Back to news
NewsMarkets

We Decoded the WEMIX$ Exploit On-Chain: the Attacker Wallets Nobody Published, a Doubling Mint Loop, and Where the Money Went

Tony Rabbit 2 days ago 148 views 0 shares
We Decoded the WEMIX$ Exploit On-Chain: the Attacker Wallets Nobody Published, a Doubling Mint Loop, and Where the Money Went

When WEMIX, the blockchain arm of Korean gaming giant Wemade, said on July 27 that its dollar-pegged stablecoin WEMIX$ had been exploited and froze every bridge on its network, the coverage stopped at the press release: an owner-key compromise, roughly 5.23 million WEMIX$ minted, about $724,000 gone. Nobody published the receipts. So we opened the WEMIX3.0 chain ourselves and decoded the attack transaction. Here are the attacker addresses, the exact mechanics, and where the value actually landed.

The entire exploit is one transaction, 0xfed2172a...fe7cefe0, mined at 09:17 UTC on July 26 in block 118,823,631. Reading its logs, the minting was not a single call. It was a doubling loop of nine separate mint events, 5.25M, then 2.62M, then 1.31M, halving all the way down, every one landing in the same wallet. Summed, the transaction printed 10.47 million WEMIX$ from nothing, roughly double the 5.23 million figure that made the headlines.

The mint loop, decoded

WEMIX$ exploit: nine halving mint events totalling 10.47M tokens in one transaction
The nine Transfer-from-zero (mint) events inside the exploit transaction, each half the previous one, summing to 10.47M WEMIX$. Decoded on-chain by DEXTools News.

The wallets nobody named

Reading the transaction's sender, its internal calls and the token transfers, three addresses define the attack. We give each an alias, its address and its role, the way we build every forensic file so the trail can be followed and, if it comes to it, cited.

AliasAddressRole
SIGNER0xc921a66e30745f11f8c7a7870e95640607ae7ea2The EOA that signed and paid for the exploit transaction; received the swapped proceeds
ROUTER0xb6bdea4941f6fd4ea3918fac902494da100ac4d2The contract SIGNER called to orchestrate the mint and the swaps
VAULT0xd2947dbfdbdbb99702de6e46c63cb1968e21d95bThe address that received all 10.47M freshly minted WEMIX$
WEMIX$ token0x8e81fcc2d4a3baa0ee9044e0d7e36f59c9bba9c1The stablecoin contract whose owner privilege was abused

Where the money actually went

Minting 10 million units of a thin stablecoin is worthless unless you can turn it into something real before the price collapses. That is exactly what the loop was for. The freshly minted WEMIX$ was dumped through WEMIX3.0's own liquidity pools, and reading the token transfers back to the SIGNER address, we can confirm the payout: about 723,294 USDC.e reached the attacker, alongside a large amount of wrapped WEMIX. That USDC.e figure lines up almost exactly with the roughly $724,000 the foundation reported as stolen, and it is the number we can stand behind because we read it off the chain.

What the chain showsFigure
WEMIX$ minted in the exploit tx (nine events)10.47M
USDC.e that reached the attacker (verified)~723,294
Attacker EOA native WEMIX balance now0
Exploit block / time118,823,631 / 09:17 UTC Jul 26

The SIGNER wallet now holds no native WEMIX at all, consistent with the funds having already been moved out toward exchanges and bridges before WEMIX pulled the plug. The foundation says some funds were deposited at centralized exchanges, that it has asked those exchanges and stablecoin issuers to freeze the addresses, and that some have already complied. Those freeze claims are the foundation's; the mint, the wallets and the USDC.e payout are ours, read directly from WEMIX3.0.

Why the bridges went dark

WEMIX's response was drastic: it suspended every bridge connecting to and from WEMIX3.0, including the recently integrated Chainlink CCIP and its own PLAY Bridge. The logic is defensive. A stablecoin whose owner key can mint unlimited supply is a machine for exporting fake value, and bridges are the export route. Freezing them traps whatever the attacker has not already moved and stops counterfeit WEMIX$ from being carried onto Ethereum or BNB Chain, where deeper liquidity would let it be laundered faster. It is a blunt instrument, and shutting your own network is an admission of how serious an owner-key compromise is.

The second breach in 18 months

This is not WEMIX's first incident. The project suffered a separate exploit little more than a year ago, and a repeat, this time striking the stablecoin at the contract-ownership level rather than a peripheral service, is the kind of pattern that erodes trust in a chain built to sit under commercial games with millions of players. The mechanism matters here: this was not a clever flaw in the token's math but control of the privileged owner account, which points at key management rather than code as the failure.

The bottom line

The headline said 5.23 million WEMIX$ and $724,000. The chain says the exploit transaction minted 10.47 million WEMIX$ in a halving loop and paid the attacker about 723,294 USDC.e, out of three addresses that no outlet had published. The stolen value is real and modest by DeFi standards, but the story is the mechanism: an owner key that could conjure a stablecoin from nothing, and a network that had to switch off its own bridges to contain it.

Data note. DEXTools News decoded transaction 0xfed2172a508d84f63b56acc7e3c30164930220004f808799998b8201fe7cefe0 directly from the WEMIX3.0 public RPC on July 27, 2026: the nine Transfer-from-zero mint events (summing to 10.47M WEMIX$), the three attacker-linked addresses, and the ~723,294 USDC.e received by the signer. The roughly 5.23M minted figure, the ~$724,000 loss, the $6.25M network-loss estimate and the bridge-freeze and exchange-freeze actions reflect WEMIX Foundation statements and public reporting. Address labels are our analytical aliases. This is information, not financial advice.

Frequently asked questions

How much was minted in the WEMIX$ exploit?

WEMIX and outlets reported about 5.23 million WEMIX$ minted. Decoding the exploit transaction on WEMIX3.0, DEXTools News found nine separate Transfer-from-zero mint events in a doubling loop (5.25M, 2.62M, 1.31M and so on) that sum to 10.47 million WEMIX$, roughly double the headline figure, all landing in one wallet.

What are the WEMIX exploiter wallet addresses?

Three addresses define the attack: the signer EOA 0xc921a66e30745f11f8c7a7870e95640607ae7ea2 that paid for and received proceeds, the orchestrating contract 0xb6bdea4941f6fd4ea3918fac902494da100ac4d2, and 0xd2947dbfdbdbb99702de6e46c63cb1968e21d95b, which received all the minted WEMIX$. The abused token contract is 0x8e81fcc2d4a3baa0ee9044e0d7e36f59c9bba9c1.

How much was actually stolen from WEMIX?

The minted WEMIX$ was dumped through WEMIX3.0 liquidity pools. Reading the transfers back to the attacker, about 723,294 USDC.e reached the signer wallet, which matches the roughly $724,000 the WEMIX Foundation reported as stolen. WEMIX also cited a $6.25M network-loss estimate.

Why did WEMIX freeze its bridges?

WEMIX suspended every bridge to and from WEMIX3.0, including Chainlink CCIP and its PLAY Bridge, to trap funds the attacker had not yet moved and to stop counterfeit WEMIX$ from being carried onto Ethereum or BNB Chain, where deeper liquidity would speed up laundering. The exploit was an owner-key (privileged account) compromise, not a flaw in the token math.

Related reading