Two separate security breaches have rocked the crypto industry this week, with Singapore payments firm Triple-A suffering an $11.8 million hot wallet drain and decentralized derivatives protocol AFX losing $24.15 million in a bridge exploit. On-chain investigators and company statements reveal a pattern of infrastructure compromises rather than smart contract flaws.
Researcher Specter reported that the Triple-A incident, first detected Friday, has now expanded across multiple chains including Ethereum, TRON, TON, Solana, and Bitcoin. Stolen funds were rapidly swapped and bridged to Ethereum, consolidating at a primary address that held 5,227 ETH at the time of initial analysis by security firm PeckShield. Despite public alerts, new deposits continued flowing into compromised wallets over 31 hours after the first outflows, suggesting the team was slow to disable functionality. Triple-A, which is licensed by Singapore’s Monetary Authority, stated that customer assets were not affected, as the drained wallets held company-owned digital assets.
Meanwhile, AFX announced a goodwill plan for users impacted by a $24.15 million USDC theft on July 22. Its post-mortem revealed the attack started with a social engineering campaign where a developer was tricked into cloning a malicious repository. The attacker eventually replaced system binaries, manipulated internal artifact repositories, and used trusted operational infrastructure to compromise validator nodes without exploiting Arbitrum’s native bridge. The compromised validators co-signed a bridge transaction that drained funds, which were then converted into approximately 12,467 ETH on Ethereum. AFX has rebuilt its infrastructure and attributed the attack to the DPRK-linked TraderTraitor group.