Two Hacks, One Delisting, $724K Stolen: WEMIX Isn’t Just Bad Luck – It’s Negligence
(SeaPRwire) –
By: Lucas Caldwell
Most blockchain gaming projects brush off one hack as bad luck. They fix the gap, rebuild trust, and work their way back to credibility. WEMIX just pulled off a second major hack in under two years, right when it was gearing up to beg for relisting on South Korea’s top exchanges. This isn’t a case of a sophisticated unknown exploit breaking through cutting edge defenses. This is repeated, basic failure to secure core contract privileges that should have been locked down years ago.
On July 26, 2026, an attacker gained full owner-level control of WEMIX$’s stablecoin contract at 9:17 UTC. They minted 5.23 million unauthorized WEMIX$ tokens, then converted the stash into 30,736 WEMIX and 724,198 USDC.e. The attacker bridged the USDC.e to Ethereum and BNB Smart Chain, swapped portions into ETH and USDT, and spread the funds across multiple separate wallets. WEMIX confirmed the hack publicly after the attacker already completed most of the conversion.
In response, WEMIX suspended all bridges connected to its WEMIX3.0 network. That includes Chainlink CCIP and the PLAY Bridge, the same tool that was exploited for a $6 million hack in 2025. It also paused all affected liquidity pools, withdrew foundation liquidity, and shut down the WEMIX$ Module and PNIX decentralized exchange. The company asked major exchanges to freeze attacker-linked addresses, and several complied. WEMIX has not named the exchanges or disclosed how much funds have been recovered so far.
This hack hits at the worst possible time for WEMIX. Back in 2025, after the first $6 million hack, all major South Korean exchanges including Upbit, Bithumb, Coinone, Korbit, and Gopax delisted the token. WEMIX was just approaching the eligibility window to reapply for relisting, which would have unlocked access to its core domestic user base. The project was already in the middle of phasing out WEMIX$ to replace it with USDC.e across all its gaming and financial services. The transition was announced in March and scheduled to launch in April, before this breach.
CoinGecko data shows WEMIX$ dropped 98.9% in a week after the hack, falling to near its all-time recorded low. WEMIX still has not released a full public report on the breach. It has not named the source of the compromised owner credentials, nor confirmed the total amount of unrecovered stolen funds. This matches the pattern from the 2025 hack, when WEMIX waited days to disclose the breach to the public, eroding trust long before the coordinated delisting.
WEMIX will never get relisted on any major South Korean exchange after this second avoidable security failure.
Author bio: Lucas Caldwell, a crypto security analyst and tech opinion leader with millions of followers on X/Twitter.