A suspected security breach at stablecoin payments firm Triple-A has seen more than $9.7m in digital assets moved out of its hot wallets and consolidated into Ethereum, according to on-chain analysts.
Singapore-based Triple-A, which offers stablecoin payment infrastructure to businesses, has not publicly confirmed any exploit or loss, leaving the incident classified by researchers as a likely hot-wallet compromise rather than a verified protocol hack.
The activity was first flagged by on-chain analyst Specter, who identified unusual outflows from wallets linked to Triple-A across several networks. Specter initially calculated that over $9.3m had been siphoned off, swapped into other assets and bridged to Ethereum.
Subsequent scrutiny by blockchain security firm PeckShield and other researchers pushed the estimated impact higher, with the apparent loss now put at more than $9.7m. The variation in figures may stem from additional transfers being uncovered or moves in the price of Ether during the incident window.
Assets moved across multiple blockchains
Wallets associated with Triple-A on Ethereum, Solana, TRON and TON were all reported to be involved in the unexplained transfers. Some researchers also highlighted linked activity on Polygon and Arbitrum, suggesting that as many as six networks could be implicated.
On-chain data cited by security specialists indicates that tokens leaving the affected wallets were swapped and bridged onto Ethereum in a series of transactions. The funds were then consolidated into a single address that held about 5,226.66 ETH – worth roughly $9.7m at the time the activity was detected.
Collecting disparate stablecoins and network-specific tokens into Ether on one chain can make subsequent movement of the funds easier to manage and potentially harder to trace across multiple ecosystems.
No research shared publicly has tied the receiving Ethereum address to any previously known exploits, and there have been no confirmed sightings of the funds being sent on to a cryptocurrency exchange, mixer or other off-ramp service.
No details yet from Triple-A
Triple-A has not issued a statement confirming that its systems were breached, nor has it explained when the suspicious transactions began, how the wallets were accessed, or whose assets were involved.
It remains unclear whether the funds belonged to Triple-A itself, to business clients using its infrastructure, or to end users receiving payments via the platform. Any firm total for losses will depend on Triple-A identifying every compromised wallet and transaction.
The absence of an official incident report or post-mortem has left external observers describing the episode as a suspected hot-wallet incident rather than a confirmed exploit of Triple-A’s core systems or protocols.
Licensed payment provider with global reach
Triple-A runs infrastructure that enables companies to accept, convert and send stablecoin payments alongside traditional bank transfers. Its product suite covers merchant checkout services, business-to-business payments, local currency payouts and cross-border settlement.
The firm says it operates as a licensed financial institution in the United States, Europe and Singapore. It also holds a Major Payment Institution licence from the Monetary Authority of Singapore and, in March, it joined Circle Payments Network to facilitate settlement between stablecoins and local currencies.
Because of its regulated presence in the US, the incident could carry implications for counterparties and supervisors there. However, there is currently no evidence that American customers or corporates have suffered losses, and any regulatory fallout will hinge on which entity controlled the affected wallets, who owned the assets and whether regulated payment flows were directly involved.
Triple-A uses Fireblocks as part of its digital-asset infrastructure, but neither researchers nor the company have suggested that Fireblocks’ custody technology has been compromised. There is no on-chain evidence at this stage linking the suspected breach to a failure at the custody provider.
Follows other multi-chain security scare
The suspected Triple-A breach comes soon after another high-profile incident involving cross-chain infrastructure. As reported by ascrypto.news, an attacker on 17 July fabricated 1,627 Solana deposit events aimed at the relayer operated by Risk Labs for Across Protocol.
Those fake deposits requested payouts totalling $41.7m across 18 destination chains. Risk Labs’ relayer processed 581 of the requests before Across halted its Solana operations, with the protocol’s post-incident report stating that realised losses were kept below $4m.
There is no indication that the Across Protocol and Triple-A cases are linked. Both, however, highlight the additional complexity and attack surface created when operations span multiple blockchains, increasing the number of wallets, transaction routes and monitoring systems that need to be supervised.
Triple-A has not yet said whether it has suspended deposits, withdrawals or cross-chain services in response to the suspected breach. Its next public update is expected to address the scale of any losses, identify which assets and networks were affected, outline how the incident occurred and confirm whether affected customers will be reimbursed.
