Triple-A Crypto Wallet Hack Losses Rise to $11.8 Million as More Funds Are Drained
Key Takeaways
- •Estimated losses from the suspected Triple-A wallet compromise have risen to about $11.8 million.
- •Specter reported that attackers stole another $1.8 million across Bitcoin and TRON after the initial suspicious transfers.
- •Affected networks previously included Ethereum, TRON, Polygon, Arbitrum, Solana, and The Open Network, with Bitcoin added after the latest findings.
- •PeckShield said stolen assets were gathered in one Ethereum wallet that temporarily held 5,226.67 ETH, worth about $9.73 million.
- •Triple-A said it has opened an investigation and maintained that customer funds were not affected.

Losses tied to the suspected compromise of Triple-A’s crypto wallets have risen to about $11.8 million after attackers continued draining newly deposited funds across multiple blockchain networks.
According to on-chain investigator Specter, the exploit widened beyond the initial theft, with additional assets disappearing more than 31 hours after the first major suspicious transfers. Specter reported that another $1.8 million was stolen across the Bitcoin and TRON networks, pushing total losses above earlier estimates.
Previous reporting had linked the attack to Ethereum, TRON, Polygon, Arbitrum, Solana, and The Open Network. Bitcoin was added to the list of affected networks only after the latest findings.
Blockchain security firm PeckShield also cited Specter’s investigation while monitoring the incident. According to PeckShield, the stolen assets were consolidated into a single Ethereum wallet that temporarily held 5,226.67 ETH, worth roughly $9.73 million. Specter also said new deposits were still arriving in the compromised wallets, allowing the attacker to continue draining incoming funds.
The continued movement of assets is significant because payment processors can receive deposits across several chains as part of normal merchant operations. When wallet infrastructure is compromised, investigators typically look not only at the initial outflow but also at whether deposit addresses remain active, whether funds are being swept into attacker-controlled wallets, and whether affected systems have been fully isolated.
Triple-A says customer funds were not affected
Triple-A addressed the incident in a post on X, confirming that it had opened an investigation into the wallet compromise. The company said it would issue a formal update after completing its review and emphasized that customer funds were not affected by the attack.
The company did not identify the assets held in the compromised wallets. However, it reiterated that customer holdings remained protected.
Triple-A operates under a Major Payment Institution license issued by the Monetary Authority of Singapore. The company processes stablecoin payments for merchants that settle in local currencies. Its European subsidiary, Paytop SAS, holds payment institution and crypto-asset service provider licenses in France, while the company also maintains money services business registrations in the United States and Canada.
Singapore’s Payment Services Regulations require licensed digital payment token providers to separate customer assets from company holdings. That distinction is central to Triple-A’s public statement that customer funds were not affected, but the company has not yet published the promised incident report in its newsroom.
The next key disclosures are likely to be the company’s explanation of which wallets were compromised, whether the affected addresses have been replaced or disabled, and how it is preventing further deposits from reaching attacker-accessible wallets.
The case adds to a series of major crypto security breaches. AFX Trade recently lost $24.15 million through an Arbitrum bridge exploit, while the Verus-Ethereum bridge suffered another attack that caused losses of roughly $7.54 million.