
Triple-A’s hot wallets appear to have lost more than $9.7 million across several blockchains, with the suspected attacker swapping the assets and consolidating the proceeds on Ethereum.
Summary
- More than $9.7 million was reportedly removed from Triple-A-controlled hot wallets.
- Suspicious outflows affected at least four networks, including Ethereum, Solana, TRON and TON.
- The suspected attacker consolidated the proceeds into approximately 5,226.66 ETH on Ethereum.
- Triple-A has not confirmed the breach or disclosed whether customer funds were affected.
What happened to Triple-A’s hot wallets
On-chain analyst Specter first identified suspicious transactions involving hot wallets linked to Triple-A, a Singapore-based provider of stablecoin payment infrastructure.
Specter initially estimated that more than $9.3 million had been removed, swapped, and transferred across chains to Ethereum. Blockchain security firm PeckShield later amplified the alert, while subsequent estimates placed the suspected loss above $9.7 million.
The activity reportedly affected Triple-A wallets operating on Ethereum, Solana, TRON and TON. Some reports also identified transactions involving Polygon and Arbitrum, potentially expanding the incident to six networks.
Triple-A had not publicly confirmed the exploit at the time of writing. The company has also not disclosed when the suspicious activity began, how its wallets were accessed, or whether the affected assets belonged to Triple-A, its business customers, or payment recipients.
Without a company statement or technical investigation, the incident remains a suspected hot-wallet compromise rather than a confirmed protocol exploit.
Stolen assets were consolidated into Ethereum
On-chain data cited by security researchers showed that the transferred assets were exchanged and bridged to Ethereum after leaving the affected wallets.
The receiving address reportedly held about 5,226.66 ETH, worth approximately $9.7 million at the time of the alert. Consolidating assets into Ether can make a collection of stablecoins and network-specific tokens easier to move from one address.
Researchers have not publicly identified the suspected attacker or established whether the address has links to previous exploits. No report has confirmed that the funds entered an exchange, mixer, or other service after reaching Ethereum.
The difference between Specter’s initial $9.3 million estimate and later figures above $9.7 million may reflect additional transfers or changes in Ether’s market value. A verified loss total will depend on Triple-A identifying every affected wallet and transaction.
Why the Triple-A incident matters in the US
Triple-A provides infrastructure that allows companies to collect, convert and send payments through stablecoins and traditional banking networks. Its services include merchant checkout, business payments, local payouts and cross-border settlement.
The company states that it operates as a licensed financial institution in the United States, Europe and Singapore. Triple-A also holds a Major Payment Institution licence from the Monetary Authority of Singapore and joined Circle Payments Network in March to support stablecoin-to-local-currency settlement.
Its US presence gives the incident a potential regulatory and counterparty angle, although there is no evidence that American customers or companies suffered losses. Any US impact will depend on which entity controlled the wallets, who owned the assets, and whether regulated payment operations were involved.
Triple-A uses Fireblocks as part of its digital-asset infrastructure. However, neither on-chain researchers nor Triple-A have attributed the suspected breach to Fireblocks, and no available evidence indicates that the custody technology provider was compromised.
Triple-A faces questions after another cross-chain attack
The suspected breach follows another recent incident involving cross-chain infrastructure. As crypto.news reported, an attacker fabricated 1,627 Solana deposit events targeting Across Protocol’s Risk Labs-operated relayer on July 17.
Those false deposits requested $41.7 million in payments across 18 destination chains. Risk Labs’ relayer filled 581 requests before Across stopped its Solana operations, limiting the realized loss to less than $4 million, according to the protocol’s post-incident report.
The Across and Triple-A incidents do not appear to be connected. However, both cases involved activity spanning several networks, increasing the number of wallets, transaction systems and monitoring processes involved in detecting suspicious transfers.
Triple-A has yet to explain whether it has suspended deposits, withdrawals or cross-chain operations. The company’s next statement will need to clarify the final loss, the affected assets, the source of the breach and whether customers will receive compensation.





Be the first to comment