The WEMIX Attacker Minted $5.2M. Only $724K Could Leave the Chain.

Headlines put the WEMIX breach at 6.25 million dollars. On-chain, 724,198 USDC.e left, capped by a stablecoin its own issuer had already retired.

Ramy Morton Analysis

Three numbers went out with the WEMIX story over the weekend, and all three describe the same on-chain event. The Crypto Times and AMBCrypto led with $6.25 million. Bloomingbit called it $5.2 million. Cryptobriefing and BlockchainGamer ran $724,000. None of them is careless. They are measuring three different quantities, and only the smallest one describes money that left the chain.

The attacker took control of owner privileges on the WEMIX$ stablecoin contract at 09:17 UTC on July 26, which was 18:17 in Seoul. After that the mint was unlimited. Wemade's own accounting, carried by crypto.news and AMBCrypto, puts the unauthorized issuance at 5,225,525 WEMIX$. Against a dollar peg that reads as $5.22 million of face value. The $6.25 million figure came from an early valuation of the abnormal issuance, taken before anyone traced the exit trades.

The wallets moved about $731,000 of it

Two outflows are confirmed by crypto.news and AMBCrypto independently, and they match to the cent: 724,198.27 USDC.e and 30,736 WEMIX. Price the WEMIX leg at the $0.2294 CoinMarketCap was showing on Monday and the pair comes to roughly $731,000. The attacker bridged the USDC.e to Ethereum and BNB Smart Chain, swapping parts of it into ETH and USDT on the way.

So a mint with $5.22 million of nominal value produced about 14 percent of that in recoverable assets. The other 86 percent stayed stranded on WEMIX3.0 as tokens nobody would price at a dollar. WEMIX$ ended the week down around 98.9 percent by crypto.news's reading, which is what happens to a dollar-pegged asset when someone prints five million of it into a pool that cannot absorb five million.

That constraint is the part worth sitting with. The contract let the attacker mint without limit. The chain did not let him sell without limit, and the reason has a date attached.

Wemade drained those pools itself, 111 days earlier

On March 5, 2026, WEMIX published a transition plan moving the WEMIX3.0 network off WEMIX$ and onto USDC.e, Circle's bridged dollar running over Chainlink CCIP. New deposits into WEMIX$ pools stopped that day. Foundation liquidity started coming out at 06:00 UTC on April 6, taking the WEMIX and WEMIX$ pair, the WCD pair, and seven further pools on WEMIX PLAY with it. From April 6, USDC.e became the base currency for GameFi services across the platform, and WEMIX$ payments were restricted.

111 days later the attacker arrived at a stablecoin whose liquidity had been deliberately withdrawn by its own issuer. The retirement schedule capped the theft. Read the same fact from the other side and it gets uncomfortable: WEMIX had finished decommissioning WEMIX$ as a payment rail in April, then left the contract's owner key live and mint-capable into the last week of July. Cryptobriefing noted the stablecoin was already on a sunset track. Nobody appears to have asked what the mint function was still doing awake.

February 2025 ran the opposite way

Wemade has been here before, and the comparison sharpens what changed. In February 2025 attackers used compromised authentication keys tied to the NILE NFT monitoring system to drain roughly 8.65 million WEMIX through the Play Bridge, worth $6.1 million to $6.2 million at the time. Those were circulating tokens taken from a bridge. Real supply, real holders behind it.

MeasurePlay Bridge, February 2025WEMIX$ contract, July 2026
Entry pointCompromised auth keys, NILE monitoring systemOwner privileges on the WEMIX$ contract
Headline figure8.65 million WEMIX, $6.1M to $6.2M5,225,525 WEMIX$, reported at $724K to $6.25M
What actually left8.65 million circulating WEMIX724,198.27 USDC.e and 30,736 WEMIX
Source of the fundsExisting token supplySupply created during the attack
DisclosureDelayed, later defended as panic controlSame evening, four to seven hours

The disclosure gap is the honest improvement. Bloomingbit's timeline has Wemade acknowledging the breach about four hours after minting began; BlockchainGamer logs the public confirmation at 16:30 UTC, closer to seven. The Block reported last year that Wemade delayed disclosing the $6.2 million bridge hack and later defended the delay as an attempt to prevent panic. This time the network went dark fast. Bridges, DEX pairs including WEMIX with USDC.e, the WEMIX$ Module, PNIX DEX and the NFT marketplace were all suspended by 01:20 UTC on July 27, with contract audits running.

What the market did with it

Almost nothing, which is its own data point. WEMIX was trading at $0.2294 on Monday, down 1.68 percent on the day, on $1.59 million of volume against a $114 million market cap. A token that loses under two percent after its stablecoin contract is minted into oblivion is a token whose holders have already priced in a certain amount of this. WEMIX cleared its second halving on July 1 and picked up a Kraken spot listing on July 8, so the past month had given the market better things to look at.

What the headline figure obscures matters beyond one Korean gaming chain. A mint exploit and a drain exploit are not the same loss, and reporting both at face value trains readers to compare numbers that were never comparable. The gap between a stated liability and a realized one shows up everywhere in this market, from the $163.7 million Poolin owes against a $52 million opening bid to the collateral claims behind any dollar-pegged token that has never been tested at scale.

Wemade has not said how the owner key was compromised. Twenty-three hours after the attack the company still had no answer on that, per Bloomingbit, which is the same unresolved question that followed the THORChain validator drain in May. Holders of stranded WEMIX$ have until March 5, 2027 to withdraw from the discontinued pools under the original transition notice, assuming the module comes back online. That deadline is now the number to watch, and it is the one nobody has written about yet.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.
Ramy Morton
Author

Ramy Morton

Ramy Morton is Coinliva's Markets & On-Chain Analyst. He covers crypto markets with a focus on price action, ETF flows, derivatives positioning, stablecoin movements, and exchange reserves. His analysis is built on primary data sources including Glassnode, CryptoQuant, Coinglass, and ETF issuer disclosures.