امسح ضوئياً للتحميل
المنصة العالمية للتحقق الرقابي للبورصات

Triple-A hot wallets lose $9.7M in suspected exploit

الملخص:Triple-A, a Singapore-based stablecoin payment firm with a US regulatory presence, appears to have suffered a cross-chain hot-wallet compromise resulting in more than $9.7 million in suspected losses. On-chain analyst Specter first flagged suspicious activity across Ethereum, Solana, TRON, and TON, later expanded to include Polygon and Arbitrum. Blockchain security firm PeckShield amplified the alert. The stolen assets—primarily stablecoins and network-specific tokens—were swapped and bridged to Ethereum, where around 5,226.66 ETH (worth ~$9.7 million) was consolidated at a single address. Triple-A has not publicly confirmed the exploit, disclosed how wallets were accessed, or stated whether the funds belonged to the company, customers, or payment recipients. The incident follows a separate cross-chain attack on Across Protocol, though no connection has been established. Triple-A uses Fireblocks for custody, but no evidence links the breach to that provider.

Triple-As hot wallets appear to have lost more than $9.7 million across several blockchains, with the suspected attacker swapping the assets and consolidating the proceeds on Ethereum.

What happened to Triple-As hot wallets

On-chain analyst Specter first identified suspicious transactions involving hot wallets linked to Triple-A, a Singapore-based provider of stablecoin payment infrastructure.

Specter initially estimated that more than $9.3 million had been removed, swapped, and transferred across chains to Ethereum. Blockchain security firm PeckShield later amplified the alert, while subsequent estimates placed the suspected loss above $9.7 million.

The activity reportedly affected Triple-A wallets operating on Ethereum, Solana, TRON and TON. Some reports also identified transactions involving Polygon and Arbitrum, potentially expanding the incident to six networks.

Triple-A had not publicly confirmed the exploit at the time of writing. The company has also not disclosed when the suspicious activity began, how its wallets were accessed, or whether the affected assets belonged to Triple-A, its business customers, or payment recipients.

Without a company statement or technical investigation, the incident remains a suspected hot-wallet compromise rather than a confirmed protocol exploit.

Stolen assets were consolidated into Ethereum

On-chain data cited by security researchers showed that the transferred assets were exchanged and bridged to Ethereum after leaving the affected wallets.

The receiving address reportedly held about 5,226.66 ETH, worth approximately $9.7 million at the time of the alert. Consolidating assets into Ether can make a collection of stablecoins and network-specific tokens easier to move from one address.

Researchers have not publicly identified the suspected attacker or established whether the address has links to previous exploits. No report has confirmed that the funds entered an exchange, mixer, or other service after reaching Ethereum.

The difference between Specter‘s initial $9.3 million estimate and later figures above $9.7 million may reflect additional transfers or changes in Ether’s market value. A verified loss total will depend on Triple-A identifying every affected wallet and transaction.

Why the Triple-A incident matters in the US

Triple-A provides infrastructure that allows companies to collect, convert and send payments through stablecoins and traditional banking networks. Its services include merchant checkout, business payments, local payouts and cross-border settlement.

The company states that it operates as a licensed financial institution in the United States, Europe and Singapore. Triple-A also holds a Major Payment Institution licence from the Monetary Authority of Singapore and joined Circle Payments Network in March to support stablecoin-to-local-currency settlement.

Its US presence gives the incident a potential regulatory and counterparty angle, although there is no evidence that American customers or companies suffered losses. Any US impact will depend on which entity controlled the wallets, who owned the assets, and whether regulated payment operations were involved.

Triple-A uses Fireblocks as part of its digital-asset infrastructure. However, neither on-chain researchers nor Triple-A have attributed the suspected breach to Fireblocks, and no available evidence indicates that the custody technology provider was compromised.

Triple-A faces questions after another cross-chain attack

The suspected breach follows another recent incident involving cross-chain infrastructure. As crypto.news reported, an attacker fabricated 1,627 Solana deposit events targeting Across Protocols Risk Labs-operated relayer on July 17.

Those false deposits requested $41.7 million in payments across 18 destination chains. Risk Labs‘ relayer filled 581 requests before Across stopped its Solana operations, limiting the realized loss to less than $4 million, according to the protocol’s post-incident report.

The Across and Triple-A incidents do not appear to be connected. However, both cases involved activity spanning several networks, increasing the number of wallets, transaction systems and monitoring processes involved in detecting suspicious transfers.

Triple-A has yet to explain whether it has suspended deposits, withdrawals or cross-chain operations. The companys next statement will need to clarify the final loss, the affected assets, the source of the breach and whether customers will receive compensation.

عدم اعطاء رأي

الآراء الواردة في هذه المقالة تمثل فقط الآراء الشخصية للمؤلف ولا تشكل نصيحة استثمارية لهذه المنصة. لا تضمن هذه المنصة دقة معلومات المقالة واكتمالها وتوقيتها ، كما أنها ليست مسؤولة عن أي خسارة ناتجة عن استخدام معلومات المقالة أو الاعتماد عليها.
المنشور السابق

تنضم Anthropic إلى البيئة التنظيمية التجريبية للذكاء الاصطناعي التابعة لهيئة السلوك المالي البريطانية مع انطلاق الدفعة الثانية

التالي

غرفة الأصول الرقمية تقاضي سلطات إلينوي بسبب ضريبة جديدة بنسبة 0.2% على معاملات العملات المشفرة