Wemade’s WEMIX Dollar (WEMIX$), the first dollar-pegged stablecoin issued by a Korean game company, has suffered a hacking incident in which roughly 8 billion won worth of tokens were minted without authorization. The administrative rights to the stablecoin-related contract were found to have been seized, once again putting the security risks of privately issued stablecoins under scrutiny.
According to Wemade on the 27th, at around 6:17 p.m. the previous day, the administrative rights to the WEMIX Dollar-related contract were seized, and a total of $5.22 million (about 7.6 billion won) worth of WEMIX Dollar was minted without authorization. WEMIX Dollar is a stablecoin issued and operated by WEMIX PTE. LTD., Wemade’s Singapore corporation, with the goal of maintaining a one-to-one value peg with the U.S. dollar.
The attacker exchanged the illicitly minted WEMIX Dollar for 30,736 WEMIX and 724,198 USDC.e on a decentralized exchange. USDC.e is a stablecoin created to allow the dollar stablecoin USD Coin (USDC) to be moved and used on other blockchains.
The attacker then moved the acquired USDC.e to Ethereum and BNB Chain through a bridge, converted it into assets such as Ethereum (ETH) and Tether (USDT), and dispersed the funds to multiple wallets. Some assets were found to have flowed into centralized exchanges. Based on the assets the attacker actually siphoned externally, the scale of the damage is estimated so far at about $720,000 (about 1 billion won).
Wemade said that immediately after confirming the abnormal transactions, it halted operation of the relevant bridge and the WEMIX Dollar module and recovered all liquidity from its liquidity pools. It also explained that it had requested domestic and overseas cryptocurrency exchanges and stablecoin issuers to freeze the attacker’s wallets and related assets, and that it is currently tracking the movement of the funds. “Additional unauthorized issuance of WEMIX Dollar is currently impossible,” a Wemade official said.
Analysts say this incident carries significant repercussions because, unlike typical hacks in which a user wallet’s private key is stolen, the contract rights controlling stablecoin issuance were attacked. This is because an attacker who secures issuance rights can mint tokens in large quantities regardless of the actual reserve assets. The point being made is that not only the stability of reserve assets, but also the smart contracts managing issuance rights and internal control systems, determine trust in a stablecoin.
WEMIX Dollar has repeatedly been mired in stability controversies, having experienced several instances of depegging, in which its dollar-linked price wavered. As a stablecoin that should maintain a one-to-one value with the dollar fell below its target price, questions have been raised about the soundness of its reserve assets and its redemption structure. With the issuance rights seizure incident now added, further damage to WEMIX Dollar’s credibility appears inevitable.
This is not the first time a large-scale security incident has occurred in the WEMIX ecosystem. Previously, WEMIX had about 9 billion won worth of WEMIX stolen through a bridge hack last year. At the time, the fact that the hack was disclosed to the outside belatedly also became a problem, leading the Digital Asset eXchange Alliance (DAXA), a joint consultative body of Korea’s digital asset exchanges, to terminate trading support for WEMIX.
Industry observers believe this incident will also affect discussions on institutionalizing a won-based stablecoin, which the government and the National Assembly are pursuing. It is expected that calls will grow for the institutionalization process to verify not only the stability of reserve assets, but also the security of the smart contracts managing issuance and burning rights and the internal control systems of issuers.
An official in the blockchain industry pointed out, “Since assets can move to other blockchains within a short time through bridges and decentralized exchanges, an industry-wide joint response system that can freeze and recover related assets immediately after an incident is also needed.”
Click Here For The Original Source
