Investing

Triple-A Says Customer Funds Are Safe as Hot Wallet Drain…

How did the Triple-A wallet drain expand?

Losses linked to an apparent compromise of hot wallets associated with Singapore-based payments firm Triple-A have risen to about $11.8 million, adding to concerns that funds continued to move long after the first large outflows were detected.

Onchain investigator Specter initially identified the activity on Friday and estimated that more than $9.3 million had been removed. The stolen assets were swapped and bridged to Ethereum, where proceeds from several networks were consolidated into a single address.

A later estimate placed the losses above $9.7 million. Specter said on Sunday that another $1.8 million had been drained across the Bitcoin and TRON networks, raising the estimated total to roughly $11.8 million.

The investigator also said new deposits were still reaching the affected wallets and being removed 31 hours after the first major transfers. That detail may indicate that some payment flows or automated systems continued directing assets to wallets that were no longer secure.

Bitcoin was not included in the initial list of affected networks. Earlier alerts identified activity across Ethereum, TRON, Polygon, Arbitrum, Solana and The Open Network, pointing to a multichain operation rather than a compromise limited to one blockchain.

Where did the stolen assets go?

The proceeds were pooled at one Ethereum address after the attacker converted and bridged assets from the affected networks. A transaction summary showed the address holding 5,226.67 Ether, valued at about $9.73 million at the time.

The address received eight transfers between 20:35 UTC on Friday and 03:03 UTC on Saturday. The largest inflow totaled about 4,140 Ether, accounting for most of the balance accumulated during the initial phase of the drain.

Consolidating stolen assets into Ethereum can make it easier for an attacker to manage funds from several blockchains. It also gives investigators a central address to monitor as they track potential transfers to exchanges, mixers, decentralized finance protocols or additional wallets.

Triple-A has not disclosed how the wallets were accessed, whether private keys were exposed or whether an internal system was compromised. The company said it was investigating and would publish a formal update when ready.

“We’re actively investigating the situation and will share a formal update once ready. We confirm that customer funds are not impacted,” Triple-A said on Saturday.

Investor Takeaway

The rising loss estimate is important, but the continued arrival of deposits at affected wallets may be the larger operational concern. It suggests that stopping the initial drain did not immediately prevent more assets from entering the compromised infrastructure.

Why does the customer-funds statement matter?

Triple-A is licensed by the Monetary Authority of Singapore as a major payment institution and processes stablecoin payments for merchants that receive settlement in local currencies. Its European subsidiary, Paytop SAS, holds payment institution and crypto-asset service provider licenses in France, while the group is registered as a money services business in the United States and Canada.

Singapore’s Payment Services Regulations have required licensed digital payment token providers to safeguard customer assets in trust accounts since Oct. 4, 2024. Regulatory guidance also calls for customer assets to be held at blockchain addresses separated from a company’s own operational holdings.

Triple-A’s statement that customer funds were unaffected may mean the drained wallets contained company-owned liquidity or operational assets rather than safeguarded client holdings. The company has not identified the assets held in the affected wallets, however, leaving the accounting and operational impact unclear.

The distinction matters because a loss involving corporate treasury funds would create a direct financial cost for Triple-A, while a breach involving customer assets could raise wider custody, reimbursement and regulatory questions.

What should the market watch next?

Triple-A had not published its promised formal update in its newsroom by Sunday. Its latest public entry remained a July 15 announcement that Dubai’s Virtual Assets Regulatory Authority had granted the company in-principle approval for broker-dealer services.

The next update will need to explain how the wallets were accessed, which entities owned the lost assets and whether the company has stopped deposits from reaching compromised addresses. Users and regulators may also seek details on wallet segregation, key management and the controls used to detect abnormal withdrawals.

The incident follows two other large crypto exploits disclosed during the same week. AFX Trade, a protocol operating on Arbitrum, lost about $24.15 million in USDC through its custody bridge, while the Verus-Ethereum bridge lost roughly $7.54 million in its second breach since May.

For payment firms, the Triple-A case shows that regulatory licensing does not remove technical and operational risks. The financial impact will depend on whether the company can recover any funds, identify the access method and prove that safeguarded customer assets remained isolated throughout the drain.

© 2026 Michaels Finance Corner. All rights reserved.