
A security breach at Triple-A led to over $9.7 million in unauthorized withdrawals from hot wallets across six blockchains. The company has not acknowledged the incident.
A security breach at Singapore-based stablecoin payment processor Triple-A has resulted in unauthorized withdrawals exceeding $9.7 million from the company's hot wallets, blockchain security researchers said Friday.
Blockchain investigator Specter first flagged anomalous fund movements from Triple-A wallets on TRON, Ethereum, Polygon, and Arbitrum. Cybersecurity firm PeckShield confirmed the findings and updated the estimated loss from $9.3 million to $9.7 million as more transactions surfaced.
The attack hit wallets on Ethereum, Solana, TRON, and TON networks. Evidence also points to compromises on Polygon and Arbitrum, potentially expanding the breach to six blockchains, security analysts said.
The stolen assets were converted and bridged to Ethereum, where the destination wallet held about 5,226.66 ETH when flagged. Converting multiple tokens into a single liquid cryptocurrency is standard procedure after cross-chain breaches, analysts said.
Triple-A offers payment processing that lets businesses accept, exchange, and disburse funds through stablecoin rails and traditional banking. The firm holds regulatory licenses in the United States, Europe, and Singapore. It secured Major Payment Institution status from Singapore's Monetary Authority and joined the Circle Payments Network in March 2026.
Triple-A has not acknowledged the incident or disclosed how the unauthorized access occurred, the timeline of suspicious activity, or whether client assets are at risk. The company has not said whether it halted deposits, withdrawals, or cross-chain transfers.
Fireblocks serves as Triple-A's digital asset custody provider. No evidence suggests Fireblocks infrastructure was compromised, security analysts said.
The attack has not been attributed to any specific group. No confirmed reports show the funds moving through exchanges or privacy mixers. Without official disclosure, the incident is classified as a suspected hot wallet security failure rather than a smart contract exploit, analysts said.
The breach is unrelated to a July 17 attack where an adversary generated fake Solana deposit records targeting Across Protocol. That incident caused losses under $4 million.
Stakeholders are waiting for Triple-A's official response on the verified loss, the attack vector, and whether the company plans to reimburse affected users.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.