Triple-A Hack Losses Rise to $11.8 Million

cryptonews.ruPublished on 2026-07-27Last updated on 2026-07-27

Abstract

Triple-A payment service hack losses have grown to $11.8 million, with funds stolen from hot wallets across multiple chains including Ethereum, Polygon, and Arbitrum. The hacker consolidated the assets into a single Ethereum address. Triple-A confirmed the breach, stating customer funds were unaffected as they are held with third-party custodians, and the loss will be covered by reserves. Separately, the WEMIX project suffered a $724,000 hack where an attacker minted unauthorized stablecoins. The team has identified wallets and requested exchanges freeze assets. Simultaneously, Blockaid reported a ~$450,000 USDT exploit targeting the cross-chain protocol Garden Finance via an off-chain database breach of an independent solver. The protocol's smart contracts were not compromised. These incidents follow other recent security breaches, highlighting ongoing vulnerabilities in the crypto space.

The volume of funds stolen in the hack of the Triple-A payment service has increased to $11.8 million. This was indicated by an on-chain researcher using the pseudonym Specter.

31 hours after pic.twitter.com/W04XoRrldv

— Specter (@SpecterAnalyst) July 26, 2026

The project's hot wallets were hacked on July 24. At that time, the specialist noted that the attacker had stolen $9.3 million and transferred it via a bridge to the Ethereum network. PeckShield analysts wrote about a theft of $9.7 million.

#PeckShieldAlert Specter has reported that @TripleAHQ wallets appear to have been drained of more than $9.7M worth of crypto across multiple chains, including #TRON, #Ethereum, #Polygon, and #Arbitrum.

The exploiter bridged the stolen funds to Ethereum. 5,227 $ETH is currently... pic.twitter.com/JxCr79V2db

— PeckShieldAlert (@PeckShieldAlert) July 25, 2026

On July 26, Specter pointed to an additional withdrawal of $1.8 million via Bitcoin and TRON. Previously, the first cryptocurrency's blockchain was not listed among the affected networks—experts had mentioned only Ethereum, Polygon, Arbitrum, Solana, and The Open Network.

The hacker consolidated the funds on one Ethereum address. According to PeckShield, 5,226.67 $ETH (~$9.73 million) has accumulated there from eight incoming transfers. The largest of these was about 4,140 $ETH.

On July 27, the Triple-A team issued a detailed statement confirming unauthorized access to its treasury wallets. To isolate the affected infrastructure segments, the service was suspended for approximately three hours. Client funds were not affected as the project stores user assets in trust accounts with third-party custodians, the company reported.

Triple-A did not disclose the exact amount stolen or the cause of the hack but assured that the damage is limited to operational accounts and will be written off against reserves. At the time of writing, services are operating normally. An investigation is underway with the involvement of cybersecurity experts and the Singapore police.

Hack of $WEMIX

On July 26, an attacker hacked a contract associated with the $WEMIX$ stablecoin from the South Korean project of the same name. Losses amounted to $724,000, the team reported.

Without authorization, the hacker minted approximately 5.23 million "stablecoins" and converted them into 30,736 $WEMIX and 724,198 $USDC.e, then transferred them via a bridge to Ethereum and $BNB Smart Chain. There, he exchanged the stolen assets for $ETH and $USDT and distributed them across several addresses.

According to $WEMIX, some of the funds ended up on centralized exchanges. The company identified the attacker's wallets and requested exchanges and stablecoin issuers to freeze the assets—some have already blocked addresses associated with the incident.

In response to the attack, the project team suspended all WEMIX3.0 network bridges and related operations. At the time of writing, the causes and full scope of the incident are being determined—preliminary figures may change, the company said.

Wemix Explains Delay in Disclosing $6.2 Million Hack

Attack on Garden Finance

In parallel, Blockaid specialists reported an attack on the cross-chain protocol Garden Finance, which suspended operations following the warning.

🚨 Blockaid detected an ongoing exploit on @gardenfi HTLC.

~$450k $USDT drained so far on Eth, Base, Arb and BSC.

More details in 🧵

— Blockaid (@blockaid_) July 26, 2026

According to the researchers, on July 26, the attacker withdrew about $450,000 in $USDT from Garden's HTLC contracts on Ethereum, Base, Arbitrum, and $BNB Smart Chain.

Later, a Garden representative clarified to Cointelegraph that the protocol and the project's smart contracts were not compromised. The hacker infiltrated the off-chain database of one of the independent solvers and inserted fake transaction data. This caused the solver to transfer funds for deals that the counterparty had not actually paid for.

At the time of writing, the project team is still determining the exact damage, the list of affected assets and networks.

Recall that on July 23, the AFX Trade exchange suspended its bridge operation after a withdrawal of 24.15 million $USDC. On the same day, developers of the Ethereum bridge Verus reported a hack of $7.54 million.

DEX Ostium Hack, Kratos Liquidation, and Other Cybersecurity Events
end-content

Related Questions

QWhat is the current estimated loss from the Triple-A hack, and how has this figure changed since the initial reports?

AThe current estimated loss from the Triple-A hack is $11.8 million. This figure increased from initial reports of $9.3 million and $9.7 million.

QHow did the Triple-A company respond to the security breach and what measures did they take to protect user funds?

ATriple-A confirmed unauthorized access to its treasury wallets. The company temporarily suspended its service for about three hours to isolate affected infrastructure segments. They stated that user funds were not affected because customer assets are stored in segregated trust accounts with third-party custodians.

QWhat was the nature of the $WEMIX exploit on July 26, and what was the reported loss amount?

AThe $WEMIX exploit involved a hacker gaining unauthorized access to a contract related to the WEMIX stablecoin, minting approximately 5.23 million stablecoins. These were converted into 30,736 $WEMIX and 724,198 $USDC.e, resulting in a reported loss of $724,000.

QDescribe the attack on Garden Finance. What was the method used by the attacker, and was the protocol's core infrastructure compromised?

AThe attack on Garden Finance involved the hacker infiltrating the off-chain database of an independent solver. The attacker injected fake transaction data, causing the solver to release funds for trades that the counterparty never actually paid for. The project's representative clarified that the core protocol and smart contracts were not compromised.

QBesides the Triple-A and $WEMIX incidents, what other major security event is mentioned in the article as occurring around the same time period (late July 2026)?

AThe article mentions an attack on the cross-chain protocol Garden Finance on July 26, where approximately $450,000 in $USDT was drained from its HTLC contracts on Ethereum, Base, Arbitrum, and BNB Smart Chain.

Related Reads

Trading

Spot
活动图片