
[Updated July 27, 2026, 22:30 UTC: Included comments from a WEMIX spokesperson.]
Layer-1 blockchain community WEMIX mentioned an attacker moved about 724,000 in USDC.e tokens after compromising possession of a contract linked to its WEMIX$ stablecoin and issuing tokens with out authorization.
The irregular transactions occurred on Sunday at 9:17 UTC, based on a preliminary incident replace from WEMIX. The attacker issued about 5.23 million WEMIX$, which was transformed into 30,736 WEMIX and 724,198.27 USDC.e. The USDC.e was then bridged to Ethereum and BNB Good Chain earlier than being exchanged for property together with Ether and Tether’s USDT and distributed throughout a number of addresses.
WEMIX mentioned a few of the funds had been deposited into centralized exchanges. The corporate recognized the attacker’s wallets and requested asset freezes and help from exchanges and stablecoin issuers, including that some exchanges had already frozen addresses linked to the incident.
The corporate quickly suspended all bridges related to its layer-1 community, WEMIX3.0, together with Chainlink CCIP and the PLAY Bridge. It additionally suspended buying and selling in affected liquidity swimming pools, withdrew foundation-provided liquidity, and paused providers together with the WEMIX$ Module and PNIX decentralized trade.
A WEMIX spokesperson advised Cointelegraph that the incident stays below inside investigation and that additional updates might be offered when accessible.
The spokesperson mentioned WEMIX had recognized the attacker’s wallets and fund actions and was actively monitoring the property, and requests for freezes and cooperation had been submitted to related exchanges and stablecoin issuers.
“Consequently, a portion of the externally transferred property has been frozen,” the spokesperson advised Cointelegraph, including that no user-owned property had been affected.
Associated: DeFi TVL drops 39% in 2026 amid market downturn and document hack exercise