πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
β€”β–²0.0%
News

Singapore's Triple-A Has Its Hot Wallets Drained

24 Jul 2026by CryptoJazz Admin1 min read111 views
Singapore's Triple-A Has Its Hot Wallets Drained

Triple-A, a Singapore-licensed payments company that settles crypto transactions for merchants, had its hot wallets drained across six blockchains on Friday. The wallets sat on Ethereum, Tron, Polygon, Arbitrum, Solana and TON. Whoever emptied them swapped the assets on decentralized exchanges and bridged the proceeds back to Ethereum, where the security firm PeckShield tracked them arriving in tranches at a single address holding roughly 5,227 ETH. Published loss figures ran between $9.3 million and about $12 million, and they did not agree with one another. Triple-A said client funds were untouched and only its own treasury assets were taken. Nothing had been recovered at the time of writing.

A key failure, not a contract bug

A hot wallet keeps its private keys on internet-connected systems so software can sign transactions without a person present. For a payments company that is not an optional convenience: merchant settlement is the product, and settling in seconds means keys the software can always reach. Nothing in the reporting points to a flaw in a smart contract. The loss traced to key management or access control, and the fact that one operator could sign as Triple-A on six separate chains at once suggests something shared behind those wallets rather than six independent break-ins. That places the incident alongside the month's other key compromises, among them the $24.15 million withdrawn from AFX Trade's Arbitrum bridge two days earlier by an attacker holding five of its seven validator keys.

Four counts between $9.3 million and $12 million

No single loss number stands. The outlets that covered the drain cut their totals at different points while it was still running:

  • $9.3 million, the earliest published count, from Crypto Times.
  • $9.7 million, PeckShield's figure, carried by news.bitcoin.com and crypto.news.
  • $11.8 million, a later Crypto Times count, struck after deposits had been draining for about 31 hours.
  • About $12 million, the figure Crypto Briefing used.

These are not four estimates of one measurement. The total climbed while the drain continued, and the assets sat in several tokens on six chains, so each count depends on when it was struck and at what prices. We could not establish which figure supersedes which; no reconciled total has been published, and the range with its sources is the accurate statement, not any single headline number.

31 hours against a three-hour maintenance notice

On-chain analysts tracked deposits being drained for roughly 31 hours beginning Friday. Triple-A, for its part, had users in what it described as a three-hour maintenance window. That gap has not been explained. Thirty-one hours should worry other processors more than the dollar figure does. It is not the time an attacker needed; it is the time that passed before an operator established that its own settlement wallets were emptying on six chains at once. Alerting on outbound transfers from a small, fixed set of known addresses is among the least demanding controls a payments firm can run.

The compounding problem is specific to payments. Settlement hot wallets are inbound rails as well as outbound ones, and merchants keep paying into the same addresses regardless of what is happening behind them. Fresh deposits kept flowing into compromised addresses through the window, which is part of why the total moved instead of settling at the first count.

The how has not been published

Nothing has been recovered. Researchers were watching the consolidation address for movement toward exchanges or mixing services, the point at which recovery generally stops being realistic. Triple-A said it remains well capitalised and is absorbing the loss from reserves, and that client deposits are held separately in trust accounts or under bank guarantee, as Singapore's Payment Services Act requires of licensed payment institutions. That separation is why this reads as a corporate loss and not a customer one. What is missing is the how. The company has described unauthorised access without saying how the keys, or the systems holding them, were reached, and until that detail is published other operators cannot check their own setup against it. Audits examine contract code, and the harder category is the one where keys fail instead of contracts.

Read also: The CFTC Tightens Event-Contract Self-Certifications

← All news