🟢 Verified 📰 News

A crypto contract got hijacked — why 'who controls it' can matter more than the code

· ✍️ altrookie editorial · 👁️ Read-only

The blockchain network WEMIX says an attacker took control of a contract tied to its WEMIX$ stablecoin and used that con…


The blockchain network WEMIX says an attacker took control of a contract tied to its WEMIX$ stablecoin and used that control to create about 5.23 million tokens out of nothing, then converted them and moved roughly 724,000 US dollars off the network. WEMIX described the figures as preliminary and said the full cause is still under investigation.

According to the company, the newly minted tokens were turned into WEMIX and about 724,000 in a dollar-linked token called USDC.e. That was then bridged to the Ethereum and BNB Smart Chain networks, swapped for assets including Ether and Tether's USDT, and spread across many addresses. Some of the funds ended up on centralized exchanges.

WEMIX said it identified the attacker's wallets and asked exchanges and stablecoin issuers to freeze them, and that some exchanges had already frozen linked addresses. As a precaution it suspended the bridges connecting its network, paused trading in the affected liquidity pools, pulled its own foundation-provided liquidity, and turned off several services while it investigates.

For someone new to crypto, the useful lesson is what actually broke. The attacker did not crack any cryptography or guess anyone's password. They gained control of the special administrative permissions on a contract — the settings that decide who is allowed to issue new tokens. Once you hold that power, you can mint coins that never should have existed.

This is a common shape for crypto losses. A token or app is often controlled by an owner key or an admin role, and if that key is stolen or misconfigured, the math underneath can be perfectly sound while the whole thing is still drained. It is a reminder that when you look at a project, it is worth asking a plain question: who is allowed to change or mint this, and what happens if that access falls into the wrong hands.

Because the investigation is ongoing, the exact amounts and details may change. None of this is advice about any token — it is a look at how one incident happened, so the pattern is easier to recognize next time.