(Screenshot from WEMIX Foundation official website)

The cause of the recent hacking incident involving Wemade's cryptocurrency "WEMIX" turned out to be an attack that exploited a loophole in Blockchain transaction processing. About 5,225,525 WEMIX Dollars were illicitly issued and leaked in this hack, with damages totaling about 7.7 billion won.

On the 30th, the WEMIX Foundation, a subsidiary of Wemade, disclosed the analysis of the cause of the security incident and the response status on its website. Regarding the circumstances of the security incident, WEMIX said, "It was an attack that targeted a loophole in Blockchain transaction processing, and administrator privileges were transferred to a third party."

WEMIX said the incident did not involve a breach of the company's internal systems or the leakage of administrator passwords (private keys).

The attacker exploited vulnerabilities in two "smart contract" systems: DIOS, which keeps the price of WEMIX Dollar (WEMIX$) stable, and the AMA program, which exchanges collateral assets 1-to-1. A smart contract is a program that runs automatically when preset conditions are met.

DIOS and AMA execute an initialization function that registers an administrator address, and after a November 2022 upgrade, the execution limit for this function changed from "allowed only once" to "allowed up to twice."

The contracts containing the initialization function were created by an outsourcing developer, and it turned out they were left in a state where anyone could execute them without separate access permission restrictions.

The attacker called the second initialization function, changed the administrator addresses of the two contracts to an attack contract they created, and granted themselves the authority to call the issuance and exchange functions. The address for receiving proceeds and fees was also changed to their own.

Abusing this, the attacker illicitly issued about 5,225,525 WEMIX Dollars worth about 7.7 billion won, and transferred about 723,244 of them (about 1 billion won) externally. Separately, 34,752 regular WEMIX coins were also transferred.

The WEMIX Foundation said, "We have identified indications linking some game tokens to WEMIX Dollar and are analyzing the related transactions," adding, "We identified the attacker address, requested blacklisting at exchanges where funds flowed in, and revoked issuance privileges to block additional issuance."

The company filed an official report with investigative authorities on the 28th and is cooperating with the investigation.

※ This article has been translated by AI. Share your feedback here.