Key Takeaways
- Approximately $9.7 million disappeared from Triple-A’s hot wallets spanning several blockchain networks
- The incident impacted Ethereum, Solana, TRON, and TON, with potential involvement of Polygon and Arbitrum
- The alleged perpetrator aggregated stolen assets into roughly 5,226.66 ETH on the Ethereum network
- Triple-A remains silent on breach confirmation and has not addressed customer fund security
- The Singapore-based firm holds payment licenses across the United States, European Union, and Singapore
A suspected security breach has placed Triple-A, a Singapore-headquartered stablecoin payment infrastructure provider, under scrutiny after blockchain analysts detected questionable withdrawals exceeding $9.7 million from its hot wallet infrastructure.
ā ļøALERT: Triple-A wallets are under an apparent active exploit with over $9.7M drained.
Onchain analyst Specter has flagged suspicious outflows from Triple-A hot wallets across TRON, Ethereum, Polygon, and Arbitrum, with the stolen assets consolidated into 5,227 ETH.
Triple-A⦠pic.twitter.com/1RykKuPGwA
ā Coin Bureau (@coinbureau) July 25, 2026
The suspicious transfers were initially identified by on-chain investigator Specter. Subsequently, blockchain security company PeckShield confirmed the findings, with loss estimates climbing from an original figure of $9.3 million to surpass $9.7 million.
Cross-Chain Asset Drainage Detected
The unauthorized withdrawals affected hot wallets operating on Ethereum, Solana, TRON, and TON blockchains. Additional analysis suggests Polygon and Arbitrum may also have been compromised, potentially expanding the affected networks to six distinct chains.
Following extraction from the original wallets, the stolen digital assets underwent conversion and cross-chain bridging operations to Ethereum. The destination wallet contained approximately 5,226.66 ETH when security researchers issued their initial warnings.
Converting stolen funds to ETH represents a standard tactic following multi-chain security incidents, as it simplifies the management and movement of diverse crypto assets through a single address.
The variation between initial and updated loss figures may stem from subsequent asset transfers or fluctuations in Ethereum’s market value.
Triple-A’s Business Model ā and Its Ongoing Silence
Triple-A delivers payment infrastructure enabling businesses to receive, exchange, and transmit funds through stablecoin technology and conventional banking channels. Its product suite encompasses merchant payment gateways, corporate payment solutions, and international remittance services.
The firm operates with regulatory authorization in the United States, European markets, and Singapore. It maintains a Major Payment Institution license granted by Singapore’s Monetary Authority and became a member of Circle Payments Network in March 2026.
Triple-A has issued no official acknowledgment of the security incident. The company has not revealed how unauthorized access occurred, when suspicious activity commenced, or whether client assets were compromised.
Triple-A utilizes Fireblocks for digital asset safeguarding. Current evidence does not suggest Fireblocks infrastructure was breached.
Perpetrator Unknown, Customer Communication Absent
Security analysts have not publicly named any suspected threat actor. No verification exists confirming the transferred funds entered cryptocurrency exchanges or mixing services following their consolidation on Ethereum.
In the absence of corporate disclosure or forensic analysis, this incident remains classified as a suspected hot wallet breach rather than a confirmed protocol-level vulnerability.
Triple-A has not announced whether deposit functions, withdrawal services, or cross-chain transaction capabilities have been paused.
This security event occurs separately from a July 17 attack in which a malicious actor generated 1,627 fraudulent Solana deposit records targeting Across Protocol. That earlier incident caused losses under $4 million after Across suspended Solana functionality. The two incidents have no established connection.
Stakeholders await Triple-A’s official response addressing the complete financial impact, the method of wallet compromise, and whether affected users will receive reimbursement.


