Triple-A Wallet Breach:
$11.8M Drained Across Seven Chains
$11.8 million was reportedly drained from Triple-A treasury wallets across seven chains as incoming deposits were swept for 31 hours; client funds were unaffected.

- Incident Date: July 25, 2026
- Target: Triple-A
- Target Overview: Triple-A is a Singapore-based stablecoin payments provider serving more than 1,000 enterprise customers. Its official statement said the affected wallets belonged to Triple A Technologies Pte. Ltd. and held the company's own treasury assets.
- Total Loss: Approximately $11,800,000, based on public on-chain estimates; Triple-A did not disclose an official loss figure
- Reported Consolidation Address:
0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1 - Attack Vector: Unauthorized wallet access; suspected hot-wallet compromise with the root cause undisclosed
Incident Review & Technical Details
1. Attack Path
- Unauthorized Access Reached Triple-A-Operated Wallets: Triple-A said it identified unauthorized access on July 25, 2026, affecting certain wallets that contained company-owned digital assets. The company has not disclosed whether the initial access involved private keys, signer credentials, wallet-management infrastructure, an insider, or another control failure.
- Assets Were Swept Across Multiple Networks: On-chain reporting attributed outflows to wallets on Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and later Bitcoin. The complete victim-wallet and transaction set has not been published by Triple-A, so the seven-chain scope remains based on third-party tracing rather than a company-provided forensic ledger.
- The Proceeds Were Swapped and Consolidated on Ethereum: Specter and PeckShield reported that stolen assets were exchanged and bridged to Ethereum. CryptoSlate later counted 12 inbound transfers above 0.01 ETH into
0x01F8...53b1on July 24 and 25, totaling approximately 5,287.09 ETH; Triple-A has not publicly confirmed that address or attributed every transfer to the incident. - Continued Sweeps Raised the Estimate to $11.8 Million: The first public estimate exceeded $9.3 million, and PeckShield later reported more than $9.7 million. Specter subsequently attributed another $1.8 million of losses to Bitcoin and TRON activity and said new inflows were still being swept approximately 31 hours after the first large outflows, bringing the running estimate to about $11.8 million.
2. Impact Scope
- Treasury-Level Loss: Public on-chain estimates place the incident at approximately $11.8 million. Triple-A said the financial impact was limited to specific operational accounts and would be absorbed by its treasury reserves, but it did not publish its own valuation.
- Client Funds: Triple-A said client funds were not affected. According to the company, it does not custody digital assets for clients, and client money is held separately in trust accounts maintained with safeguarding institutions that were not exposed.
- Multi-Chain Exposure: Researchers reported affected activity across seven networks: Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin. This expanded the containment and tracing problem beyond a single wallet or chain.
- Operational Disruption: Certain Triple-A services entered maintenance mode for approximately three hours while the company secured the affected infrastructure and performed checks. Triple-A later said transactions and settlements had resumed normally across all markets.
- Ecosystem Contagion: The reviewed sources did not report client losses, payment-system insolvency, a stablecoin depeg, or losses at an underlying blockchain or bridge. The available evidence points to compromised Triple-A-operated accounts rather than a base-chain failure.
3. Official Statements
- Triple-A: In its official statement, Triple-A confirmed unauthorized access to company-operated wallets, said client funds and other group entities were unaffected, and stated that the incident had been contained. The company also said it remained able to meet its liabilities and was operating normally.
- Specter: The on-chain investigator first estimated more than $9.3 million in outflows and later raised the running total to approximately $11.8 million, reporting that incoming funds continued to be swept 31 hours after the first large outflows.
- PeckShield: PeckShield amplified the multi-chain tracing and reported that more than $9.7 million had been drained and bridged to Ethereum, where approximately 5,227 ETH was consolidated at the time of its alert.
4. Investigation Progress
Triple-A said it is working with internal and external cybersecurity specialists, blockchain-forensics providers, the Singapore Police Force, and other relevant authorities to investigate the incident, trace the affected assets, and support recovery efforts.
As of July 30, 2026, the reviewed public sources had not identified the initial access method, published the complete affected-wallet list, confirmed the consolidation address, disclosed a final company-calculated loss, or reported any recovered amount. They also did not establish that a wallet vendor, blockchain, bridge, or third-party custody platform was compromised. The distinction is important: unauthorized wallet access is confirmed, while the underlying security failure remains under investigation.
AUTOSEC.DEV Solution
The Triple-A incident shows why payment operators need both tightly bounded multi-chain wallet authority and a response plan capable of shutting down every exposed deposit route at once.
- Security Strategy & Planning — Triple-A-linked inflows were reportedly still being swept 31 hours after the first large outflows across a seven-chain footprint. AUTOSEC.DEV designs wallet-control architectures with segregated operational roles, per-wallet exposure ceilings, hardware-backed approvals, independent signer paths, automated anomaly thresholds, and circuit breakers that can disable deposits and rotate settlement routes across every supported network.
- Incident Response — The reported proceeds were converted across chains and concentrated into an Ethereum address while the loss estimate continued to rise. AUTOSEC.DEV supports rapid wallet quarantine, access and signer rotation, transaction and log preservation, cross-chain fund tracing, attacker-address labeling, and coordination with bridges, stablecoin issuers, exchanges, and law enforcement for freeze and recovery requests.