Crypto
$9.7M Drained Across Ethereum, Solana, TRON, TON in Triple-A Exploit
Triple-A suffered a $9.7 million hot wallet exploit across Ethereum, Solana, TRON and TON. Here's what happened and whether users were affected.
3h ago 4,280
Triple-A suffered a $9.7 million hot wallet exploit across Ethereum, Solana, TRON and TON. Here's what happened and whether users were affected.

A sophisticated attack drained nearly $9.7 million from the hot wallets of crypto payment gateway Triple-A. The stolen assets have been traced across Ethereum, Solana, TRON, and TON before being consolidated on Ethereum.
While the incident targeted the company's operational liquidity wallets, which function as treasury wallets used to process deposits, withdrawals, and merchant settlements.
Blockchain security researchers Specter first detected suspicious fund movements from Triple-A's hot wallet infrastructure, revealing a coordinated attack spanning four major blockchain networks.
According to on-chain findings, the attacker targeted the company's hot wallets, which are used to process instant crypto payouts and maintain liquidity for merchant transactions.
Researchers suspect the attacker gained access to the wallets by compromising private keys or other access controls, although the exact attack vector remains unknown. Once access was gained, automated scripts rapidly drained stablecoins and native assets across Ethereum, Solana, TRON, and TON before the affected infrastructure could be secured.
Blockchain records show the attacker ultimately accumulated 5,226.66 ETH, worth approximately $9.72 million, making it one of the larger cross-chain wallet compromises this year.
The attacker acted quickly to make the stolen assets harder to recover. Instead of leaving the funds on their original blockchains, the attacker first exchanged many of the stolen stablecoins for more liquid crypto assets through decentralized exchanges (DEXs).
This step reduced the risk of stablecoin issuers freezing or blacklisting the stolen tokens.
The assets were then bridged from Solana, TRON, and TON to Ethereum, allowing the attacker to gather the proceeds in one place.

On-chain data shows most of the transfers occurred between July 24 and July 25, with the largest transaction moving 4,140 ETH into the attacker's wallet. Additional deposits of 615 ETH, 157 ETH, 112 ETH, 100 ETH, 72 ETH, and 23 ETH followed shortly afterward.
All of the funds were eventually consolidated into a single Ethereum wallet, identified as 0x01F…253b1, where investigators continue monitoring the assets for any further movement.
The stolen ETH had not yet been widely dispersed or routed through privacy mixers, giving blockchain investigators a clearer view of the attacker's holdings.
Based on available evidence, customer funds do not appear to have been stolen.
The exploit was limited to Triple-A's internal operational liquidity wallets, sometimes referred to as treasury or hot liquidity reserves. These wallets provide the working capital needed to process deposits, withdrawals, and merchant settlements in real time.
The company reportedly separates customer assets from its operational funds by storing merchant balances and client deposits in secure institutional-grade custody systems rather than the affected hot wallets.
Despite the ongoing investigation, Triple-A has not yet released an official public statement detailing the root cause of the exploit or confirming exactly how the attacker gained access to the hot wallets.
The Triple-A incident reflects a growing trend in crypto exploits. The Triple-A incident reflects a broader trend of increasingly sophisticated cross-chain exploits. In July 2026, hackers stole $24.15 million from the AFX Trade bridge after compromising five of its seven validator keys, allowing them to forge withdrawal approvals and drain the Arbitrum-hosted bridge.
Likewise, the Verus-Ethereum Bridge was exploited twice in May and July 2026 through the same bridge verification flaw, resulting in combined losses of $19.12 million.
No comments yet
Be the first to share your take when accounts launch.