Monday, July 27, 2026

Triple‑A Hot Wallets Drained of Approximately $9.7M Across Multiple Chains

Breached multi-chain hot wallet draining coins toward glowing Ethereum address in neon-lit futuristic scene.

Triple-A has confirmed unauthorized access to wallets holding the company’s own digital assets, following on-chain alerts that initially estimated losses above $9.7 million. The Singapore-based payment provider identified the incident on July 25, 2026, but has not disclosed a final loss figure.

The company said the incident has been contained and all services are operating normally. Client funds were not affected because Triple-A does not custody digital assets for customers, while client money is held separately through trust accounts maintained with safeguarding institutions.

Stolen Assets Were Consolidated on Ethereum

On-chain investigators traced suspicious outflows across Ethereum, TRON, Polygon, Arbitrum, Solana and TON. Specter first flagged movements involving Triple-A-linked wallets, while PeckShield placed the initial drain above $9.7 million and identified approximately 5,227 ETH consolidated on Ethereum.

The attacker appears to have swapped stablecoins and other liquid assets before bridging the proceeds to Ethereum. Consolidating assets from several networks into ETH simplified the fund structure and created a single destination for investigators to monitor.

The transaction pattern points toward a compromise of wallet access or operational credentials rather than a confirmed smart contract vulnerability. Triple-A has not yet explained how the unauthorized access occurred, so the root cause remains under forensic investigation.

Security tracking also indicated continued activity involving affected wallet infrastructure after the first major outflows. Triple-A has not published a wallet-by-wallet reconciliation or addressed whether newly arriving operational funds were exposed before the infrastructure was fully secured.

Triple-A Says Treasury Will Absorb the Loss

Triple-A placed certain services into maintenance mode for approximately three hours while securing the affected systems and completing security checks. Transactions and settlements have since resumed across all of the company’s markets.

The company described the financial impact as limited to specific operational accounts containing treasury assets. It said it remains well capitalized, can meet its liabilities and will absorb the loss through its own treasury reserves rather than passing it to clients.

The affected wallets were operated by Triple A Technologies Pte. Ltd., the company’s Singapore entity. Triple-A said no other group entities or operations were affected by the breach.

The company is working with cybersecurity specialists, blockchain forensic investigators and the Singapore Police Force to trace the assets and support recovery efforts. It has not disclosed whether any stolen funds have been frozen or recovered.

The incident represents a multichain treasury and wallet-security failure rather than a loss of safeguarded client funds. The next critical disclosures will be the final loss calculation, the method of unauthorized access, the scope of any recovered assets and the security changes applied to Triple-A’s operational wallets.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.