- Garden Finance temporarily suspended its app when an attacker hacked an independent solver’s off-chain database, leading to a reported $450,000 USDT exploit.
- Garden Finance emphasized that its protocol and HTLC smart contracts were not compromised, and no customer cash was lost during the incident.
- WEMIX halted bridges and services after an attacker exploited a WEMIX$-linked contract and shifted about $724,000 in USDC.
Three crypto companies, Garden Finance, Triple-A, and WEMIX, have reported separate security breaches that together led to losses exceeding $13 million. Despite the incidents, each company said the attacks did not put customer funds at risk or directly affect users.
The cases show that cybercriminals are targeting different parts of the crypto infrastructure, including off-chain databases, treasury wallets, and contract ownership.
Garden Finance temporarily shut down its app after an attacker breached the off-chain database of one of its independent solvers
Garden Finance Pauses App
🚨 Blockaid detected an ongoing exploit on @gardenfi HTLC.
~$450k USDT drained so far on Eth, Base, Arb and BSC.
More details in 🧵
— Blockaid (@blockaid_) July 26, 2026
Earlier, blockchain security firm Blockaid reported on X that roughly $450,000 in USDT had been drained from Garden Finance’s Hash Time-Locked Contracts (HTLCs) across Ethereum, Base, Arbitrum, and BNB Smart Chain. The firm also shared wallet addresses believed to be connected to the attack.
Garden Finance later clarified that its protocol and HTLC smart contracts were not hacked. Instead, the attacker gained access to an independent solver’s off-chain database and created fake swap records. This caused the solver to release funds for transactions that had never been funded by the other party.
The company said no user funds were affected, and the losses were limited to assets owned by the solver. As a precaution, Garden temporarily paused its services while investigating the incident and is now working with zeroShadow, Quantstamp, and Blockaid to trace and recover the stolen funds.
Triple-A Confirms The Treasury Wallet Breach, Says Customer Funds Remain Safe
The business secured the impacted systems and put some of its services in maintenance mode for almost three hours after discovering the problem. On-chain investigator Specter calculated the losses at about $11.8 million, despite Triple-A not disclosing the exact amount that was taken.
On 25 July 2026, Triple-A identified unauthorized access to certain wallets containing the company’s own digital assets.
Client funds were not affected. Triple-A does not provide digital assets custody on behalf of its clients, and client funds are held separately in trust… pic.twitter.com/CPQmMXAaOP
— Triple-A (@TripleAHQ) July 27, 2026
Triple-A said the stolen assets came only from its company-owned treasury wallets and did not involve customer funds. The company explained that it does not hold users’ crypto assets and keeps client funds separately in safeguarded trust accounts.
Since then, the business has resumed all services, and settlements and transactions are proceeding as usual. It is currently investigating the hack, tracking down the stolen assets, and assisting with recovery efforts in collaboration with cybersecurity experts, blockchain forensic companies, and the Singapore Police Force.
Attacker Mints 5.23M WEMIX$ & Moves $724K In Crypto Assets
The Layer-1 blockchain network WEMIX also disclosed a security issue when an attacker took over a contract linked to its WEMIX$ stablecoin.
Update on WEMIX$ Security Issue and Response Measures
The abnormal transactions involving WEMIX$ and have taken immediate emergency measures to protect user assets and prevent further impact. Investigation and asset tracking are actively underway.
Full Announcement:… pic.twitter.com/PHcAdB0uAw
— WEMIX (@WemixNetwork) July 26, 2026
The company claims that the attacker converted the tokens into 30,736 WEMIX and 724,198.27 USDC, earning around 5.23 million WEMIX$. After being connected to the Ethereum and BNB Smart Chain, the USDC.e was traded for assets including Ether (ETH) and Tether (USDT).
According to WEMIX, centralized exchanges received a portion of the pilfered assets. While the inquiry is ongoing, the business asked stablecoin issuers and exchanges to freeze the money and temporarily halt bridges, liquidity pools, and a number of services.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like









Leave a comment