Triple-A Hot Wallets Drained of $9.7 Million Across Six Chains: Heres What Peckshield Found

요약:Triple-A, a Singapore-based crypto payment gateway, suffered a hot wallet exploit resulting in approximately $9.7 million in losses across six blockchains, according to security firm Peckshield. The attacker swapped stolen assets on decentralized exchanges and bridged them to Ethereum, consolidating roughly 5,227 ETH in a single address. More than eight hours after the breach was first flagged by onchain investigator Specter, Triple-A had not issued any public statement acknowledging the incident or detailing possible customer impact. The attack follows a pattern seen in other 2024 hot wallet compromises, where attackers drain liquid funds quickly and use cross-chain bridges to launder proceeds before funds can be frozen. Security researchers are tracking the consolidated Ethereum address for any moves toward exchanges or mixing services.

Key Takeaways

  • Triple-A lost over $9.7 million from hot wallets across six chains, per Peckshield.
  • The attacker bridged proceeds to Ethereum, consolidating roughly 5,227 ETH in one address.
  • Triple-A had issued no public statement more than eight hours after the breach was flagged.

Onchain Investigator Flags the Breach First

Onchain investigator Specter first reported the incident. According to a Peckshield alert published Saturday, wallets tied to Triple-A, a Singapore-based fiat-to-crypto payment gateway, had been drained of funds across Ethereum, Tron, Polygon, Arbitrum, Solana and The Open Network (TON).

Triple-A operates payment infrastructure that lets merchants accept cryptocurrency and settle in fiat currency, meaning its hot wallets hold a rotating pool of customer funds and liquid stablecoins to process transactions quickly. Hot wallets stay connected to the internet for speed, a tradeoff that makes them more exposed than offline cold storage.

Onchain data reviewed by security researchers shows the attacker swapped stolen stablecoins and other liquid assets on decentralized exchanges before bridging the proceeds to Ethereum. The funds landed in a single address beginning with 0x01F8, which held roughly 5,227 ETH, worth about $9.7 million, as of Saturday.

Image source: X

The consolidated wallet received the stolen assets in several tranches rather than one lump transfer, a move that is in line with nefarious actors of the past involved with methodically converting assets across multiple chains before regrouping them.

Lastly, it bears mentioning that Peckshield has flagged similar bridge-to-Ethereum consolidation before, including a suspected exploit that saw $5.25 million bridged from Hedera to Ethereum just a couple of weeks ago.

A Familiar Pattern for Payment Infrastructure

Triple-A joins a growing list of crypto payment processors and exchanges targeted for hot wallet compromises this year. Attacks on Web3 infrastructure firms often follow a similar arc, i.e., attackers gain access to a hot wallets private keys or a misconfigured smart contract, drain liquid assets quickly, then launder proceeds through decentralized exchanges (DEXs) and cross-chain bridges before centralized platforms can freeze funds.

A mirror identical playbook was witnessed when the Gravity Bridge was drained of $5.4 million in May, with the attacker routing stolen funds through Binance to obscure the trail. Not only that, the cybersecurity giant has found that the industry lost $75.87 million to 40 separate hacks just in June alone, a 7.13% drop from Mays $81.7 million (with hot wallet compromises remaining among the most common attack vectors alongside smart contract bugs and private key leaks).

No Remedial Measures Taken

More than eight hours after the breach was first flagged, Triple-A is yet to issue an official statement acknowledging the exploit or detailing what customer funds, if any, were affected. The silence leaves open questions about whether merchants using Triple-As payment rails experienced any disruption to settlement, and whether the company holds reserves sufficient to make affected users whole.

Over the coming few hours, security researchers will likely continue tracking the consolidated Ethereum address for signs that the attacker moves funds toward centralized exchanges or a mixing service, a step that could offer investigators a chance to flag the wallet before proceeds are cashed out.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

기관용 암호화폐 거래 플랫폼 LMAX, 매각 및 상장(IPO) 검토 중

다음

로빈후드 체인의 실물 자산, 토큰화된 주식 대규모 거래 시작과 함께 5배 증가