Incident Summary
Published 7/27/2026, 10:41:03 PM
Triple-A, a Singapore-based crypto payment gateway, suffered a hot wallet exploit between July 24 and July 25, 2026, resulting in a loss of approximately $11.8 million to $12 million. The attack was notable for its persistence, lasting over 31 hours as the attackers continued to "sweep" new merchant deposits in real-time across seven different blockchain networks.
Incident Summary
The losses were absorbed entirely from Triple-A's treasury and operational reserves; customer funds remained safe as they are held in segregated trust accounts per Monetary Authority of Singapore (MAS) regulations.
| Metric | Details |
|---|---|
| Total Estimated Loss | ~$11.8M – $12M |
| Primary Assets Stolen | ~5,227 ETH (consolidated value) + ~$1.8M in BTC/TRX |
| Chains Affected | Ethereum, TRON, Polygon, Arbitrum, Solana, TON, Bitcoin |
| Primary Attacker Address | 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1 |
| Attack Duration | 31+ hours |
How the Funds Were Lost
The exploit followed a sophisticated multi-stage process involving cross-chain drainage and consolidation:
- Initial Breach: Attackers gained unauthorized access to Triple-A's hot wallet infrastructure. While the exact technical mechanism has not been publicly disclosed, security researchers suggest the breach likely involved compromised private keys, API exploitation, or a vulnerability in the wallet management layer.
- Multi-Chain Drainage: Funds were simultaneously drained from wallets across seven different blockchains. A critical failure in the incident response allowed the attackers to continue "sweeping" new incoming merchant settlements for over a day after the initial breach was detected.
- Swapping and Bridging: Stolen assets were converted into liquid tokens (primarily stablecoins) via decentralized exchanges (DEXs) and subsequently bridged to the Ethereum network.
- Consolidation: The proceeds were concentrated into a single Ethereum address (
0x01F8...53b1), which eventually held approximately 5,227 ETH.
Technical Context and Detection
Triple-A utilizes Fireblocks for its MPC-based custody. However, both Triple-A and independent security researchers have stated that the Fireblocks platform itself was not compromised [Note: not independently confirmed]. The breach is believed to have occurred at the application or credential level where Triple-A managed its own keys or API access.
The exploit was first flagged by independent on-chain analyst Specter and security firm PeckShield on July 24/25. Triple-A did not officially confirm the "unauthorized access" until July 27, roughly 35 hours after the initial alerts were raised by the security community. Services were reportedly fully restored following a three-hour maintenance window on July 25 [Note: not independently confirmed].