TL;DR

  • Triple-A lost an estimated $11.8 million in a hot wallet incident tracked across multiple blockchains.
  • Investigators observed deposits continuing to reach affected wallets and being swept for at least 31 hours after the first transfers.
  • Triple-A said the loss involved treasury assets, not client funds, but key details including access method and final loss remain undisclosed.

Crypto payments company Triple-A lost an estimated $11.8 million from its hot wallets in an incident first flagged by blockchain investigator Specter on July 24. Deposits kept arriving at the affected wallets and being swept for at least 31 hours after the first unauthorized transfers. Triple-A has since said the loss hit company treasury assets, not client funds. However, the access method and a final confirmed loss figure remain undisclosed.

What investigators tracked, July 24–26

Specter first reported the activity at 5:18 p.m. ET on July 24, saying more than $9.3 million had been taken, converted and bridged to Ethereum. PeckShield followed roughly four and a half hours later, raising the estimate above $9.7 million. It identified activity across Ethereum, TRON, Polygon, Arbitrum, Solana and The Open Network. PeckShield’s alert included a snapshot of eight transfers reaching a single Ethereum address between 20:35 UTC on July 24 and 03:03 UTC on July 25. It held 5,226.67 ETH, then valued at about $9.73 million.

By July 26, Specter had added Bitcoin to the list of affected networks, attributing another $1.8 million in losses to Bitcoin and TRON. That brought the estimated total to approximately $11.8 million. The investigator also reported that new deposits were still reaching the affected wallets and being swept 31 hours after the first large outflows appeared.

Triple-A’s only public comment during this window came on July 25, when the company told reporters it was actively investigating the wallet incident. At the time it assured that the attack had not affected customer funds. It did not elaborate on what the wallets held, how access had occurred, or whether the activity had stopped. The loss figures are based on on-chain tracking and not a confirmed company accounting. Triple-A has not confirmed the loss estimate or published a list of affected addresses.

Triple-A’s account, July 27

Roughly 35 hours after Specter’s initial alert, Triple-A published a newsroom statement addressing the wallet incident directly. The company said the affected wallets held its own treasury assets and no client funds. Client funds, it said, are held separately in trust accounts that were not exposed, consistent with Singapore’s rules requiring licensed digital payment token providers to safeguard customer assets apart from company holdings. Triple A Technologies Pte. Ltd., the company’s Singapore entity, holds a major payment institution licence from the Monetary Authority of Singapore.

The statement also said the company detected unauthorized access on July 25. Subsequently, it placed some services into maintenance mode for about three hours while securing the affected infrastructure. Once it completed additional security checks, normal processing resumed. Triple-A said it is working with cybersecurity firms and the Singapore Police Force, and that it remains well-capitalized and able to meet its liabilities. The financial impact would be absorbed through treasury reserves.

The statement did not disclose a specific loss figure, wallet addresses, or how the unauthorized access occurred.

Where the two accounts do not line up

Triple-A’s description of a three-hour maintenance window on July 25 sits awkwardly next to Specter’s report of deposits still being swept 31 hours later, into July 26. Businesses often continue sending funds to previously issued deposit addresses until those addresses are replaced. If a compromised address remains active, additional deposits can keep reaching an attacker well after the initial breach has been identified and contained elsewhere.

Pausing certain services is not the same as disabling on-chain deposit addresses. Also, Triple-A has not specified which systems underwent the maintenance period or whether it rotated any deposit addresses. The two timelines are not necessarily contradictory, since a brief pause to secure core infrastructure would not automatically stop funds from landing on addresses still in circulation. But nothing in Triple-A’s statement accounts for the extended sweep Specter described, and the company has not addressed the gap directly.

Still open

Several questions remain unanswered. Triple-A has not disclosed whether stolen credentials, compromised private keys or another failure allowed the transfers, nor has it published a final loss figure or the specific wallet addresses involved. It has also not said whether any exchanges or stablecoin issuers froze funds linked to the incident, or whether it recovered any assets.

As of publication, two days after Triple-A’s July 27 statement, no further update has confirmed whether the sweeping of new deposits described by Specter has stopped.

LEAVE A REPLY

Please enter your comment!
Please enter your name here