Singapore-based crypto payments firm Triple-A has suffered a multi-chain hot wallet breach between July 24 and July 25, 2026, resulting in Triple-A hot wallet losses now exceeding $9.7 million. On-chain investigator Specter initially flagged the suspicious activity, noting an unsettling detail: new deposits were still being siphoned from the compromised addresses even after the initial discovery.
This ongoing drainage highlights a critical security challenge for the regulated entity. It raises questions about the efficacy of Triple-A’s real-time monitoring and its ability to halt the flow of funds to compromised wallets promptly, an issue that can profoundly impact user trust and operational integrity.
Tracing the multi-chain hot wallet losses
The financial impact of the Triple-A hot wallet losses has grown since Specter first reported the incident on Friday, July 25, 2026. Initially, Specter estimated more than $9.3 million in drained assets. Blockchain security firms PeckShield and Lookonchain quickly corroborated these reports, providing further insights into the attacker’s methods.
The affected wallets spanned multiple blockchains, including TRON, Ethereum, Polygon, Arbitrum, Solana, and The Open Network (TON). Attackers employed a calculated strategy, rapidly swapping stolen stablecoins and other liquid assets on decentralized exchanges. They then bridged these converted assets to the Ethereum network.
These proceeds were ultimately consolidated into a single Ethereum address, 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1. PeckShield’s analysis indicated this address held approximately 5,226.67 ETH, valued around $9.73 million at the time. Eight incoming transfers were identified to this address between 8:35 p.m. UTC on Friday and 3:03 a.m. UTC on Saturday, with one transaction alone moving roughly 4,140 ETH.
New deposits still being swept from compromised addresses
Perhaps the most concerning aspect of the Triple-A hot wallet losses is the discovery that compromised wallets continued to be drained of new incoming deposits. Specter observed that funds were still flowing into these affected addresses and being swept by attackers more than 31 hours after the initial large outflows.
“It looks like the team are not aware as deposit are not disabled and every new deposit is being drained,” Specter posted on X. This suggests a significant gap in the firm’s security response or awareness. Such a prolonged vulnerability can severely amplify financial damage and erode confidence in a platform’s operational security.
Triple-A’s regulatory status and customer fund assurances
Triple A Technologies Pte. Ltd. is licensed by the Monetary Authority of Singapore (MAS) as a major payment institution. Its European arm, Paytop SAS, also holds payment institution and crypto-asset service provider licenses in France, with the group registered as a money services business in the U.S. and Canada.
On Saturday, Triple-A addressed the reports on X, stating, “We’re actively investigating the situation and will share a formal update once ready. We confirm that customer funds are not impacted.” However, as of July 27, 2026, no formal update has been published in its newsroom.
Regulatory frameworks in Singapore, effective since October 4, 2024, mandate licensed digital payment token service providers safeguard customer assets in trust accounts, separate from their own holdings. The lack of transparency regarding the affected wallets’ contents and the ongoing drain raises questions, despite Triple-A’s assurance that customer funds are unaffected.
Broader implications for hot wallet security
The incident with Triple-A underscores the persistent challenge of hot wallet security in the crypto industry. Hot wallets, by their internet-connected nature, are inherently more susceptible to attacks. Their compromise frequently leads to rapid asset exfiltration across various chains, as seen in this multi-chain breach.
This event follows other significant exploits this week, including AFX Trade’s loss of about $24.15 million in USDC and the Verus-Ethereum bridge’s loss of roughly $7.54 million. These incidents highlight that maintaining robust security and ensuring rapid incident response are paramount for regulated entities and the broader digital asset ecosystem.
