NewsCryptoTriple-A Treasury Wallet Breach and WEMIX Exploit Underscore Crypto Security Risks

Triple-A Treasury Wallet Breach and WEMIX Exploit Underscore Crypto Security Risks

Author: CoinEdition·

Key Takeaways

  • •Triple-A said the July 25 breach affected only company treasury wallets and did not expose customer funds.
  • •On-chain investigator Specter estimated Triple-A’s losses at about $11.8 million across Ethereum, TRON, Polygon, and Arbitrum wallets.
  • •Triple-A said treasury reserves will cover the financial impact and that it remains able to meet all liabilities.
  • •WEMIX said an attacker minted about 5.22 million unbacked WEMIX$ tokens and moved approximately $724,000 worth of assets off-chain.
  • •WEMIX halted affected bridges and decentralized exchanges and asked exchanges to freeze related assets during its investigation.
Triple-A Treasury Wallet Breach and WEMIX Exploit Underscore Crypto Security Risks

Stablecoin payments company Triple-A has confirmed that attackers gained unauthorized access to treasury wallets holding company-owned digital assets, while on-chain investigators estimated losses at about $11.8 million.

Triple-A said customer funds were not affected, stating that client assets are held separately in trust accounts with safeguarding institutions and were not exposed to the breach. That distinction is important for payments firms because treasury wallets typically hold company operating assets, while segregated client accounts are designed to keep customer funds separate from a company’s own balance sheet.

The disclosure came as the WEMIX ecosystem reported a separate smart contract exploit involving its WEMIX$ stablecoin contract. In that incident, attackers minted about 5.22 million unbacked WEMIX$ tokens and moved roughly $724,000 worth of assets off-chain before the protocol halted affected operations.

Triple-A Says Client Assets Were Not Exposed

In a statement, Triple-A said it detected unauthorized access on July 25 to certain wallets that held the company’s own digital assets.

The company stressed that the incident did not affect customer funds because Triple-A does not provide crypto custody services. Instead, it said client assets are maintained separately in trust accounts with safeguarding institutions, which were not exposed to the breach.

As a precautionary step, Triple-A placed some services into maintenance mode for about three hours while it secured its infrastructure. The company said all services have since resumed and that transactions and settlements are operating normally.

Triple-A did not publicly disclose the value of the stolen assets. However, on-chain investigator Specter estimated the losses at about $11.8 million across wallets on Ethereum, TRON, Polygon, and Arbitrum.

According to Triple-A, only its treasury assets were affected. The company said the financial impact will be fully covered by its treasury reserves and added that it remains well-capitalized and able to meet all liabilities.

Triple-A said it is working with cybersecurity experts, blockchain forensics specialists, and the Singapore Police Force to investigate the breach, trace the stolen assets, and support recovery efforts. Blockchain forensics firms often track stolen funds across public ledgers, but recovery can depend on whether assets reach centralized venues that can freeze funds or remain under attacker-controlled wallets.

WEMIX Reports Separate WEMIX$ Contract Exploit

Less than 24 hours after the Triple-A incident, the WEMIX blockchain disclosed a separate security breach involving the WEMIX$ stablecoin contract.

According to WEMIX, an attacker gained control of the contract and minted about 5.22 million unbacked WEMIX$ tokens. The attacker swapped part of those tokens and moved approximately $724,000 worth of assets off-chain before the protocol halted its bridges and decentralized exchanges.

Initial reports placed the losses at around $6.25 million. WEMIX later said the amount successfully bridged out of the ecosystem was about $724,000.

The WEMIX team has also asked exchanges to freeze any related assets while the project continues investigating the incident. The response reflects a common containment approach after token-minting exploits, where projects try to limit liquidity paths, bridge transfers, and exchange withdrawals tied to the affected assets.

2026 Crypto Security Losses Continue to Mount

The Triple-A and WEMIX incidents add to a growing list of crypto security breaches reported in 2026. Industry estimates indicate that more than $1 billion has already been lost to hacks this year, highlighting continuing risks tied to treasury wallet management and smart contract vulnerabilities.

The two cases also show how different parts of crypto infrastructure can be exposed in different ways: company-controlled wallets can be targeted through operational security failures, while smart contracts can create losses when attackers gain unauthorized control over minting or transfer mechanisms.

Triple-A maintains that its breach was limited to operational treasury wallets, while WEMIX is continuing recovery work following its second major security incident in less than 18 months.