Loading live prices...

Triple-A's $11.8M Weekend: The Hot Wallet That Wouldn't Stop Leaking

For many financial institutions, a hack is a one-time occurrence: transaction processed, money lost, damage done. The breach involving Singapore-based crypto payment company Triple-A has differed from most breaches not only due to its extent – new money kept flowing into the compromised wallets and right back out for over an entire day after the breach was first spotted by researchers – by the time the company made its first public announcement, it was already public knowledge that the losses had already surged from an initial $9.3 million to nearly $12 million.

A cracked red Triple A logo surrounded by Ethereum and Solana tokens under red lighting.
Daniel Mercer
Written by Daniel Mercer
Updated Jul 28, 2026 4 min. read
|

A Breach That Outpaced Its Own Headlines

Late on July 24, the warning bells started ringing when the blockchain investigator Specter noticed unusual outflows from the wallets linked to Triple-A, estimating approximately $9.3 million had already been swapped and sent to Ethereum. A few hours later, the security firm PeckShield confirmed the activity and raised the estimated amount to approximately $9.7 million.

This was going to be just another crypto hack headline, but the amount of money reported was still rising. On Sunday, Specter reported that another $1.8 million or so was gone from the wallets of Bitcoin and TRON networks, and that brought the total loss to approximately $11.8 million about 31 hours after the start of the outflows. Bitcoin hadn’t even been named as an affected chain in the earlier reports; only TRON, Ethereum, TON, and Solana had. More than anything, the growing chain list demonstrated that the authorities were still observing the breaking news as it was happening rather than treating it as an isolated event.

According to one of the most important discoveries resulting from investigators’ on-chain activities, the wallets subjected to the attack continued receiving transactions even after the attack started, with the amount of money in those wallets going down as fast as it appeared. This indicates a much more complex situation than just a key being compromised, where the access was not immediately cut off and normal transactions kept feeding the exposed wallet.

Tracking the Money

Whoever was responsible for this operation did not use six different tokens across six different networks. The information that was analyzed indicated that the stolen assets were transferred and exchanged to a single Ethereum address, which resulted in the accumulation of around 5,227 ETH (worth around $9.7 million at the time of the instant, until the losses in Bitcoin and TRON were included in the amount). At around 7 hours, on July 24 and 25, eight different incoming transactions were processed, during which the largest amount deposited totaled about 4,140 ETH.

At this moment in the timeline, neither Triple-A nor the investigating team had said a word about the event, whether any suspects were identified. There were no public reports that the combined ETH went to any crypto exchange or mixing company.

Triple-A Finally Speaks, And Draws a Sharp Line

Roughly two days after the first alerts, Triple-A broke its silence with an official statement acknowledging unauthorized access to wallets holding the company’s own digital assets. The framing was deliberate: this was described as a treasury event, not a customer-custody event.

According to the company, it detected the intrusion on July 25. It responded by pulling some services into maintenance mode for about three hours while it locked down the affected infrastructure, services it says have since been fully restored, with transactions and settlements processing normally worldwide.

As Triple-A claims, it does not control the property of its clients. Since the money is safely stored in separate accounts of different banks, there has been no damage to customers because they had nothing to do with the crime. The company adds that any financial consequences of the incident will be absorbed by its treasury and that it has enough capital to pay off all liabilities.

One main point missing from the statement is that Triple-A did not mention how much was stolen, how fraudsters committed their crime, and when the investigation process will finish. Although it has hired forensic experts and notified the police, there is still no information on whether any amount of stolen funds is available.

The Context on Regulations

Triple-A is not an unknown offshore player. It is a licensed Major Payment Institution by Singapore’s Monetary Authority, has received further authorization by its French branch Paytop SAS, and has money-services-business registration in both the USA and Canada. The rules on payment services in Singapore were enacted in October 2024 and require licensed digital payment token providers to keep customer funds either in trust accounts or at blockchain addresses not used by the companies themselves. Provided, of course, that Triple-A’s version of events is true, it is precisely the reason why the clients’ funds did not get affected.

On the other hand, it is a different story whether such a framework can allay worries of the regulators and merchant partners in the future, which are questions to be raised by the Monetary Authority and its colleagues from abroad when they analyze the incident.

Not an Isolated Incident

The incident involving Triple-A happened during a string of unfortunate events in crypto security. Just days before, an Arbitrum-based project named AFX Trade lost around $24 million in USDC via its custody bridge, and in another misfortune for the Verus-Ethereum Bridge, it lost around $7.5 million in its second hack since May. The analysis conducted by researchers who monitor DeFi hacking incidents indicates a total of nearly $630 million in losses in the industry in the first 7 months of the year 2026, related to compromised credentials.

This incident is a part of the trend that shows the way. Cold storage is offline vaults designed to store the majority of a company’s assets and largely work as described. Hot wallets are assets that stay online to facilitate quick transactions and remain the weak point for stealing money from companies connected to the internet.

What Happens From Here

The open inquiries are the unanswered ones by Triple-A: what permitted the breach in the first place, if there was a private key compromise or some type of insider mistake, and the size of the eventual loss figure once the company discloses real numbers instead of estimated ones. For merchants using Triple-A’s terminals, everything that matters in the news is whether client money is kept separately and safeguarded.

Crime Hacks & Exploits Security
Daniel Mercer
Daniel is an experienced author with a background in financial journalism. He writes about digital assets and crypto with a focus on clear, risk-aware explanations rather than hype, approaches price predictions cautiously and prioritises verifiable facts over exaggerated market expectations. When sharing cryptocurrency research and news, exchange reviews, and crypto gambling articles, Daniel's aim is to highlight topics that might not receive the attention they deserve, such as fees, custody, proof of reserves and more. His articles here on TradeBlock are intended for informational purposes only and do not constitute financial advice.