
Specter says new deposits kept flowing to compromised wallets more than 31 hours after the first outflows. The firm says customer funds are not impacted.
Losses tied to a hot-wallet compromise at Singapore payments firm Triple-A have climbed to about $11.8 million. Onchain investigator Specter said fresh deposits were still arriving at affected addresses more than 31 hours after the first large outflows were detected, suggesting the drain did not immediately stop the inflow of new funds.
Specter initially flagged the activity on Friday, estimating more than $9.3 million had been removed. The stolen assets were swapped and bridged to Ethereum, where proceeds from several networks were consolidated into a single address. A later estimate placed the losses above $9.7 million. On Sunday, Specter said another $1.8 million had been drained across Bitcoin and TRON, raising the total to roughly $11.8 million.
The investigator also noted that new deposits were still reaching the compromised wallets and being removed. That detail may point to a deeper operational problem: payment flows or automated systems kept directing assets into wallets that were no longer secure.
Bitcoin was not on the initial list of affected networks. Earlier alerts flagged activity across Ethereum, TRON, Polygon, Arbitrum, Solana and The Open Network, pointing to a multichain compromise rather than a breach limited to one blockchain.
The attacker pooled proceeds at one Ethereum address after converting and bridging assets from the affected networks. A transaction summary showed that address holding 5,226.67 Ether, worth about $9.73 million at the time. The address received eight transfers between 20:35 UTC Friday and 03:03 UTC Saturday. The largest inflow totaled roughly 4,140 Ether, accounting for most of the balance accumulated during the initial phase.
Consolidating stolen assets into Ethereum makes it easier for an attacker to manage funds across blockchains. It also gives investigators a single address to monitor as they track potential transfers to exchanges, mixers, decentralized finance protocols or additional wallets.
Triple-A has not disclosed how the wallets were accessed, whether private keys were exposed or whether an internal system was compromised. The company said it was investigating and would publish a formal update when ready.
“We’re actively investigating the situation and will share a formal update once ready. We confirm that customer funds are not impacted,” Triple-A said on Saturday.
The rising loss estimate is material. The continued arrival of deposits at affected wallets may be the larger concern. It suggests that stopping the initial drain did not immediately prevent more assets from entering the compromised infrastructure.
Triple-A is licensed by the Monetary Authority of Singapore as a major payment institution and processes stablecoin payments for merchants that receive settlement in local currencies. Its European subsidiary, Paytop SAS, holds payment institution and crypto-asset service provider licenses in France. The group is registered as a money services business in the United States and Canada.
Singapore’s Payment Services Regulations have required licensed digital payment token providers to safeguard customer assets in trust accounts since Oct. 4, 2024. Regulatory guidance also calls for customer assets to be held at blockchain addresses separated from a company’s own operational holdings.
Triple-A’s statement that customer funds were unaffected may mean the drained wallets contained company-owned liquidity or operational assets rather than safeguarded client holdings. The company has not identified the assets held in the affected wallets, however, leaving the accounting and operational impact unclear.
The distinction matters because a loss involving corporate treasury funds would create a direct financial cost for Triple-A. A breach involving customer assets could raise wider custody, reimbursement and regulatory questions.
Triple-A had not published its promised formal update in its newsroom by Sunday. Its latest public entry remained a July 15 announcement that Dubai’s Virtual Assets Regulatory Authority had granted the company in-principle approval for broker-dealer services.
The next update will need to explain how the wallets were accessed, which entities owned the lost assets and whether the company has stopped deposits from reaching compromised addresses. Users and regulators may also seek details on wallet segregation, key management and the controls used to detect abnormal withdrawals.
The incident follows two other large crypto exploits disclosed during the same week. AFX Trade, a protocol operating on Arbitrum, lost about $24.15 million in USDC through its custody bridge. The Verus-Ethereum bridge lost roughly $7.54 million in its second breach since May.
For payment firms, the Triple-A case shows that regulatory licensing does not remove technical and operational risks. The financial impact will depend on whether the company can recover any funds, identify the access method and prove that safeguarded customer assets remained isolated throughout the drain.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.