WEMIX and Garden Finance pause services after separate security incidents drain over $1 million in stablecoins
Cryptocurrency

WEMIX and Garden Finance pause services after separate security incidents drain over $1 million in stablecoins

WEMIX contract compromise sees millions of unauthorised tokens minted

Layer-1 blockchain WEMIX and decentralised finance protocol Garden Finance halted operations on Sunday following distinct security incidents that resulted in the movement of at least $1.17 million in stablecoins. The events underscore the persistent vulnerabilities within the digital asset ecosystem, particularly concerning cross-chain infrastructure and off-chain components.

WEMIX disclosed that an attacker managed to compromise the ownership of a contract related to WEMIX$. Through this unauthorised access, the malicious actor issued approximately 5.23 million tokens. The attacker subsequently converted these illicitly minted tokens into 30,736 WEMIX and roughly 724,200 USDC.e. To obscure the trail and secure the funds, the assets were bridged to the Ethereum and BNB Chain networks. Bridging assets across different blockchains is a common tactic employed by attackers to complicate recovery efforts and take advantage of liquidity across various decentralised exchanges.

In response to the breach, WEMIX took the decisive step of pausing its services to prevent further unauthorised transactions and to assess the full extent of the vulnerability. The compromise of contract ownership represents a severe failure in access controls, allowing the attacker to manipulate the token supply at will. The conversion of the minted WEMIX$ into WEMIX and then into USDC.e demonstrates a multi-step laundering process typical of sophisticated exploits in the cryptocurrency sector. The movement of funds to Ethereum and BNB Chain suggests an attempt to leverage the high liquidity and complex transaction environments of these larger networks. You can read more about similar incidents in our Bitcoin coverage and broader crypto security reports.

Garden Finance solver breach drains $450,000 in USDT

Separately, decentralised finance protocol Garden Finance experienced a significant security incident on the same day. According to blockchain security firm Blockaid, approximately $450,000 in USDT was drained from Garden Finance’s hash time-locked contracts. These contracts were deployed across multiple networks, including Ethereum, Base, Arbitrum and BNB Chain.

Hash time-locked contracts are a fundamental component of cross-chain bridges and atomic swaps, ensuring that transactions are completed within a specific timeframe or the funds are returned. However, the security of these mechanisms relies heavily on the integrity of the off-chain infrastructure that supports them. Garden Finance clarified that its core contracts were not compromised. Instead, the protocol attributed the incident to a breach of an independent solver’s off-chain database.

A solver in this context is an off-chain entity responsible for finding optimal routes and facilitating transactions across different chains. The breach of the solver’s database allowed the attacker to manipulate the off-chain data required to authorise the release of funds from the on-chain hash time-locked contracts. Garden Finance emphasised that no user funds were lost or placed at risk, asserting that the vulnerability was isolated to the independent solver’s infrastructure. Despite this assurance, the protocol paused its services to mitigate the immediate threat and investigate the breach thoroughly. The incident highlights the often-overlooked risks associated with off-chain components that interact with immutable on-chain smart contracts. While the blockchain itself may be secure, the centralised or semi-centralised services built on top of it can present lucrative targets for malicious actors.

Market implications and security concerns for DeFi bridges

The dual incidents at WEMIX and Garden Finance collectively resulted in the movement of over $1 million in stablecoins, sending ripples of concern through the decentralised finance community. These events serve as a stark reminder of the multifaceted risks present in the crypto ecosystem. The WEMIX exploit demonstrates the catastrophic potential of compromised contract ownership, while the Garden Finance incident exposes the vulnerabilities inherent in off-chain solver infrastructure.

For the market, the immediate implication is a renewed focus on security audits and access controls. Protocols are likely to face increased pressure from their communities to implement more robust multi-signature wallets and time-locks for contract ownership changes. The WEMIX attack, which involved the unauthorised minting of tokens, directly impacts the token’s supply and could have severe repercussions on its market value and liquidity. The rapid conversion and bridging of these tokens indicate that the attacker was well-prepared to capitalise on the exploit immediately.

The Garden Finance breach, on the other hand, brings attention to the security of hash time-locked contracts and the solvers that manage them. As cross-chain interoperability becomes more prevalent, the reliance on off-chain solvers increases. These entities often operate with less transparency than the on-chain protocols they support, creating potential blind spots for users. The fact that $450,000 in USDT could be drained through an off-chain database breach suggests that the security of these auxiliary services is just as critical as the smart contracts themselves.

From a regulatory perspective, these incidents are likely to draw further scrutiny from policymakers. Regulators have already expressed concerns about the systemic risks posed by cross-chain bridges and the broader DeFi ecosystem. The ability of an attacker to mint tokens unauthorised and move them across chains exacerbates fears about money laundering and the traceability of illicit funds. The involvement of multiple networks, including Ethereum, BNB Chain, Base and Arbitrum, complicates the investigative process, as different jurisdictions and validator sets are involved.

Furthermore, the distinction made by Garden Finance that its contracts were not compromised and no user funds were at risk, while technically accurate, may do little to assuage broader market fears. The reality is that the protocol’s operational functionality was disrupted, and a significant amount of value was extracted. This nuance between on-chain contract security and off-chain infrastructure security is likely to be a focal point for future regulatory frameworks, which may begin to classify and regulate solvers and other off-chain service providers more strictly.

Analytical closing: The persistent threat of off-chain vulnerabilities

The security breaches affecting WEMIX and Garden Finance illustrate a complex and evolving threat landscape. The WEMIX incident is a textbook example of the dangers associated with centralised points of failure in contract ownership. The ability of an attacker to mint millions of tokens and bridge them to other networks underscores the need for stringent security measures, including multi-signature controls and delayed execution of sensitive operations.

The Garden Finance incident is particularly notable because it targeted the off-chain infrastructure rather than the smart contracts themselves. This represents a shift in attack vectors, where malicious actors are increasingly looking for weaknesses in the auxiliary systems that support blockchain networks. The breach of an independent solver’s database to drain funds from hash time-locked contracts demonstrates that the security of a DeFi protocol is only as strong as its weakest link.

As the crypto industry continues to mature and cross-chain interoperability expands, the security of off-chain components will become paramount. Protocols must adopt a holistic approach to security, ensuring that both their on-chain contracts and off-chain infrastructure are subject to rigorous audits and continuous monitoring. The market’s reaction to these incidents will likely dictate a higher standard for transparency and security practices, as users demand greater assurance that their funds are safe from both on-chain exploits and off-chain breaches. The events of Sunday serve as a critical reminder that in the pursuit of decentralisation, the vulnerabilities of centralised and semi-centralised components remain a significant hurdle to overcome.

CN

CryptoGazette Newsroom

Crypto Reporter

CryptoGazette Newsroom is the lead news desk covering price action, on-chain analytics, regulation, DeFi protocols, NFTs, and institutional adoption across the cryptocurrency ecosystem. The Newsroom focuses on time-sensitive market-moving stories.