Triple-A-Linked Wallets Drained of More Than $9.7 Million Across Four Blockchains
Key Takeaways
- •More than $9.7 million was drained from wallets attributed to Triple-A across four blockchain networks before the assets were consolidated into 5,227 ETH.
- •The conversion to native ETH limits recovery options because ETH lacks the freeze or blacklist mechanisms available to stablecoin issuers.
- •Triple-A had not acknowledged the wallet movements, suspended services, or clarified whether the affected addresses handled treasury, payments, or customer funds at the time of publication.
- •Triple-A is regulated across Singapore, the European Union, and the United Arab Emirates, having recently secured MiCA authorization and in-principle VARA approval for broker-dealer services.
- •The incident follows three earlier attacks in the same week targeting AFX Trade, the Verus Ethereum Bridge, and B2 tokens, collectively involving bridges and project-controlled wallets.

Wallets attributed to stablecoin payments firm Triple-A were drained of more than $9.7 million across TRON, Ethereum, Polygon, and Arbitrum before the stolen assets were routed to Ethereum, according to onchain analysis.
Onchain analyst Specter traced the multichain outflows and linked the affected wallets to Triple-A. The stolen assets were moved through cross-chain bridges and ultimately consolidated into 5,227 ETH at an Ethereum address beginning with 0x01F8 and ending with 53b1. The transfers converged on that address after funds were moved out of wallets across all four networks. The conversion to native ETH limits recovery options because, unlike stablecoins such as USDC or USDT, which issuers can freeze at the smart contract level, native ETH has no comparable blacklist mechanism.
The affected wallet roles, ownership of the drained balances, and any potential exposure involving merchant settlement funds remain unconfirmed. No technical analysis has yet identified whether the transfers resulted from a private-key compromise, stolen signing credentials, or another type of breach of Triple-A's wallet infrastructure.
Triple-A Has Not Confirmed the Loss
Triple-A had not published a security notice or acknowledged the wallet movements at the time of publication. The company also had not announced any suspension of payments, withdrawals, or settlement services.
The Singapore-based company provides infrastructure that allows businesses to collect and send payments using stablecoins and local currencies. Its platform handles conversion and settlement without requiring merchants to manage crypto assets directly, meaning any disruption to its operational wallets could affect merchants who rely on the platform without holding crypto themselves.
Triple-A operates as a Major Payment Institution regulated by the Monetary Authority of Singapore. The company secured full MiCA authorization for digital asset services in the European Union last month. It also received in-principle approval from Dubai's Virtual Assets Regulatory Authority (VARA) on July 15 for broker-dealer services. The incident therefore involves an entity regulated across Singapore, the European Union, and the United Arab Emirates, each with distinct frameworks for digital asset custody and operational security.
The company has not clarified whether the affected addresses were used for treasury management, payment processing, customer deposits, or internal liquidity operations.
CryptoAdventure contacted Triple-A for confirmation of the wallet movements, the source of the breach, and any potential customer exposure. The company had not responded at the time of publication.
Drain Extends a Week of Crypto Losses
The Triple-A transfers follow three separate attacks disclosed earlier in the week, all involving bridges and project-controlled wallets.
AFX Trade lost 24.15 million USDC from its Arbitrum bridge after an unauthorized withdrawal cleared its validator threshold and dispute window. The attacker bridged the funds to Ethereum and exchanged them for approximately 12,467 ETH.
The Verus Ethereum Bridge was subsequently drained of approximately $7.54 million through a malicious import that released assets without matching deposits on the Verus network. In a separate incident, 8.59 million B2 tokens were drained and valued near $3.86 million before the assets were sold on BNB Chain.
Triple-A had not identified the compromised wallet tier, issued customer instructions, or disclosed a recovery process at the time of publication.