USDT live
Supply 112.4B +0.8%
Tron share 53.2%
ETH share 38.4%
TRC20 gas $0.95 -2.1%
ERC20 gas $4.20
24h volume $48.2B
English · 中文

WEMIX Dollar Stablecoin Suffers Illegal Minting: Admin Control Hijacked, Three Things U-Card Users Should Watch

2026-07-31

The WEMIX Foundation (part of the Wemade group) explained on its official site on July 30 the cause and remediation status of the illegal minting incident affecting its WEMIX Dollar stablecoin. The affected components were two smart contract systems: DIOS, which is responsible for maintaining WEMIX Dollar’s peg, and AMA, which handles 1:1 conversion against collateral assets. Both contracts contained an initializer function used to register admin addresses, and attackers exploited this step to transfer admin control to a third-party address, then minted tokens illegally. The Foundation states that further issuance has been halted. On scale, Tokenpost’s report frames the figure as being “in the billions of Korean won” (roughly in the low millions of US dollars range). At the time of writing we could not find a precise loss figure published by the Foundation, so this article does not treat any specific amount as confirmed fact — readers should verify the original text themselves via the announcement board on the WEMIX official site.

Editorial take: what this has to do with the card in your wallet

WEMIX Dollar is not USDT, nor USDC. Most readers won’t hold it directly, so the first-order impact is zero: if your funding path is “USDT on an exchange or in a wallet → card balance → spend,” this incident changes nothing. Holders of MPCard (including the Asia Elite variant) and Bybit Card don’t need to do anything.

What actually warrants a second look is one level deeper: whether your deposit path involves any non-mainstream stablecoin. Over the past couple of years, most card issuers have opened deposit pages to an ever-growing list of coins and chains in order to shave down fees. When you convert a chain’s “local stablecoin,” or some gaming/ecosystem token, into card balance, you are effectively underwriting the contract-level risk of that asset. When an incident like this one happens, the first response is typically for the issuer to suspend the deposit channel for that coin — not to suspend the whole card. In practice this can look like: within 7 days, a coin’s deposit option going grey; within 30 days, its conversion rate being marked down or a surcharge added; within 90 days, quiet delisting. Self-custody-oriented products such as OneKey Card have a different exposure path to contract-level risk than custodial ones, but they still can’t sidestep the underlying question of whether the deposit asset itself is safe.

The conclusion is simple: consolidate your deposit assets into USDT (TRC20 / ERC20 and other mainstream chains) and USDC, and leave the “0.2% cheaper” temptation to someone else. To compare fee structures across card types, see the lowest-fee USDT cards; if you’re still working out the basic mechanics of how funds move through a U-card, What is a U-card breaks down the full path.

Historical parallel: a new victim of an old bug

Technically, an unlocked initializer function (an uninitialized initializer, or the init function on an upgradeable/proxy contract) is not a new vulnerability class — it’s a classic pattern repeatedly discussed in smart contract security circles:

All three examples above are publicly disclosed industry incidents; we cite them here only as pattern comparisons, not as sources for any unverified figures. What’s shared: the flaw sits in permission initialization, not in the cryptographic algorithm; the scale of loss is determined by who discovers it first; and the remediation approach in every case is to cut off further minting before addressing the fallout. What’s different: this time the affected asset is a fiat-pegged stablecoin, and the issuer sits within a South Korean listed gaming company group — meaning it now faces not just community scrutiny, but South Korean disclosure requirements and regulatory inquiry. Worth noting: WEMIX went through a coordinated delisting episode across Korean exchanges in late 2022 (later relisted in stages), a history that will likely make regulators less tolerant of any shortfall in disclosure quality this time.

Compliance angle: “stablecoin issuer liability” is tightening across Asia-Pacific

Under South Korea’s current framework, the Virtual Asset User Protection Act already places obligations around asset custody and abnormal-transaction monitoring at the exchange level, but reserve disclosure and reserve audits for stablecoin issuers themselves are still at the legislative-development stage. In other words: illegal minting itself is of course unlawful (falling under property crime), but “how to define an issuer’s negligence liability for contract permission management, and whether compensation is owed” remains a grey area under current law. The relevant policy body is the Financial Services Commission of Korea (FSC), and its official site is the most reliable single source for tracking what happens next.

usdtcard does not currently have a dedicated Korea page; the two closest Asia-Pacific references are the Japan compliance guide (which classifies stablecoin issuers under “funds transfer service / trust-type” licensing, the clearest path currently available) and the Hong Kong compliance guide (where the Stablecoins Ordinance has established a licensing regime). Using these two jurisdictions as a benchmark: clearly permitted are fiat-pegged stablecoins from licensed issuers; the grey zone covers unlicensed algorithmic or partially-collateralized stablecoins; clearly prohibited is offering retail users pegged assets with no reserve disclosure. For Korean users’ practical considerations when choosing a card, see USDT card comparison for Korea.

Four things worth watching next

  1. The WEMIX Foundation’s follow-up announcements: whether they disclose the exact amount minted, the scope of affected addresses, and whether there’s a buyback/burn plan. An announcement without precise figures is itself a signal.
  2. Investment-warning status on Korean exchanges (DAXA members): if the token is designated an investment-warning item, this typically triggers another round of liquidity contraction.
  3. Audit reports and contract upgrade records: whether the fix is “lock the initializer” or a full migration to a new contract determines the handling cost for existing holdings.
  4. Changes to issuers’ lists of accepted deposit coins: this is the observation point closest to your own wallet — open the deposit page of the card you use, take a screenshot for your records, and compare again in a month.

Editorial recommendations

usdtcard does not conduct independent on-chain testing. All facts in this article are drawn from the public sources cited above; figures and liability determinations should be taken as final only from the WEMIX Foundation’s official announcements and statements from South Korean regulators.