Triple-A Hot Wallets Drained of $9.7 Million Across Six Chains, Says Peckshield
Singapore-based fiat-to-crypto payment gateway Triple-A lost more than $9.7 million from its hot wallets across six blockchains on July 24 and July 25, according to blockchain security firm Peckshield.
Onchain investigator Specter first reported the breach. Peckshield later confirmed that wallets tied to Triple-A were drained across Ethereum, Tron, Polygon, Arbitrum, Solana, and The Open Network (TON).
Triple-A operates payment infrastructure that allows merchants to accept cryptocurrency and settle in fiat. Its hot wallets hold a rotating pool of customer funds and liquid stablecoins for fast transaction processing. Hot wallets are internet-connected, making them more vulnerable than offline cold storage.
Onchain data reviewed by security researchers shows the attacker swapped stolen stablecoins and other liquid assets on decentralized exchanges before bridging the proceeds to Ethereum. The funds were consolidated into a single address starting with 0x01F8, which held roughly 5,227 ETH (about $9.7 million) as of Saturday. The assets arrived in several tranches, a method consistent with past attackers who systematically convert assets across chains before regrouping them.
Peckshield has flagged similar bridge-to-Ethereum consolidation patterns before, including a suspected exploit of the Hedera network that saw $5.25 million bridged to Ethereum just weeks earlier.
Triple-A joins a growing list of crypto payment processors and exchanges targeted for hot wallet compromises this year. Attacks on Web3 infrastructure firms often follow a similar arc: attackers gain access to hot wallet private keys or exploit misconfigured smart contracts, drain liquid assets quickly, then launder proceeds through decentralized exchanges and cross-chain bridges before centralized platforms can freeze funds.
A similar incident occurred in May when the Gravity Bridge was drained of $5.4 million, with the attacker routing stolen funds through Binance. According to Peckshield, the industry lost $75.87 million to 40 separate hacks in June alone, a 7.13% drop from May’s $81.7 million, with hot wallet compromises remaining among the most common attack vectors alongside smart contract bugs and private key leaks.
More than eight hours after the breach was flagged, Triple-A had not issued an official statement acknowledging the exploit or detailing whether customer funds were affected. The silence raises questions about potential disruption to merchant settlements and whether the company holds sufficient reserves to cover losses.
Security researchers will likely continue tracking the consolidated Ethereum address for signs that the attacker moves funds toward centralized exchanges or mixing services, which could offer investigators a chance to flag the wallet before proceeds are cashed out.
Source: https://news.bitcoin.com/triple-a-hot-wallet-exploit-9-7-million-peckshield/