Go to app

Incident Summary

Published 7/27/2026, 10:41:03 PM

Triple-A, a Singapore-based crypto payment gateway, suffered a hot wallet exploit between July 24 and July 25, 2026, resulting in a loss of approximately $11.8 million to $12 million. The attack was notable for its persistence, lasting over 31 hours as the attackers continued to "sweep" new merchant deposits in real-time across seven different blockchain networks.

Incident Summary

The losses were absorbed entirely from Triple-A's treasury and operational reserves; customer funds remained safe as they are held in segregated trust accounts per Monetary Authority of Singapore (MAS) regulations.

MetricDetails
Total Estimated Loss~$11.8M – $12M
Primary Assets Stolen~5,227 ETH (consolidated value) + ~$1.8M in BTC/TRX
Chains AffectedEthereum, TRON, Polygon, Arbitrum, Solana, TON, Bitcoin
Primary Attacker Address0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1
Attack Duration31+ hours

How the Funds Were Lost

The exploit followed a sophisticated multi-stage process involving cross-chain drainage and consolidation:

  1. Initial Breach: Attackers gained unauthorized access to Triple-A's hot wallet infrastructure. While the exact technical mechanism has not been publicly disclosed, security researchers suggest the breach likely involved compromised private keys, API exploitation, or a vulnerability in the wallet management layer.
  2. Multi-Chain Drainage: Funds were simultaneously drained from wallets across seven different blockchains. A critical failure in the incident response allowed the attackers to continue "sweeping" new incoming merchant settlements for over a day after the initial breach was detected.
  3. Swapping and Bridging: Stolen assets were converted into liquid tokens (primarily stablecoins) via decentralized exchanges (DEXs) and subsequently bridged to the Ethereum network.
  4. Consolidation: The proceeds were concentrated into a single Ethereum address (0x01F8...53b1), which eventually held approximately 5,227 ETH.

Technical Context and Detection

Triple-A utilizes Fireblocks for its MPC-based custody. However, both Triple-A and independent security researchers have stated that the Fireblocks platform itself was not compromised [Note: not independently confirmed]. The breach is believed to have occurred at the application or credential level where Triple-A managed its own keys or API access.

The exploit was first flagged by independent on-chain analyst Specter and security firm PeckShield on July 24/25. Triple-A did not officially confirm the "unauthorized access" until July 27, roughly 35 hours after the initial alerts were raised by the security community. Services were reportedly fully restored following a three-hour maintenance window on July 25 [Note: not independently confirmed].