WEMIX Security Incident: Attackers Exploit Public Smart Contract Vulnerability

iconPANews
Share
AI summary iconSummary
WEMIX disclosed a security incident involving its WEMIX$ token, triggered by a vulnerability in a public smart contract. On July 26, attackers gained control of two smart contracts—DIOS and AMA—and deployed a malicious contract in a single transaction. They executed nine rounds of flash loans and swaps, illegally minting 5,225,524.9997 WEMIX$. The incident underscores the importance of contract security and did not involve a compromise of WEMIX’s internal systems or private keys.

PANews, July 30: WEMIX has released an analysis of the cause and updated response to the WEMIX$ security incident. On July 26, ownership of two smart contracts was transferred to an unauthorized third party. The affected contracts were DIOS, designed to maintain the price stability of WEMIX$, and AMA, intended to enable 1:1 redemption of WEMIX$ for collateral assets. The attacker deployed a malicious contract in a single transaction, gained control over both contracts, and executed nine rounds of flash loans and swap transactions, resulting in the unauthorized minting of 5,225,524.9997 WEMIX$. This incident did not involve a breach of WEMIX’s internal systems or leakage of administrator private keys, but rather exploited vulnerabilities in publicly accessible on-chain smart contracts.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.