USDT live
Supply 112.4B +0.8%
Tron share 53.2%
ETH share 38.4%
TRC20 gas $0.95 -2.1%
ERC20 gas $4.20
24h volume $48.2B
English · 中文

WEMIX Ecosystem Stablecoin Unauthorized Minting, ~¥1B Drained: What This Means for the ₮ Card in Your Wallet

2026-07-27

South Korea’s blockchain gaming platform WEMIX has suffered an unauthorized minting incident involving its proprietary stablecoin: the owner (admin) privileges of the smart contract were seized, and the attacker minted additional tokens under admin authority and cashed them out, for a total of roughly ¥1 billion (at a rough rate of $1 ≈ ¥150, that’s on the order of $6.5 million). WEMIX has published information on its response to the incident, which was reported by CoinPost (original article in Japanese, published July 27, 2026). This is not a depeg caused by insufficient reserves, nor a cross-chain bridge exploit — the problem lies in the permission design of the issuance contract itself: who can call mint, and how many people hold that key.

Editorial take: what’s affected isn’t USDT, it’s the deposit channel that “accepts anything”

Let’s state the conclusion up front: this incident will not affect USDT’s redemption, nor will it affect any virtual card balance settled in USDT/USDC. WEMIX’s ecosystem stablecoin and Tether are two entirely separate issuance systems — the seizure of contract permissions on the former does not propagate to the latter’s reserves (Tether’s reserve disclosures can be found on its transparency page).

What actually deserves attention is the deposit side. Mainstream U-cards currently fall into two categories:

Reasonable expectations for the time windows ahead: within 7 days, exchanges are likely to issue trading risk warnings for the affected token, suspend deposits/withdrawals, or adjust margin parameters; within 30 days, if the fraudulently minted tokens are confirmed to have flowed into CEXs, regional delistings or investment-warning tags may appear; within 90 days, South Korea is likely to revisit disclosure requirements and reserve standards for “proprietary stablecoins within gaming ecosystems.” Readers holding cards settled solely in USDT don’t need to take any action during any of these three windows.

Historical comparison: same country, same structural weakness of “in-ecosystem proprietary stablecoins”

Three prior cases are worth comparing, with both similarities and differences clearly visible:

  1. The 2022 Terra/UST collapse: also a Korean team, also an “in-ecosystem proprietary stablecoin.” The similarity is the narrative structure — the token’s value was propped up by ecosystem activity rather than external reserves. The difference is the collapse mechanism: UST self-destructed via an algorithmic mechanism under a run, whereas this WEMIX incident is a failure of contract permission governance, an engineering and key-management problem that is, in theory, fixable and traceable.
  2. WEMIX’s delisting from South Korea’s DAXA exchange alliance in late 2022 (the controversy at the time centered on circulating-supply disclosure not matching actual figures). The sensitivity of this current incident is amplified by that history: the same issuer running into a second supply-credibility problem will meet noticeably lower market tolerance.
  3. The brief USDC depeg in March 2023 (the Silicon Valley Bank incident). That case involved a problem at the reserve custodian while the stablecoin contract itself remained intact; this case is the opposite — the reserve narrative wasn’t in question, but the contract itself was breached. These two risk types require two different defenses: for the former, check reserve disclosures; for the latter, check whether mint permissions require multi-signature, whether there’s a timelock, and whether the owner is an EOA.

The takeaway for U-card users is direct: judging whether a stablecoin “can be treated as spendable balance” requires looking beyond reserves to whether its issuance contract is managed by a single key.

Compliance boundaries: no unified answer across Asia-Pacific, but disclosure obligations are tightening

Since South Korea’s Virtual Asset User Protection Act took effect, exchanges have had clear reporting and delisting obligations for abnormal token issuance and supply discrepancies — which is why South Korean exchanges are likely to respond faster than other regions following this incident. In Japan, stablecoins fall under the existing regulatory framework for funds transfer services / electronic payment instruments, with stricter pre-listing review for third-party stablecoins — see our Japan compliance guide for details. If you hold and spend cards in Singapore or Hong Kong, the sections on stablecoin issuer qualifications in our Singapore compliance guide and Hong Kong compliance guide are worth comparing as well.

The current gray zone is this: a “proprietary stablecoin issued by a gaming platform for in-ecosystem settlement” is, in most Asia-Pacific jurisdictions, neither explicitly banned nor granted the status of a regulated stablecoin. It’s closer to a high-risk token, yet is often marketed under the label “stablecoin.” What’s explicitly permitted is licensed issuance with segregated, audited reserves; what’s explicitly banned is unlicensed public issuance of tokens with payment functions. WEMIX-type tokens fall in between — which is exactly why it was able to maintain a loosely designed contract permission structure for so long without triggering regulatory intervention.

Four things worth watching next

Editorial recommendations