Wallets tied to Singapore-based payments firm Triple-A were drained of more than $9.7 million across six blockchains, according to on-chain analyst Specter and blockchain security firm PeckShield, while Triple-A itself had not confirmed the breach or disabled deposits.
On-chain analyst Specter first flagged suspicious transactions involving wallets attributed to Triple-A, with blockchain security firm PeckShield subsequently amplifying the warning. The reported activity involved assets moving out of wallets across multiple networks before being swapped, bridged and consolidated on Ethereum.
The receiving Ethereum address was reported to hold roughly 5,227 ETH, with the value of the consolidated funds hovering around $9.7 million at the time of reporting. The exact loss remains unverified, however, because Triple-A had not publicly confirmed the incident or provided a forensic explanation.
Triple-A wallets show suspicious multichain outflows
The Triple-A crypto hack was initially estimated at more than $9.3 million before subsequent blockchain tracking pushed the suspected total beyond $9.7 million.
The transfers reportedly affected wallets associated with Ethereum, Solana, TRON and TON. Additional reporting identified activity involving Polygon and Arbitrum, potentially bringing the number of affected networks to six.
The suspected attacker appears to have targeted liquid assets held in hot wallets — blockchain-connected wallets designed to facilitate rapid transactions. After assets were removed, they were reportedly swapped and moved between networks before being consolidated on Ethereum.
Specter warned that the situation could be especially serious if deposits remained active while the suspicious activity was underway. “It looks like the team are not aware as deposit are not disabled and every new deposit is being drained,” the analyst said in a post cited by BeInCrypto.
That observation has intensified questions about Triple-A’s incident response, although it does not establish exactly how the wallets were compromised or whether the suspected attacker retained access.
Triple-A had not publicly confirmed the breach at the time of reporting. The company had also not disclosed whether the affected crypto belonged to Triple-A itself, its corporate customers or payment recipients. As a result, the incident is more accurately described as a suspected hot-wallet compromise rather than a confirmed protocol exploit.
Stolen crypto converges on Ethereum
The most visible development in the Triple-A crypto hack investigation is the movement of the suspected stolen assets into a single Ethereum wallet.
Blockchain researchers tracking the transfers reported that the assets were swapped and bridged to Ethereum before being consolidated. PeckShield said the destination wallet contained approximately 5,227 ETH.
One report tracking the address identified a series of large ETH deposits, including a transfer of more than 4,000 ETH, followed by several smaller deposits. The consolidation makes the flow of funds easier to monitor because assets originating from different networks can ultimately be tracked from one Ethereum address.
There is still no publicly established identity for the suspected attacker. Researchers have also not confirmed that the funds were deposited into a centralized exchange, mixer or other cash-out service.
The difference between early estimates and later figures should also be treated cautiously. A suspected loss can change as investigators identify additional transactions, while the dollar value of ETH and other crypto assets fluctuates. A definitive figure will require Triple-A or an independent forensic investigation to identify every affected wallet and reconcile the assets involved.
Why the incident matters for stablecoin payments
The Triple-A crypto hack carries significance beyond the immediate dollar figure because Triple-A sits at the intersection of cryptocurrency and traditional payments.
Triple-A provides infrastructure for businesses to accept, send and settle digital currencies and stablecoins. Its services include merchant payments, business payouts and cross-border settlement. The company says its operations span the United States, Europe, Singapore and Canada.
Triple-A Technologies Pte. Ltd. holds a Major Payment Institution licence from Singapore’s Monetary Authority of Singapore, while its U.S. entity is registered with FinCEN and licensed as a money transmitter in various states. Its European business is licensed as a payment institution and registered as a crypto-asset service provider in France.
The company also announced in March that it had integrated with Circle Payments Network to support stablecoin-to-local-currency settlement for cross-border payments, including remittances, payroll and supplier payments.
That regulatory and payments footprint raises obvious counterparty questions. However, there is currently no evidence showing that U.S. customers suffered losses or that regulated payment operations were directly compromised.
Triple-A also publicly identifies Fireblocks as part of its digital-asset infrastructure. Fireblocks says its relationship with Triple-A supports wallet management, treasury operations and transaction policies. Crucially, neither the on-chain reports nor available reporting has attributed the suspected wallet compromise to Fireblocks, and there is no evidence that Fireblocks itself was breached.
Another cross-chain attack raises broader security concerns
The Triple-A crypto hack comes only days after another cross-chain security incident exposed weaknesses in infrastructure operating across multiple blockchain networks.
On July 17, an attacker targeted Risk Labs’ Solana relayer infrastructure used by Across Protocol by fabricating 1,627 deposit events with a combined face value of about $41.7 million. The relayer processed 581 of the fraudulent requests before Solana operations were halted. The resulting loss was reported at less than $4 million after accounting for funds that remained trapped.
The incidents do not appear to be connected, and the technical mechanisms are different. Across involved forged off-chain deposit events, while the Triple-A case currently appears to involve suspicious outflows from hot wallets.
Still, the timing highlights a growing challenge for crypto payment companies: operating across several blockchains expands the number of wallets, signing systems, bridges, monitoring tools and operational controls that must work together securely.
For Triple-A, the next stage will be critical. The company will need to establish the precise amount lost, identify the affected wallets and assets, explain how access was obtained and determine whether customer funds were involved.
Until that information emerges, the Triple-A crypto hack remains a suspected compromise rather than a confirmed breach. But the reported $9.7 million drain is already a significant warning for the rapidly expanding stablecoin payments industry: connecting crypto rails to mainstream finance does not eliminate wallet security risks — it can make effective custody, transaction monitoring and rapid incident response even more important.