Triple-A Loss Reaches $11.8M Alongside New DeFi Attacks

izobrazhenie_2026-07-24_172154372-e1784906529588.png

A wave of security breaches targeting crypto payment services and DeFi protocols has resulted in millions of dollars in losses. Crypto payment gateway Triple-A has revised the damage estimate from its recent breach upward, while South Korean project WEMIX and cross-chain protocol Garden Finance have encountered fresh exploits.

Triple-A: Losses Rise to $11.8M

The estimated damage from the hot wallet breach at payment gateway Triple-A has increased significantly. According to pseudonymous on-chain researcher Specter, total losses have reached $11.8 million.

Timeline and Attack Details

  • July 24: Analysts detected an exploit targeting the project’s hot wallets. Specter initially reported $9.3 million stolen and bridged to Ethereum, while PeckShield analysts estimated the loss at $9.7 million. Affected networks included Ethereum, Polygon, Arbitrum, Solana, and TON.
  • July 26: Specter identified an additional $1.8 million drained via the Bitcoin and TRON networks. The Bitcoin blockchain had not previously been listed among the impacted networks.
  • Fund Consolidation: The attacker consolidated stolen funds into a single Ethereum address. PeckShield noted that 5,226.67 ETH (~$9.73 million) accumulated across eight incoming transactions, with the largest single transfer totaling roughly 4,140 ETH.

Company Response

On July 27, the Triple-A team issued an official statement:

  • Customer Safety: Customer funds were not impacted, as user assets are stored in segregated trust accounts with third-party custodians.
  • Threat Isolation: Unauthorized access was strictly limited to treasury (operational) wallets. To isolate compromised infrastructure segments, operations were temporarily paused for approximately three hours.
  • Current Status: Losses will be covered entirely using Triple-A’s internal reserves. Services are currently operating as normal, and an investigation is underway involving cybersecurity experts and the Singapore Police Force.

WEMIX: $724,000 Unauthorized Mint

On July 26, an attacker exploited a smart contract associated with the WEMIX$ stablecoin from South Korean project WEMIX.

Attack Mechanism

  1. Unauthorized Minting: The attacker generated 5.23 million WEMIX$ stablecoins without authorization.
  2. Conversion and Bridging: The attacker swapped the minted tokens for 30,736 WEMIX and 724,198 USDC.e, then bridged the assets to Ethereum and BNB Smart Chain.
  3. Laundering: On the destination chains, the stolen funds were swapped for ETH and USDT before being distributed across several addresses.

Mitigation Measures

A portion of the stolen funds reached centralized exchanges (CEXs). The WEMIX team identified the attacker’s wallet addresses and requested that exchanges and stablecoin issuers freeze the funds—several platforms have already blacklisted the associated addresses.

As a precaution, the WEMIX team temporarily suspended all bridge operations on the WEMIX3.0 network while working to determine the full scope of the incident.

Garden Finance: Off-Chain Infrastructure Compromise

On July 26, blockchain security firm Blockaid reported suspicious withdrawals from cross-chain protocol Garden Finance. The attacker drained roughly $450,000 in USDT from HTLC contracts across Ethereum, Base, Arbitrum, and BNB Smart Chain, prompting the protocol to temporarily pause operations.

Off-Chain Attack Vector

As a Garden representative clarified in a statement to Cointelegraph, the protocol itself and its smart contracts were not breached.

Instead, the attacker breached the off-chain database of an independent solver (an execution agent for cross-chain transactions) and injected forged transaction data. This caused the solver to automatically fulfill transfers for trades where the counterparty had not actually provided payment.

The Garden Finance team is currently determining the exact financial impact, as well as the full list of affected networks and assets.

scroll to top