YFarmX

Tools Crypto Exploit Tracker exploit-0017

Exploit record

Triple-A Hot Wallet Drain

Loss
$10M
Attack vector
Other
Chain
Multichain
Sector
Payments

What happened

On 25 July 2026, wallets belonging to Triple-A, a licensed digital payments company, were drained of more than $9.7M across TRON, Ethereum, Polygon and Arbitrum. The attacker bridged the proceeds to Ethereum and consolidated about 5,227 ETH into a single address. The analyst who flagged it reported that deposits had not been disabled, so each new deposit was being taken as it arrived.

Triple-A holds a Major Payment Institution licence from the Monetary Authority of Singapore, an ACPR payment institution licence and French CASP registration, FinCEN and NMLS registration in the United States, and FINTRAC registration in Canada, and had secured in-principle approval from Dubai VARA ten days earlier. The vector is unconfirmed and logged as Other for that reason: losing balances on four networks at once, in assets that had to be swapped before they could be moved, points at compromised hot wallet signing keys rather than a contract flaw. Triple-A published no incident notice, so the loss is an on-chain estimate rather than a reconciled figure.

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026