Key Takeaways
- Suspicious withdrawals exceeding $9.7 million were detected from Triple-A’s hot wallets spanning several blockchain networks
- The breach affected Ethereum, Solana, TRON, and TON, with potential involvement of Polygon and Arbitrum
- The alleged attacker converted stolen assets into roughly 5,226.66 ETH and moved them to Ethereum
- Triple-A remains silent on whether the incident occurred and if user deposits are compromised
- The Singapore-based firm operates under payment licenses across the United States, European Union, and Singapore
A suspected security breach targeting Triple-A, a Singapore-headquartered stablecoin payment infrastructure provider, has resulted in unauthorized withdrawals exceeding $9.7 million from the company’s hot wallets, according to blockchain security researchers monitoring on-chain activity.
ALERT: Triple-A wallets are under an apparent active exploit with over $9.7M drained.
Onchain analyst Specter has flagged suspicious outflows from Triple-A hot wallets across TRON, Ethereum, Polygon, and Arbitrum, with the stolen assets consolidated into 5,227 ETH.
Triple-A… pic.twitter.com/1RykKuPGwA
— Coin Bureau (@coinbureau) July 25, 2026
Blockchain investigator Specter initially identified the anomalous fund movements. Cybersecurity firm PeckShield subsequently confirmed the findings, with damage assessments climbing from an early estimate of $9.3 million to more than $9.7 million as additional transactions were discovered.
Assets Drained From Six Blockchain Networks
The unauthorized withdrawals targeted wallets operating on Ethereum, Solana, TRON, and TON blockchains. Additional evidence suggests Polygon and Arbitrum may also have been compromised, potentially expanding the attack surface to six separate networks.
Following extraction, the stolen digital assets underwent conversion and cross-chain bridging operations before landing on Ethereum. The destination wallet contained approximately 5,226.66 ETH when security analysts flagged the activity.
Converting multiple tokens into ETH represents standard procedure following cross-chain breaches, as it simplifies the movement of disparate assets through a single, liquid cryptocurrency.
The variance between initial and updated loss figures likely stems from ongoing transfers or fluctuations in Ethereum’s market value during the incident window.
Triple-A’s Business Operations and Official Silence
Triple-A delivers payment processing solutions enabling businesses to accept, exchange, and disburse funds through stablecoin rails and conventional banking channels. Its product suite encompasses point-of-sale integrations, enterprise payment systems, and international money transfers.
The firm maintains regulatory approval across multiple jurisdictions, including American, European, and Singaporean territories. It secured Major Payment Institution status from Singapore’s Monetary Authority and became part of Circle Payments Network during March 2026.
Triple-A has issued no official acknowledgment of the security incident. The company has not revealed how unauthorized access occurred, the timeline of suspicious activity, or whether client assets face exposure.
Fireblocks serves as Triple-A’s digital asset custody provider. Currently available information contains no indication that Fireblocks infrastructure suffered any compromise.
Attacker Identity Unknown, Customer Impact Unclear
Security analysts have not publicly attributed the attack to any specific threat actor. No confirmed reports indicate whether the consolidated funds subsequently moved through cryptocurrency exchanges or privacy-enhancing mixing services.
Absent official disclosure or forensic analysis, this incident remains classified as a suspected hot wallet security failure rather than a verified smart contract vulnerability.
Triple-A has not announced whether it has paused deposit acceptance, withdrawal processing, or cross-blockchain transfer capabilities in response to the suspected breach.
This event occurs separately from a July 17 attack wherein an adversary generated fraudulent Solana deposit records targeting Across Protocol. That unrelated incident caused losses below $4 million after Across suspended Solana integration. No connection exists between the two security breaches.
Stakeholders await Triple-A’s official response addressing the verified loss amount, the attack vector employed, and whether the company intends to reimburse impacted users.
The post Triple-A Crypto Payment Provider Hit by $9.7M Multi-Blockchain Security Breach appeared first on Blockonomi.

7 hours ago
26









English (US) ·