A licensed payments firm lost $9.7m from its hot wallets, and kept taking deposits
Wallets belonging to payments firm Triple-A were drained of more than $9.7m across four chains on 25 July. The analyst who spotted it says deposits were still open and still being taken while the drain ran.
Listen to this articleListen
Most of the money stolen in crypto this year has come out of protocols: bridges with bad key handling, lending markets with mispriced collateral, contracts nobody read closely enough. The loss reported on 25 July is a different shape. It came out of a licensed payments company.
Blockchain security firm PeckShield, relaying findings from the on-chain analyst Specter, reported that wallets belonging to Triple-A had been drained of more than $9.7m across four chains: TRON, Ethereum, Polygon and Arbitrum. The attacker bridged the proceeds to Ethereum and consolidated them into a single address holding about 5,227 ETH.
What the chain shows
The consolidation address is the clearest part of the picture. It holds 5,226.67 ETH, which was worth $9,725,837 at the price quoted when the alert went out and floats with the market from there. Everything else is inference: the funds left wallets attributed to Triple-A on four networks, were swapped, and were bridged into one place.
That pattern says something about the failure. A single-chain contract bug drains a single chain. Losing balances on four networks at once, in assets that had to be swapped before they could be moved, points at the keys rather than the code. Whoever did this could sign for wallets on several networks, which is the signature of compromised hot wallet infrastructure rather than an exploited contract.
Hot wallets are the working till of a payments business. They stay connected so that incoming customer payments can be processed in seconds, which is precisely the property that makes them the softest target a payments firm has.

The detail that turns a loss into a failure
The damaging line in Specter’s account is not the amount. It is this: the team appeared not to have noticed. Deposits had not been disabled, and each new deposit was being drained as it arrived.
If that held, everything arriving during the window was going straight to the attacker. Triple-A’s statement two days later pushed back on what that would mean: the breach, it says, was limited to wallets holding the company’s own digital assets, run by its Singapore entity, and client funds, held separately in trust accounts with safeguarding institutions, were not affected. Specter’s account and the company’s are both on the record, and the loss figure that would settle the difference has not been published. Detecting a breach is hard. Turning off the front door once you know is not, which is why the interval between the two is the number that actually measures an incident response.
This was not an unregulated venue
Triple-A is about as licensed as a digital payments business gets. On its own account it operates as a Major Payment Institution under the Monetary Authority of Singapore, holds a payment institution licence from France’s ACPR through Paytop SAS and a French CASP registration, is registered with FinCEN as a money services business and licensed as a money transmitter in the United States, and is registered with FINTRAC in Canada. It was the first digital currency payments company to be licensed by MAS. It serves merchants including Grab, Razer and Farfetch, and moves money in more than 140 countries.
On 15 July, ten days before the drain, it announced in-principle approval from Dubai’s virtual assets regulator.
What that record does and does not buy is the point. Payment licences regulate conduct: capital requirements, safeguarding of customer funds, anti-money-laundering controls, complaint handling, reporting lines. They are meaningful, and they are the direction of travel everywhere, including in Britain’s incoming FSMA regime, which makes safeguarding cryptoassets a regulated activity in its own right from October 2027.
What no licence does is hold your private keys for you. A regulator can require that customer funds be segregated and safeguarded; it cannot make the wallet infrastructure holding them resistant to whoever obtained the signing keys. Supervision raises the floor on governance. It does not substitute for operational security, and the gap between those two things is where this money went.

There is a second-order point for the industry’s regulatory argument. The case for bringing payments firms inside the perimeter has always been that supervision makes users safer than the alternative. An incident like this at a firm with this licence stack is the strongest counter-example available, and pretending otherwise helps nobody.
Where the money goes next
Consolidating into ETH on one address is normal attacker behaviour: it turns a scattered position across four chains into one liquid asset, ready to be moved when the attention dies down. Because the address is public and tagged, every exchange compliance desk can see it, which is the point of the Travel Rule machinery that now sits between stolen funds and a bank account.
That machinery works better than it did. It is also why funds of this size usually sit still for a while, then move through mixers or cross-chain routes designed to break the trail. Where the funds move next will say more than the headline figure.
Three hours of maintenance, and no loss figure
Triple-A’s statement, published on 27 July, confirms unauthorised access on 25 July to wallets containing the company’s own digital assets, limits the incident to its Singapore entity, Triple A Technologies Pte. Ltd., and says services were restored after roughly three hours of maintenance. It gives no loss figure, so the $9.7m stays an on-chain estimate, and it names no attack vector. The four chains named here are the ones in PeckShield’s alert.
Every confirmed 2026 incident is logged in our Crypto Exploit Tracker.
Sources
- PeckShieldAlert, on-chain alert (25 July 2026)x.com
- Triple-A, licences and regulatory statussupport.triple-a.io
- Triple-A, first digital currency payment company licensed by MAStriple-a.io
- Triple-A, 'Official Statement Regarding Recent Wallet Activity' (27 July 2026)triple-a.io
- Triple-A newsroomtriple-a.io


