A licensed payments firm lost $9.7m from its hot wallets, and kept taking deposits
Wallets belonging to payments firm Triple-A were drained of more than $9.7m across four chains on 25 July. The analyst who spotted it says deposits were still open and still being taken while the drain ran.
Listen to this article

Most of the money stolen in crypto this year has come out of protocols: bridges with bad key handling, lending markets with mispriced collateral, contracts nobody read closely enough. The loss reported on 25 July is a different shape. It came out of a licensed payments company.
Blockchain security firm PeckShield, relaying findings from the on-chain analyst Specter, reported that wallets belonging to Triple-A had been drained of more than $9.7m across four chains: TRON, Ethereum, Polygon and Arbitrum. The attacker bridged the proceeds to Ethereum and consolidated them into a single address holding about 5,227 ETH.
What the chain shows
The consolidation address is the clearest part of the picture. It holds 5,226.67 ETH, which was worth $9,725,837 at the price quoted when the alert went out and floats with the market from there. Everything else is inference: the funds left wallets attributed to Triple-A on four networks, were swapped, and were bridged into one place.
That pattern says something about the failure. A single-chain contract bug drains a single chain. Losing balances on four networks at once, in assets that had to be swapped before they could be moved, points at the keys rather than the code. Whoever did this could sign for wallets on several networks, which is the signature of compromised hot wallet infrastructure rather than an exploited contract.
Hot wallets are the working till of a payments business. They stay connected so that incoming customer payments can be processed in seconds, which is precisely the property that makes them the softest target a payments firm has.

The detail that turns a loss into a failure
The damaging line in Specter’s account is not the amount. It is this: the team appeared not to have noticed. Deposits had not been disabled, and each new deposit was being drained as it arrived.
If that holds, the money lost is only the money that had arrived so far. Every merchant payment routed through the platform during that window went into an attacker’s wallet, and the customers making them had no way to know. Detecting a breach is hard. Turning off the front door once you know is not, which is why the interval between the two is the number that actually measures an incident response.
This was not an unregulated venue
Triple-A is about as licensed as a digital payments business gets. On its own account it operates as a Major Payment Institution under the Monetary Authority of Singapore, holds a payment institution licence from France’s ACPR through Paytop SAS and a French CASP registration, is registered with FinCEN as a money services business and licensed as a money transmitter in the United States, and is registered with FINTRAC in Canada. It was the first digital currency payments company to be licensed by MAS. It serves merchants including Grab, Razer and Farfetch, and moves money in more than 140 countries.
On 15 July, ten days before the drain, it announced in-principle approval from Dubai’s virtual assets regulator.
That record is worth stating plainly because of what it does and does not buy. Payment licences regulate conduct: capital requirements, safeguarding of customer funds, anti-money-laundering controls, complaint handling, reporting lines. They are meaningful, and they are the direction of travel everywhere, including in Britain’s incoming FSMA regime, which makes safeguarding cryptoassets a regulated activity in its own right from October 2027.
What no licence does is hold your private keys for you. A regulator can require that customer funds be segregated and safeguarded; it cannot make the wallet infrastructure holding them resistant to whoever obtained the signing keys. Supervision raises the floor on governance. It does not substitute for operational security, and the gap between those two things is where this money went.

There is a second-order point for the industry’s regulatory argument. The case for bringing payments firms inside the perimeter has always been that supervision makes users safer than the alternative. An incident like this at a firm with this licence stack is the strongest counter-example available, and pretending otherwise helps nobody.
Where the money goes next
Consolidating into ETH on one address is normal attacker behaviour: it turns a scattered position across four chains into one liquid asset, ready to be moved when the attention dies down. Because the address is public and tagged, every exchange compliance desk can see it, which is the point of the Travel Rule machinery that now sits between stolen funds and a bank account.
That machinery works better than it did. It is also why funds of this size usually sit still for a while, then move through mixers or cross-chain routes designed to break the trail. The address is worth watching rather than the headline figure.
What is not known
A good deal. Triple-A has not published an incident notice, so the attack vector is unconfirmed and the loss is an on-chain estimate rather than a reconciled figure. It is not established which entity’s wallets these were, whether the funds were merchant settlement balances or the firm’s own, or whether customers face any loss. Reports differ on the exact chain list, and the four named here are the ones in PeckShield’s alert.
Every confirmed 2026 incident is logged in our Crypto Exploit Tracker.


