Payment gateway Triple-A had more than $9.7 million drained from its hot wallets across six blockchains on July 24 and July 25, according to security alert service Peckshield.
Key Takeaways
Triple-A lost over $9.7 million from hot wallets across six chains, per Peckshield.The attacker bridged proceeds to Ethereum, consolidating roughly 5,227 ETH in one address.Triple-A had issued no public statement more than eight hours after the breach was flagged.Triple-A operates payment infrastructure that lets merchants accept cryptocurrency and settle in fiat currency, meaning its hot wallets hold a rotating pool of customer funds and liquid stablecoins to process transactions quickly. Hot wallets stay connected to the internet for speed, a tradeoff that makes them more exposed than offline cold storage.
Onchain data reviewed by security researchers shows the attacker swapped stolen stablecoins and other liquid assets on decentralized exchanges before bridging the proceeds to Ethereum. The funds landed in a single address beginning with 0x01F8, which held roughly 5,227 ETH, worth about $9.7 million, as of Saturday.
The consolidated wallet received the stolen assets in several tranches rather than one lump transfer, a move that is in line with nefarious actors of the past involved with methodically converting assets across multiple chains before regrouping them.
A Familiar Pattern for Payment InfrastructureTriple-A joins a growing list of crypto payment processors and exchanges targeted for hot wallet compromises this year. Attacks on Web3 infrastructure firms often follow a similar arc, i.e., attackers gain access to a hot wallet’s private keys or a misconfigured smart contract, drain liquid assets quickly, then launder proceeds through decentralized exchanges (DEXs) and cross-chain bridges before centralized platforms can freeze funds.
More than eight hours after the breach was first flagged, Triple-A is yet to issue an official statement acknowledging the exploit or detailing what customer funds, if any, were affected. The silence leaves open questions about whether merchants using Triple-A’s payment rails experienced any disruption to settlement, and whether the company holds reserves sufficient to make affected users whole.
Over the coming few hours, security researchers will likely continue tracking the consolidated Ethereum address for signs that the attacker moves funds toward centralized exchanges or a mixing service, a step that could offer investigators a chance to flag the wallet before proceeds are cashed out.


















