Two separate security incidents have hit the cryptocurrency sector in quick succession, with decentralized finance protocol GardenFi and stablecoin payments company Triple-A both confirming unauthorized access that drained company-held funds. The attacks, which targeted assets across multiple blockchains, underscore the persistent risks faced by multi-chain and cross-chain systems.
GardenFi hit by active HTLC exploit
Blockchain security firm Blockaid reported that it detected an ongoing exploit affecting GardenFi’s hashed timelock contract (HTLC) component. According to the alert, approximately $450,000 in USDT was drained across Ethereum, Base, Arbitrum, and BNB Chain. Because the activity was described as active, the total loss may change as investigators review additional wallets and transaction paths. No official statement from GardenFi had been released at the time of the initial report, leaving users waiting for guidance on affected contracts, asset exposure, and any recovery efforts. The multi-chain nature of the attack has placed fresh scrutiny on the security architecture of DeFi protocols that operate across several networks, highlighting the need for rapid monitoring and emergency pause mechanisms.
Triple-A confirms $11.8 million treasury breach
Triple-A, a Singapore-based stablecoin payments firm, acknowledged that unauthorized access to its treasury wallets resulted in the loss of company-owned digital assets. The company detected the breach on July 25 and initiated a three-hour maintenance window to secure infrastructure and complete additional security checks. Triple-A stressed that client funds were not affected because it does not provide custody services; customer assets are held separately in trust accounts at safeguarding institutions. The company said it remains well capitalized and can meet all liabilities, with the financial impact absorbed through its treasury reserves. However, on-chain investigators – including Specter and PeckShield – had already flagged suspicious transactions days before the official statement. Specter estimated that more than $11.8 million in assets was drained from wallets across Tron, Ethereum, TON, and Solana, with the stolen funds swapped and bridged to Ethereum, accumulating around 5,226.66 ETH in a single receiving address. Triple-A is working with cybersecurity experts, blockchain forensics firms, and the Singapore Police Force to trace the stolen assets, but neither the attackers nor the exact cause of the breach have been identified.
These incidents add to a grim tally for 2026, with cumulative losses from DeFi attacks exceeding $630 million in the first seven months of the year, according to researcher estimates. The back-to-back exploits reinforce calls for stronger security practices, faster incident response, and more transparent communication with affected users.