NewsCryptoTriple-A Suffers Suspected $9.7M Hot Wallet Exploit Across Multiple Blockchains

Triple-A Suffers Suspected $9.7M Hot Wallet Exploit Across Multiple Blockchains

Author: LiveBitcoinNews·

Key Takeaways

  • •Triple-A, a Singapore-based crypto payment provider, experienced a suspected hot wallet exploit that drained over $9.7 million in digital assets across multiple blockchain networks.
  • •Security firms Specter and PeckShield traced the compromise across TRON, Ethereum, Polygon, and Arbitrum, with additional on-chain activity linked to Solana and TON.
  • •The attacker swapped stolen assets through decentralized exchanges before bridging them to Ethereum and consolidating roughly 5,227 ETH into a single wallet address.
  • •Triple-A had not released an official statement as of publication, leaving unclear whether customer funds, business reserves, or operational assets were affected.
  • •The suspected exploit occurred during a week that saw multiple other major crypto attacks, including incidents involving AFX Trade, the Verus Ethereum Bridge, and B2 Network.
Triple-A Suffers Suspected $9.7M Hot Wallet Exploit Across Multiple Blockchains

Triple-A, a Singapore-based crypto payment infrastructure provider that enables businesses to accept cryptocurrency payments, has reportedly suffered a suspected hot wallet exploit that drained more than $9.7 million across multiple blockchain networks.

Blockchain security firms and on-chain analysts reported that stolen assets were rapidly swapped, bridged to Ethereum, and consolidated into a single wallet. The breadth of chains involved — spanning EVM and non-EVM networks — highlights the elevated risk multi-chain payment operators face, as a single compromised key set can expose treasury across disparate ecosystems simultaneously. At the time of publication, Triple-A had not issued an official statement confirming the incident or clarifying whether customer funds, business reserves, or operational assets were affected. For merchants and partners relying on Triple-A's rails, the lack of clarity on fund attribution leaves open the question of whether settlement operations could be disrupted.

Security Researchers Trace Funds Across Multiple Networks

On-chain analyst Specter first identified suspicious transactions involving wallets linked to Triple-A. The analyst's initial estimate placed losses above $9.3 million before subsequent updates pushed the suspected total beyond $9.7 million.

Blockchain security firm PeckShield later corroborated the findings, reporting that attackers had drained crypto assets from hot wallets operating across TRON, Ethereum, Polygon, and Arbitrum. Earlier on-chain tracking also linked the suspicious activity to Solana and TON, suggesting the compromise may have spanned multiple blockchain ecosystems.

According to investigators, the attacker rapidly swapped the stolen assets before bridging them to Ethereum. The funds were then consolidated into a single Ethereum address holding approximately 5,227 ETH, valued at roughly $9.7 million at the time of the incident.

#PeckShieldAlert Specter has reported that @TripleAHQ wallets appear to have been drained of more than $9.7M worth of crypto across multiple chains, including #TRON, #Ethereum, #Polygon, and #Arbitrum. The exploiter bridged the stolen funds to Ethereum. 5,227 $ETH is currently… pic.twitter.com/JxCr79V2db

— PeckShieldAlert (@PeckShieldAlert) July 25, 2026

Security researchers also identified several additional wallet addresses connected to the transfers. However, they have not publicly attributed the attack to any known hacking group or linked the destination wallets to previous exploits.

Incident Adds to a Growing Series of Crypto Security Breaches

The suspected exploit underscores persistent security challenges surrounding hot wallets, which remain connected to the internet to facilitate faster transaction processing. While these wallets enhance payment efficiency, they also present a broader attack surface compared to offline storage solutions.

Researchers believe the attacker likely gained unauthorized access to Triple-A's hot wallet infrastructure before moving liquid assets through decentralized exchanges. Consolidating the proceeds into Ethereum could simplify future transfers and streamline asset management for the attacker.

The discrepancy between the initial $9.3 million estimate and the later $9.7 million figure may reflect additional transfers recorded after the first alert, or it may result from fluctuations in Ethereum's market price during the course of the investigation.

The incident follows several other major crypto exploits reported during the same week, including attacks on AFX Trade, the Verus Ethereum Bridge, and B2 Network. Although investigators have found no evidence connecting those incidents, the latest attack reinforces mounting concerns over cross-chain security and digital asset custody.

Triple-A is expected to disclose additional details upon completing its internal investigation. Until then, the exact cause of the suspected exploit and the full financial impact remain unconfirmed.