Triple-A Hot Wallets Reportedly Lose More Than $9.7 Million in Suspected Cross-Chain Exploit
Key Takeaways
- •Researchers estimate the suspected loss from Triple-A-linked hot wallets at more than $9.7 million.
- •Suspicious transfers reportedly involved Ethereum, Solana, TRON and TON, with Polygon and Arbitrum also cited in some reports.
- •The suspected attacker consolidated the proceeds into about 5,226.66 ETH on Ethereum.
- •Triple-A had not confirmed the incident or disclosed whether customer assets were affected at the time of writing.
- •No available evidence has linked the suspected breach to Fireblocks or shown that its custody technology was compromised.

Triple-A-controlled hot wallets appear to have lost more than $9.7 million across multiple blockchains, with the suspected attacker swapping the assets and consolidating the proceeds on Ethereum, according to on-chain analysts and blockchain security researchers.
Suspicious outflows reportedly affected at least four networks, including Ethereum, Solana, TRON and TON. Some reports also pointed to transactions involving Polygon and Arbitrum, which could expand the incident to six networks.
The suspected attacker consolidated the proceeds into approximately 5,226.66 ETH on Ethereum. Triple-A had not confirmed the breach at the time of writing and had not disclosed whether customer funds were affected.
Suspicious activity identified in Triple-A hot wallets
On-chain analyst Specter first flagged suspicious transactions involving hot wallets linked to Triple-A, a Singapore-based provider of stablecoin payment infrastructure.
Hot wallets are internet-connected wallets typically used for operational liquidity, including deposits, withdrawals and payments. That makes the distinction between a wallet compromise and a protocol-level exploit important, because the affected controls, counterparties and recovery options can differ.
Specter initially estimated that more than $9.3 million had been removed, swapped and transferred across chains to Ethereum. Blockchain security firm PeckShield later amplified the alert, while subsequent estimates put the suspected loss above $9.7 million.
There appear to be ongoing wallet draining involving @TripleH hot wallets across multiple chains, including TRON, Ethereum, TON, and Solana. So far, more than $9.3M has been drained, swapped, and bridged to Ethereum. The funds are currently being consolidated here: Ethereum… pic.twitter.com/pLKvVwMWav — Specter (@SpecterAnalyst) July 24, 2026
https://x.com/SpecterAnalyst/status/2080764538874462386?ref_src=twsrc%5Etfw
The activity reportedly involved Triple-A wallets operating on Ethereum, Solana, TRON and TON. Additional reports cited possible activity on Polygon and Arbitrum, though Triple-A had not publicly confirmed the scope of affected networks.
The company also had not disclosed when the suspicious activity began, how the wallets were accessed, or whether the affected assets belonged to Triple-A, its business customers or payment recipients.
In the absence of a company statement or a completed technical investigation, the incident remains a suspected hot-wallet compromise rather than a confirmed protocol exploit.
Assets were bridged and consolidated on Ethereum
On-chain data cited by security researchers indicated that the transferred assets were exchanged and bridged to Ethereum after leaving the affected wallets.
The receiving address reportedly held about 5,226.66 ETH, valued at approximately $9.7 million at the time of the alert. Consolidating assets into Ether can make a mix of stablecoins and network-specific tokens easier to move from one address.
Researchers have not publicly identified the suspected attacker. They also have not established whether the receiving address is linked to previous exploits. No report has confirmed that the funds moved into an exchange, mixer or other service after reaching Ethereum.
The gap between Specter’s initial estimate of more than $9.3 million and later figures above $9.7 million may reflect additional transfers or changes in Ether’s market value. A verified loss figure will depend on Triple-A identifying every affected wallet and transaction.
Triple-A’s payments role adds regulatory and counterparty questions
Triple-A provides infrastructure that allows companies to collect, convert and send payments through stablecoins and traditional banking networks. Its services include merchant checkout, business payments, local payouts and cross-border settlement.
For a payments company, the source and ownership of assets in operational wallets can determine whether an incident is limited to treasury funds or affects merchants, payment flows or settlement obligations. Those details had not been disclosed at the time of writing.
The company says it operates as a licensed financial institution in the United States, Europe and Singapore. Triple-A also holds a Major Payment Institution licence from the Monetary Authority of Singapore and joined Circle Payments Network in March to support stablecoin-to-local-currency settlement.
Triple-A’s U.S. presence gives the incident a potential regulatory and counterparty dimension, although there is no evidence that American customers or companies suffered losses. Any U.S. impact will depend on which entity controlled the wallets, who owned the assets and whether regulated payment operations were involved.
Triple-A uses Fireblocks as part of its digital-asset infrastructure. However, neither on-chain researchers nor Triple-A have attributed the suspected breach to Fireblocks, and no available evidence indicates that the custody technology provider was compromised.
Incident follows a separate cross-chain attack
The suspected Triple-A breach follows another recent incident involving cross-chain infrastructure. As crypto.news reported, an attacker fabricated 1,627 Solana deposit events targeting Across Protocol’s Risk Labs-operated relayer on July 17.
Those false deposits requested $41.7 million in payments across 18 destination chains. Risk Labs’ relayer filled 581 requests before Across stopped its Solana operations, limiting the realized loss to less than $4 million, according to the protocol’s post-incident report.
The Across and Triple-A incidents do not appear to be connected. However, both cases involved activity spanning several networks, increasing the number of wallets, transaction systems and monitoring processes needed to detect suspicious transfers.
Triple-A has not yet said whether it has suspended deposits, withdrawals or cross-chain operations. The company’s next statement is expected to clarify the final loss, the affected assets, the source of the breach and whether customers will receive compensation.