On July 26, 2025, at 18:17 KST, an attacker quietly exploited two dormant WEMIX smart contracts. The breach resulted in the unauthorized minting of approximately 5,225,525 WEMIX Dollar tokens – worth roughly 7.7 billion KRW. Furthermore, the attacker drained 723,244 USDC.e in collateral and transferred 34,752 WEMIX coins.
The WEMIX team has since published a detailed post-incident analysis, revealing the root cause, the attack sequence, and the remediation steps taken.
What Caused the WEMIX Exploit?
The breach did not stem from a private key leak or an internal system compromise. Instead, the vulnerability lived inside two aging smart contracts.
The Two Vulnerable Contracts
The first was DIOS, the contract responsible for maintaining the price stability of WEMIX Dollar. The second was AMA, a contract that exchanges collateral assets on a one-to-one basis.
Both contracts had been largely inactive. In fact, the team was already planning to retire them.
The Initialization Function Flaw
Each contract contained an initialization function. This function registers the owner address and is designed to run only once – immediately after deployment.
However, during a November 2022 update, developers changed the call limit from one to two. Critically, they did not re-execute the function itself. As a result, the call counter remained at one, leaving the second invocation open and completely unguarded by any access control check.
How the Attacker Executed the Exploit
The attacker moved methodically. First, they deployed a malicious contract of their own. Then, they called the initialization function a second time, replacing the owner addresses of both DIOS and AMA with their own wallet address.
Gaining Full Owner Privileges
With ownership transferred, the attacker gained the ability to call token minting and swap functions freely. They could also redirect transaction fees and protocol revenue directly to their wallet.
Nine Flash Loan Cycles
To mint the fraudulent tokens, the attacker executed nine rounds of flash loans and swaps between the two contracts. Each cycle generated additional WEMIX Dollar tokens without depositing any genuine collateral.
What Was Stolen?
The attack produced three categories of loss.
First, the unauthorized minting created approximately 7.7 billion KRW worth of WEMIX Dollar tokens. Second, the attacker withdrew 723,244 USDC.e – the stablecoin serving as collateral backing for WEMIX Dollar – valued at roughly 1 billion KRW. Third, 34,752 standard WEMIX coins were transferred out separately.
Additionally, the team identified potential links between certain gaming tokens and WEMIX Dollar, and is continuing to analyze the associated transactions.
How WEMIX Responded
The response was swift once the incident was detected.
Immediate Containment
The team identified the attacker’s wallet address and contacted the exchanges where stolen funds were sent, requesting those addresses be blocked. They also revoked minting privileges to prevent any further token issuance.
Protocol Shutdowns
Several protocol components were temporarily suspended. These included the WEMIX Dollar liquidity pools, the Chainlink CCIP bridge, the internal PLAY Bridge, and the PNIX DEX exchange.
Law Enforcement Action
Wemade filed an official report with law enforcement on July 28 and is actively cooperating with the ongoing investigation.
Lessons for Smart Contract Developers
This incident illustrates a subtle but dangerous class of vulnerability. Moreover, it demonstrates how legacy code – even code that appears dormant – can harbor critical flaws.
Developers should enforce strict single-execution constraints on all initialization functions. Equally important, they must audit access control logic after every contract upgrade. A change to call limits without re-examining permission checks is precisely the kind of gap attackers exploit.
Finally, contracts that are no longer in active use should be formally deprecated and deactivated – not merely ignored.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.