. The Seoul Economic Daily noted that the incident would likely intensify regulatory scrutiny of smart contract security and internal controls, particularly in the context of South Korean government discussions about institutionalizing a won-based stablecoin.","heading":"Regulatory History and South Korean Market Impact","severity":"high","sources":[{"credibility":2,"name":"WEMIX token plunges as top South Korean exchanges confirm second delisting - Invezz","type":"news_article","url":"https://invezz.com/news/2025/05/02/wemix-token-plunges-as-top-south-korean-exchanges-confirm-second-delisting/"},{"credibility":2,"name":"WEMIX loses delisting battle in court against South Korean exchanges - CoinGeek","type":"news_article","url":"https://coingeek.com/wemix-loses-delisting-battle-in-court-against-south-korean-exchanges-but-promises-to-continue-the-fight/"},{"credibility":2,"name":"Korea's First Game-Company Stablecoin Hit by Security Breach - Seoul Economic Daily","type":"news_article","url":"https://en.sedaily.com/finance/2026/07/27/koreas-first-game-company-stablecoin-hit-by-security-breach"}]},{"content":"The WEMIX exploit occurred during a period of heightened DeFi attack frequency. According to TRM Labs data cited in contemporaneous reporting, the first half of 2026 recorded 207 hacks — the highest six-month period on record and more than double the 83 incidents in H1 2025 — though total financial losses of approximately $972 million were lower than the $2.3 billion stolen in H1 2025, suggesting increasing attack frequency alongside decreasing average breach severity. The WEMIX incident was characterized as a mid-scale breach relative to 2026 incidents. The simultaneous Garden Finance breach, involving approximately $450,000 in USDT drained across multiple blockchains, was reported in the same news cycle as the WEMIX exploit.","heading":"Broader 2026 DeFi Security Context","severity":"medium","sources":[{"credibility":1,"name":"WEMIX and Garden Hacks Add to Record 2026 Crypto Breaches - Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/wemix-garden-hacks-add-record-104654412.html"},{"credibility":2,"name":"Triple-A Hack and WEMIX Exploit Highlight Crypto Security Risks - Coin Edition","type":"news_article","url":"https://coinedition.com/triple-a-hack-and-wemix-exploit-highlight-crypto-security-risks/"}]}],"sources_used":[{"credibility":2,"name":"WEMIX Hacked Again: $6.25M Stablecoin Exploit Forces Network Shutdown - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/wemix-hacked-again-6-25m-stablecoin-exploit-forces-network-shutdown/"},{"credibility":2,"name":"WEMIX$ Hack Explained: 5.23M Tokens Minted and $724K Moved Across Chains - KuCoin Blog","type":"news_article","url":"https://www.kucoin.com/blog/wemix-dollar-hack-unauthorized-mint-explained"},{"credibility":2,"name":"WEMIX Confirms Admin Privilege Breach Led To $5.2M Abnormal Stablecoin Minting - BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/wemix-admin-breach-stablecoin-issuance/"},{"credibility":1,"name":"WEMIX Hit With $724K Stablecoin Security Breach - PYMNTS","type":"news_article","url":"https://www.pymnts.com/cryptocurrency/2026/wemix-hit-with-724k-stablecoin-security-breach/"},{"credibility":2,"name":"WEMIX Suspends Bridges After $724K Stablecoin Contract Exploit - NFT Plazas","type":"news_article","url":"https://nftplazas.com/wemix-suspends-bridges-724k-stablecoin-exploit/"},{"credibility":2,"name":"WEMIX freezes bridges after owner-key breach mints 5.23M WEMIX$ - Crypto.news","type":"news_article","url":"https://crypto.news/wemix-freezes-bridges-after-owner-key-breach-mints-5-23m-wemix/"},{"credibility":2,"name":"WEMIX suspends bridges and trading after $724K breach - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/wemix-suspends-bridges-724k-breach/"},{"credibility":2,"name":"Korea's First Game-Company Stablecoin Hit by Security Breach - Seoul Economic Daily","type":"news_article","url":"https://en.sedaily.com/finance/2026/07/27/koreas-first-game-company-stablecoin-hit-by-security-breach"},{"credibility":2,"name":"Wemix Hit by $5.2 Million Hack, Cause Still Unknown 23 Hours Later - Bloomingbit","type":"news_article","url":"https://en.bloomingbit.io/feed/news/117070"},{"credibility":1,"name":"WEMIX and Garden Hacks Add to Record 2026 Crypto Breaches - Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/wemix-garden-hacks-add-record-104654412.html"},{"credibility":2,"name":"WEMIX Suffers $6.25M Smart Contract Exploit, Funds Dispersed Across Chains - KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/wemix-suffers-6-25m-smart-contract-exploit-funds-dispersed-across-chains"},{"credibility":2,"name":"WEMADE Freezes Assets Following WEMIX Hacking Incident - Inven Global","type":"news_article","url":"https://www.invenglobal.com/articles/24179/wemade-freezes-assets-following-wemix-hacking-incident"},{"credibility":2,"name":"WEMIX Halts Services After Stablecoin Smart Contract Hack - Castle Crypto","type":"news_article","url":"https://castlecrypto.gg/news/wemix-halts-services-after-stablecoin-smart-contract-hack/"},{"credibility":2,"name":"WEMIX token plunges as top South Korean exchanges confirm second delisting - Invezz","type":"news_article","url":"https://invezz.com/news/2025/05/02/wemix-token-plunges-as-top-south-korean-exchanges-confirm-second-delisting/"},{"credibility":2,"name":"WEMIX loses delisting battle in court against South Korean exchanges - CoinGeek","type":"news_article","url":"https://coingeek.com/wemix-loses-delisting-battle-in-court-against-south-korean-exchanges-but-promises-to-continue-the-fight/"},{"credibility":2,"name":"Explained: The Wemix Hack (March 2025) - Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-wemix-hack-march-2025"},{"credibility":2,"name":"WEMIX Faces Delisting After $6.2M Hack, Regulatory Scrutiny - Ainvest","type":"news_article","url":"https://www.ainvest.com/news/wemix-faces-delisting-6-2m-hack-regulatory-scrutiny-2504/"},{"credibility":2,"name":"Triple-A Hack and WEMIX Exploit Highlight Crypto Security Risks - Coin Edition","type":"news_article","url":"https://coinedition.com/triple-a-hack-and-wemix-exploit-highlight-crypto-security-risks/"},{"credibility":2,"name":"WEMIX hit by stablecoin hack, with $724,198 taken - BlockchainGamerBiz","type":"news_article","url":"https://www.blockchaingamer.biz/news/42683/wemix-stablecoin-hack-724198-dollars/"},{"credibility":2,"name":"WEMIX investigates potential security breach of WEMIX$ stablecoin contract - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/wemix-investigates-wemix-dollar-contract-breach/"},{"credibility":2,"name":"Hackers Illegally Mint 5.22 Million WEMIX$ Tokens in Latest Wemix Security Breach - The Elec","type":"news_article","url":"https://www.thelec.net/news/articleView.html?idxno=12570"}],"summary":"On July 26, 2026, an unidentified attacker obtained administrative (owner) privileges over the WEMIX Dollar (WEMIX$) stablecoin smart contract on the WEMIX3.0 network, minting approximately 5.23 million unauthorized tokens worth roughly $5.22 million and moving approximately $724,198 in USDC.e off-chain before WEMIX suspended all bridges and liquidity pools. The incident marked the second major security breach for Wemade's WEMIX blockchain platform in under 18 months, compounding prior regulatory penalties including a June 2025 delisting by South Korea's top five exchanges under DAXA.","timeline":[{"date":"2025-02-28","event":"WEMIX Play Bridge Vault hacked; approximately 8.65 million WEMIX tokens (~$6.1-6.2 million) stolen after authentication keys were compromised via a shared developer repository. Wemade delayed public disclosure by approximately four days.","source":"Halborn / Ainvest","source_url":"https://www.ainvest.com/news/wemix-faces-delisting-6-2m-hack-regulatory-scrutiny-2504/"},{"date":"2025-05-02","event":"DAXA (South Korea's Digital Asset eXchange Alliance) announced the delisting of the WEMIX token from South Korea's five major exchanges, effective June 2, 2025, citing token circulation disclosure failures and the handling of the 2025 hack. WEMIX token briefly fell over 60%.","source":"Invezz","source_url":"https://invezz.com/news/2025/05/02/wemix-token-plunges-as-top-south-korean-exchanges-confirm-second-delisting/"},{"date":"2025-06-02","event":"WEMIX token delisted from Upbit, Bithumb, Korbit, Coinone, and Gopax per DAXA decision.","source":"CoinGeek","source_url":"https://coingeek.com/wemix-loses-delisting-battle-in-court-against-south-korean-exchanges-but-promises-to-continue-the-fight/"},{"date":"2026-03-01","event":"WEMIX began transitioning from its native WEMIX$ stablecoin to USDC.e on its WEMIX3.0 network, requiring contract redeployments and permission reconfigurations that analysts later noted may have introduced new attack surfaces.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/wemix-suspends-bridges-724k-breach/"},{"date":"2026-07-26","event":"At approximately 18:17 KST (09:17 UTC), an unidentified attacker exploited compromised owner-level administrative privileges on the WEMIX$ stablecoin smart contract, minting approximately 5,225,525 unauthorized WEMIX$ tokens (~$5.22 million).","source":"CryptoTimes / KuCoin Blog","source_url":"https://www.cryptotimes.io/2026/07/27/wemix-hacked-again-6-25m-stablecoin-exploit-forces-network-shutdown/"},{"date":"2026-07-26","event":"Attacker swapped minted WEMIX$ for approximately 30,736 WEMIX tokens and 724,198.27 USDC.e on a DEX, then bridged the USDC.e to Ethereum and BNB Smart Chain and dispersed into ETH, USDT, and other assets across multiple wallets.","source":"KuCoin Blog / Crypto.news","source_url":"https://www.kucoin.com/blog/wemix-dollar-hack-unauthorized-mint-explained"},{"date":"2026-07-27","event":"WEMIX publicly disclosed the exploit approximately 15 hours after the incident. The foundation suspended all WEMIX3.0 bridges (Chainlink CCIP and PLAY Bridge), froze affected liquidity pools, halted the PNIX DEX and WEMIX$ conversion module, withdrew foundation liquidity from DeFi protocols, and requested global exchange asset freezes.","source":"WEMIX / BitcoinWorld / CryptoTimes","source_url":"https://bitcoinworld.co.in/wemix-admin-breach-stablecoin-issuance/"},{"date":"2026-07-27","event":"Wemixfi's total value locked (TVL) fell by approximately 66% following emergency liquidity withdrawal and service suspensions.","source":"BitcoinWorld","source_url":"https://bitcoinworld.co.in/wemix-admin-breach-stablecoin-issuance/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 1f3861bd-97af-4b5e-9247-b755e41ed683
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.