VERSE PRESS

Crypto News, Global First.

Singapore Crypto Payment Gateway Triple-A Loses $11.8M as Compromised Wallets Keep Accepting Live Deposits

Singapore-based crypto payment processor Triple-A has lost at least $11.8 million after attackers gained control of its hot wallet infrastructure across six blockchain networks, with losses climbing sharply because new merchant deposits continued flowing into the breached wallets for hours after the attack began.

|

The incident unfolded between July 24 and 26, 2026. On-chain analyst Specter flagged suspicious activity via Telegram roughly one hour before any public disclosure of the breach, observing that assets were being drained simultaneously from wallets on Ethereum, TRON, Polygon, Arbitrum, Solana, and TON. The defining feature of the breach was not the initial drain alone. Every deposit that merchants or users sent to Triple-A's wallet addresses during the active attack period was immediately swept by the attacker, pushing total losses from an initial estimate of $9.3 million on July 25 to $9.7 million by later that day, then to $11.8 million by July 26, according to The Block.

The attacker's consolidation address on Ethereum, 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1, held approximately 5,227 ETH at the time of reporting, based on data flagged by blockchain security firm PeckShield. The firm noted on X that stolen funds were bridged across chains before being routed into that single address.

PeckShield's public alert read: "#PeckShieldAlert Specter has reported that @TripleAHQ wallets appear to have been drained of more than $9.7M worth of crypto across multiple chains, including #TRON, #Ethereum, #Polygon, and #Arbitrum. The exploiter bridged the stolen funds to Ethereum. 5,227 $ETH is currently being consolidated at: 0x01F8...53b1."

The attack was not a smart contract bug. Security researchers believe the attacker obtained compromised executor keys. In the MPC-based custody infrastructure used by providers such as Fireblocks, executor keys are signing keys within a multi-party computation scheme rather than conventional private keys; no single party holds a complete key, meaning a compromise at this level targets the distributed signing architecture itself. Anyone who gains access to these keys can sign and broadcast transactions as if they were the legitimate account owner, bypassing smart contract audits entirely. Triple-A uses Fireblocks as its custody provider; Fireblocks has not been reported as compromised in this incident.

Triple-A's Head of Marketing, Tatyana Chernov, issued a brief statement: "We are actively investigating the situation and will share a formal update as soon as possible. We can confirm that customer funds are not impacted." As of publication, the company had not released a formal incident report, disclosed the attack vector, or provided guidance on whether merchants should pause active integrations.

For merchants across South Asia and Africa, the TRON compromise carries specific weight. TRON is the dominant network for USDT transfers in Pakistan, Bangladesh, India, and across sub-Saharan Africa because its transaction fees are a fraction of Ethereum's. Businesses in these regions rely on TRC-20 USDT for remittances and trade settlement, preferring it for low-cost cross-border settlement. That TRON was among the six chains drained, and that live deposits were swept in real time, means any business with an active Triple-A integration during the breach window may have had incoming payments taken without immediate warning.

The incident also carries direct regulatory relevance for South Africa. Triple-A holds registration with South Africa's Financial Sector Conduct Authority (FSCA) as a Foreign Financial Services Provider. South Africa and Nigeria have both been active in building stablecoin payment corridors under the African Continental Free Trade Area framework, with companies including Onafriq, Yellow Card, and Flutterwave already using stablecoins for backend settlement. A high-profile breach of a regulated processor adds a trust dimension to an adoption story that is still proving itself to regional merchants and regulators.

Triple-A was founded in Singapore in 2017 and holds a Major Payment Institution licence from the Monetary Authority of Singapore. The company was the first to receive a digital payment token licence from MAS, according to CapitalMarkets.sg and Triple-A's official newsroom. Triple-A serves more than 20,000 businesses globally and raised $10 million in a Series A round in October 2023, co-led by Peak XV Partners (formerly Sequoia India and Southeast Asia) and Shorooq Partners, a MENAP-focused venture firm with offices across the Gulf, North Africa, and Pakistan.

The broader context makes the timing worse for the industry. Crypto hacks and exploits had already exceeded $750 million in total losses by mid-2026, making the current period one of the most active for crypto security incidents on record, according to Crypto Times and BeInCrypto. The Triple-A breach raises fresh concerns about hot wallet security at payment-layer infrastructure companies, a category that sits upstream of millions of end users and businesses. The security community has advised merchants to revoke API keys connected to Triple-A integrations, suspend deposit flows, and avoid any unofficial channels claiming to assist with fund recovery (per Blockonomi). Whether Triple-A will clarify the full scope of the breach and its reimbursement policy for merchants caught in the sweep window remains an open question as the investigation continues.