Singapore's Triple-A Has Its Hot Wallets Drained

Triple-A, a Singapore-licensed payments company that settles crypto transactions on behalf of merchants, had its hot wallets drained across six blockchains on Friday. Assets were taken from wallets on Ethereum, Tron, Polygon, Arbitrum, Solana and TON, swapped on decentralized exchanges and bridged back to Ethereum, where the security firm PeckShield tracked them arriving in tranches at a single address holding roughly 5,227 ETH. Reported losses ran from $9.3 million to about $12 million, and the published figures did not agree with one another. Triple-A said client funds were not affected and only its own treasury assets were taken. Nothing had been recovered.
The Mechanism: A Key Failure, Not a Contract Bug
A hot wallet is one whose private keys sit on internet-connected systems so that transactions can be signed automatically, without a person present. For a payments company that is not an optional convenience: merchant settlement is the product, and settling in seconds means keys the software can always reach. Nothing in the reporting points to a flaw in a smart contract. The loss traced to key management or access control, and the fact that one operator could sign as Triple-A on six separate chains at once suggests something shared behind those wallets rather than six independent break-ins. That places the incident alongside the month's other key compromises, among them the $24.15 million withdrawn from AFX Trade's Arbitrum bridge two days earlier by an attacker holding five of its seven validator keys.
The Count: Four Figures Between $9.3 Million and $12 Million
No single loss number stands. The total climbed as the drain continued, and different trackers cut it at different points:
- $9.3 million — the earliest published count, from Crypto Times.
- $9.7 million — PeckShield's figure, carried by news.bitcoin.com and crypto.news.
- $11.8 million — a later Crypto Times count, struck after deposits had been drained for about 31 hours.
- About $12 million — the figure used by Crypto Briefing.
These are not four estimates of one measurement. They differ because the drain was still running when the first counts appeared, and because the assets sat in several tokens on six chains, so the value depends on when it was struck and at what prices. No reconciled total has been published, so the range and its sources are the accurate statement rather than any headline number.
The Window: 31 Hours Against a Three-Hour Maintenance Notice
On-chain analysts tracked deposits being drained for roughly 31 hours beginning Friday. Triple-A, for its part, had users in what it described as a three-hour maintenance window, a gap that has not been explained. Thirty-one hours should concern other processors more than the dollar figure. It is not the time an attacker needed; it is the time that passed before an operator established that its own settlement wallets were emptying on six chains at once. Alerting on outbound transfers from a small, fixed set of known addresses is among the least demanding controls a payments firm can run.
The compounding problem is specific to payments. Settlement hot wallets are inbound rails as well as outbound ones, and merchants keep paying into the same addresses regardless of what is happening behind them. Fresh deposits therefore kept flowing into compromised addresses during the window, which is part of why the total moved rather than settling at the first count.
What Is Unresolved: A Consolidated Address and No Explanation
Nothing has been recovered. Researchers were watching the consolidation address for movement toward exchanges or mixing services, the point at which recovery generally stops being realistic. Triple-A said it remains well capitalised and is absorbing the loss from reserves, and that client deposits are held separately in trust accounts or under bank guarantee, as Singapore's Payment Services Act requires of licensed payment institutions. That separation is why this reads as a corporate loss rather than a customer one. What is missing is the how: the company has described unauthorised access without saying how the keys, or the systems holding them, were reached, and until that is published other operators cannot check their own setup against it. Audits examine contract code, and the harder category is the one where keys fail rather than contracts.
Read also: The CFTC Tightens Event-Contract Self-Certifications