Crimes and Fraud News

Triple-A Payment Service Hack Drains $11.8M — How Bad Is It?

Nana K.
27 July 2026 3 min read

The summer of 2026 has seen a surge in hacker and scammer activity. We break down several attacks targeting Triple-A, Garden Finance, and WEMIX.

Singapore-based payment service Triple-A, which specializes in stablecoin settlements, has confirmed unauthorized access to its treasury wallets.

Hot topic: PlanB Comes Out Against BIP 110 Bitcoin Fork

According to on-chain researcher Specter, the stolen amount has grown to $11.8 million. Initial reports put it at $9.3 million, then $9.7 million, before additional bitcoin (BTC) and TRON (TRX) withdrawals pushed it to the current figure.

The company said client funds were unaffected, as they are held in trust accounts with third-party custodians per regulatory requirements. The damage was limited to operational accounts and will be covered by Triple-A’s reserves.

Contents

How the Hacker Stole $11.8M and What’s Known About the Attack

The attack began on July 24. The attacker withdrew funds across multiple networks, including Ethereum (ETH), Polygon (POL), Arbitrum (ARB), Solana (SOL), and The Open Network, then added another $1.8 million via bitcoin and TRON. The hacker consolidated 5,226.67 ETH$1,761.17 into a single address.

Triple-A discovered the attack on Saturday, July 25, and temporarily suspended services for about three hours to isolate affected infrastructure segments. The damage was limited to operational accounts and will be written off against company reserves.

The company said all services are restored and operating normally, with transactions and settlements processing as usual. The investigation involves cybersecurity experts and Singapore police.

Read more: Could Rogue AI Steal Your Crypto? Why the OpenAI Scare Has Investors on Alert

Two Attacks Over the Weekend: WEMIX Loses $724,000, Garden Finance $450,000

On July 26, an attacker exploited a contract tied to South Korean project WEMIX’s stablecoin. The hacker minted about 5.23 million “stable coins” without authorization and converted them to 30,736 WEMIX and 724,198 USDC$0.9999.e, then bridged to Ethereum and BNB Smart Chain. Some funds ended up on centralized exchanges.

The WEMIX team suspended all WEMIX3.0 network bridges and asked exchanges and stablecoin issuers to freeze assets–some addresses have already been blocked.

Separately, Blockaid reported an attack on cross-chain protocol Garden Finance. The attacker drained about $450,000 in USDT from hash-time-locked contracts across Ethereum, Base, Arbitrum, and BNB$572.56 Smart Chain. But Garden Finance said the protocol and smart contracts weren’t compromised. The hacker infiltrated an off-chain database of an independent solver and injected fake transaction data, causing the solver to send funds for unpaid deals. The protocol paused operations for investigation.

Read more: Tron Blockchain Crypto Future — Why More Users Are Choosing Other Networks Instead

A Week of Hacks: AFX Trade, Verus, and New Attacks

The Triple-A, WEMIX, and Garden Finance incidents follow last week’s cross-chain bridge attacks. On July 23, AFX Trade lost $24.15 million through validator compromise, and the Verus-Ethereum bridge lost $7.54 million in a repeat exploit.

This highlights persistent systemic risks in the cross-chain infrastructure segment, which has been hit by at least 10 major exploits in 2026 with total losses exceeding $350 million. For Triple-A, the incident is a serious reputational test–especially given its major payment institution license from the Monetary Authority of Singapore.

Learn more: What Is TENDIES Crypto? The Viral Memecoin Fueling Robinhood Chain’s Latest Rally

Nana K.

Crypto journalist and content creator specializing in market analytics, regulatory developments, and the social impact of cryptocurrency. With experience at BeInCrypto and Cointelegraph, she covers both breaking news and creative…