Triple-A hot wallets drained of $9.7M across six chains

Peckshield reports Triple-A lost about $9.7 million from hot wallets on July 24–25; attacker swapped assets on DEXs and bridged funds into one Ethereum address holding ~5,227 ETH.

Security service Peckshield reported that Triple-A, a Singapore-based fiat-to-crypto payment gateway, had about $9.7 million removed from its hot wallets on July 24 and July 25. Onchain investigator Specter first flagged the activity and Peckshield published an alert after reviewing transaction data.

Wallets tied to Triple-A were drained on Ethereum, Tron, Polygon, Arbitrum, Solana and The Open Network (TON). The attacker converted stolen stablecoins and other liquid tokens on several decentralized exchanges, then moved the proceeds through cross-chain bridges into Ethereum. The funds were consolidated in a single address beginning with 0x01F8, which held roughly 5,227 ETH as of the alert. The transfers arrived in multiple tranches rather than a single lump sum.

Triple-A operates payment infrastructure that lets merchants accept cryptocurrency and settle in fiat. The platform keeps hot wallets online to process transactions quickly and hold a rotating pool of customer funds and liquid stablecoins for settlements. Hot wallets remain connected to the internet for speed, which exposes them to higher risk than offline cold storage.

More than eight hours after the breach was first reported, Triple-A had not issued a public statement acknowledging the incident or describing whether customer funds were affected. The lack of an official response leaves questions about whether merchants experienced settlement interruptions and whether the company has reserves to cover any losses.

Security analysts described the transfer pattern as consistent with prior incidents: attackers convert assets across chains, use decentralized platforms to obscure transaction paths, then regroup funds in Ethereum before attempting further laundering. Peckshield previously reported a similar consolidation that moved about $5.25 million from Hedera to Ethereum a few weeks earlier. In May, the Gravity Bridge lost $5.4 million in a separate incident that involved routing stolen assets through centralized platforms.

Industry data cited by security firms show the sector lost $75.87 million to 40 hacks in June, with hot wallet compromises among the common attack types along with smart contract bugs and private key leaks.

Researchers and onchain trackers are monitoring the consolidated Ethereum address for activity that might move funds to centralized exchanges or mixing services. Interaction with platforms that enforce compliance could allow investigators or compliance teams to flag or freeze the assets. Further updates are expected as security teams trace transactions and if Triple-A issues a formal response explaining the scope of the breach and remedial steps.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author