The amount stolen from the payment service Triple-A has surged to $11.8 million, according to the on-chain researcher known as Specter.
31 hours after pic.twitter.com/W04XoRrldv
— Specter (@SpecterAnalyst) July 26, 2026
The project’s hot wallets were compromised in a hacking incident on July 24. At that time, Specter reported that the attacker had stolen $9.3 million, transferring it through a bridge to the Ethereum network. Analysts from PeckShield mentioned a theft amounting to $9.7 million.
— PeckShieldAlert (@PeckShieldAlert) July 25, 2026
On July 26, Specter highlighted an additional $1.8 million was withdrawn via Bitcoin and TRON. Previously, the blockchain of the first cryptocurrency was not listed among the affected networks, with experts only mentioning Ethereum, Polygon, Arbitrum, Solana, and The Open Network.
The hacker consolidated the stolen funds into a single Ethereum address. According to PeckShield, this address has accumulated 5,226.67 ETH (approximately $9.73 million) through eight incoming transfers, with the largest being around 4,140 ETH.
On July 27, the Triple-A team issued a detailed statement confirming unauthorized access to their treasury wallets. To isolate the affected parts of their infrastructure, the service was temporarily halted for about three hours. The company assured that customer funds remained safe, as they keep user assets in trust accounts with third-party custodians.
While Triple-A did not specify the exact amount stolen or the reason behind the hack, they assured that the losses are confined to operational accounts and will be covered by reserves. As of the time of this report, the services are functioning normally. An investigation is underway with the involvement of cyber experts and the Singapore police.
WEMIX Hack
On July 26, a hacker breached a contract associated with the WEMIX$ stablecoin from the South Korean project of the same name, causing losses of $724,000, as reported by the team.
The attacker unauthorizedly issued around 5.23 million "stable coins" and converted them into 30,736 WEMIX and 724,198 USDC.e, subsequently transferring them through a bridge to Ethereum and BNB Smart Chain. There, they exchanged the stolen assets for ETH and USDT, distributing them across multiple addresses.
According to WEMIX, part of the funds ended up on centralized exchanges. The company identified the hacker's wallets and requested asset freezes from exchanges and stablecoin issuers, with some already blocking addresses related to the incident.
In response to the attack, the project team suspended operations of all bridges in the WEMIX3.0 network and related activities. As of this writing, the causes and full extent of the incident are still being determined, with preliminary figures subject to change, the company noted.
Garden Finance Attack
Simultaneously, Blockaid reported an attack on the cross-chain protocol Garden Finance, which paused operations after being warned.
🚨 Blockaid detected an ongoing exploit on @gardenfi HTLC.
~$450k USDT drained so far on Eth, Base, Arb and BSC.
More details in 🧵
— Blockaid (@blockaid_) July 26, 2026
Researchers indicated that on July 26, the hacker withdrew approximately $450,000 in USDT from Garden's HTLC contracts across Ethereum, Base, Arbitrum, and BNB Smart Chain.
Later, a representative from Garden clarified in a comment to Cointelegraph that the protocol and the project's smart contracts were unaffected. The hacker infiltrated the off-chain database of one of the independent solvers and entered fake transaction data, resulting in the solver transferring funds for transactions that the counterparty had not actually paid.
As of this report, the project team is still assessing the exact damage, as well as the list of affected assets and networks.
It is worth noting that on July 23, the AFX Trade exchange suspended its bridge operations after $24.15 million in USDC was withdrawn. On the same day, developers of the Ethereum bridge Verus reported a hack totaling $7.54 million.
