Triple-A Payment Service Hacked for $11.8M Amidst Growing Cross-Chain Risks
Singapore-based Triple-A payment service has confirmed unauthorized access to its treasury wallets, resulting in a significant loss of $11.8 million. According to on-chain researcher Specter, the stolen amount grew from initial reports of $9.3 million to $9.7 million before additional bitcoin and TRON withdrawals pushed it to the current figure.
The company assured that client funds were unaffected as they are held in trust accounts with third-party custodians per regulatory requirements. The damage was limited to operational accounts, which will be covered by Triple-A's reserves.
The attack began on July 24 and involved withdrawals across multiple networks, including Ethereum, Polygon, Arbitrum, Solana, and The Open Network. The hacker consolidated 5,226.67 ETH into a single address and added another $1.8 million via bitcoin and TRON. The company discovered the attack on Saturday, July 25, temporarily suspended services for about three hours, and restored them after isolating affected infrastructure segments.
Triple-A is cooperating with cybersecurity experts and Singapore police in the ongoing investigation. This incident follows recent cross-chain bridge attacks, highlighting persistent systemic risks in the sector.