TLDR
- Over $9.7 million was removed from Triple-A hot wallets across multiple blockchains
- Networks affected include Ethereum, Solana, TRON, and TON, possibly extending to Polygon and Arbitrum
- The suspected attacker consolidated funds into approximately 5,226.66 ETH on Ethereum
- Triple-A has not confirmed the breach or said whether customer funds were at risk
- Triple-A operates as a licensed payment institution in the US, Europe, and Singapore
Singapore-based stablecoin payment provider Triple-A is at the center of a suspected hot wallet exploit after on-chain analysts flagged suspicious outflows totaling more than $9.7 million.
⚠️ALERT: Triple-A wallets are under an apparent active exploit with over $9.7M drained.
Onchain analyst Specter has flagged suspicious outflows from Triple-A hot wallets across TRON, Ethereum, Polygon, and Arbitrum, with the stolen assets consolidated into 5,227 ETH.
Triple-A… pic.twitter.com/1RykKuPGwA
— Coin Bureau (@coinbureau) July 25, 2026
On-chain analyst Specter first spotted the unusual transactions. Blockchain security firm PeckShield later amplified the alert, with estimates rising from an initial $9.3 million to above $9.7 million.
Funds Moved Across Multiple Chains
The suspicious activity hit wallets on Ethereum, Solana, TRON, and TON. Some reports also flagged transactions on Polygon and Arbitrum, potentially bringing the total to six networks.
After leaving those wallets, the assets were swapped and bridged to Ethereum. The receiving address held around 5,226.66 ETH at the time of the alert.
Consolidating into ETH is a common step after a multi-chain exploit, making it easier to move varied assets from one address.
The difference between early and later estimates may reflect additional transfers or price movement in Ether.
What Triple-A Does — and What It Has Not Said
Triple-A provides infrastructure that lets companies collect, convert, and send payments using stablecoins and traditional banking networks. Services include merchant checkout, business payments, and cross-border settlement.
The company holds licenses in the US, Europe, and Singapore. It also holds a Major Payment Institution licence from Singapore’s Monetary Authority and joined Circle Payments Network in March 2026.
Triple-A has not confirmed the exploit. It has not disclosed how the wallets were accessed, when activity began, or whether customer funds were affected.
The company uses Fireblocks for digital asset custody. No available evidence points to Fireblocks being compromised.
No Confirmed Attacker, No Customer Statement
Researchers have not publicly identified the suspected attacker. No report has confirmed the funds moved into an exchange or mixer after reaching Ethereum.
Without a company statement or technical investigation, this remains a suspected hot wallet compromise, not a confirmed protocol exploit.
Triple-A has not said whether deposits, withdrawals, or cross-chain operations have been suspended.
The incident follows a separate attack on July 17, when an attacker fabricated 1,627 Solana deposit events targeting Across Protocol. That incident resulted in under $4 million in losses after Across halted Solana operations. The two cases are not linked.
Triple-A’s next public statement will need to cover the final loss total, how wallets were breached, and whether affected customers will be compensated.






Be the first to comment