Loading market data...

Triple-A Loses $9.7M in Hot Wallet Hack Across Six Chains

Triple-A Loses $9.7M in Hot Wallet Hack Across Six Chains

Triple-A, a Singapore-based fiat-to-crypto payment gateway, lost more than $9.7 million from its hot wallets over two days. The theft hit six blockchains on July 24 and July 25. Security firm Peckshield reported the breach Saturday, with onchain investigator Specter first spotting the incident.

The six-blockchain attack

According to Peckshield's alert, the attacker drained funds from Triple-A's hot wallets across six different blockchains. The exact chains weren't named in the public alert, but the multi-chain nature suggests the attacker had access to multiple private keys or a master seed. Hot wallets are connected to the internet, making them a prime target for hackers. The total haul: more than $9.7 million.

Specter, an onchain investigator, was the first to flag the suspicious transactions. Peckshield followed up with a formal alert on Saturday. Neither firm provided details on how the attacker gained access.

Triple-A's role in crypto payments

Triple-A is a payment gateway that lets businesses accept cryptocurrency and automatically convert it to fiat currency. Think of it as a Stripe or PayPal for crypto — merchants get paid in dollars or euros, while customers pay in Bitcoin, Ethereum, or stablecoins. The company is licensed in Singapore and has been operating since 2018.

Because Triple-A holds customer funds temporarily during settlement, its hot wallets need to be liquid. That liquidity is exactly what made them a target. The $9.7 million loss represents a significant chunk of the working capital a payment processor typically keeps on hand.

Hot wallet security under scrutiny

This isn't the first time a payment gateway has been hit. Hot wallet breaches are a recurring problem in crypto — the convenience of instant settlement comes with real risk. Most exchanges and processors keep only a small percentage of funds in hot wallets, with the rest in cold storage. The fact that Triple-A lost $9.7 million suggests either a large hot wallet balance or a failure to limit exposure.

Triple-A hasn't said whether it uses multi-signature wallets, hardware security modules, or other safeguards. The company also hasn't confirmed if the stolen funds were insured. Without those details, it's hard to judge whether this was a sophisticated exploit or a basic security lapse.

As of Saturday evening, Triple-A had not issued a public statement. The company's website and social media channels remain silent. Affected merchants and users are waiting to hear whether they'll be made whole. The Singapore police and the Monetary Authority of Singapore have not commented on the breach.