WEMIX Details WEMIX$ Incident After Attackers Leveraged Public Smart Contract Flaw
AI Market Summary
WEMIX disclosed a WEMIX$ smart-contract exploit where attackers seized ownership of two public contracts (DIOS and AMA) and used flash loans/swaps to mint ~5.23M WEMIX$ without compromising internal systems or admin keys. The incident highlights onchain contract-risk and governance attack surfaces, likely weighing on confidence in similar stablecoin-like designs and DeFi protocols reliant on upgradeable contracts in the near term.
Impact level
● Medium
Affected assets
BTC/USDT+0.80%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
PANews, July 30 — WEMIX published an updated post-incident review of the WEMIX$ security event, outlining the root cause and response measures. The company said that on July 26 the ownership of two smart contracts was transferred to an unauthorized third party. The impacted contracts were DIOS, which is designed to support WEMIX$ price stability, and AMA, which enables 1:1 redemption of WEMIX$ for collateral assets.
According to WEMIX, the attacker used a single transaction to deploy a malicious contract, seized control of both DIOS and AMA, then carried out nine rounds of flash-loan and swap operations. The activity led to the unauthorized minting of 5,225,524.9997 WEMIX$.
WEMIX said the incident was not caused by a compromise of its internal systems or a leak of administrator private keys. Instead, the attacker exploited vulnerabilities in publicly accessible onchain smart contracts.