Triple-A Suffers $12M Hot Wallet Breach Amid Growing Payments Infrastructure Concerns
Triple-A, a Singapore-based licensed crypto payments gateway, suffered a security breach that drained an estimated $12M from its hot wallets across multiple blockchains. The incident, which was first flagged by blockchain analysts on July 24, highlights the vulnerability of internet-connected wallets in the growing payments infrastructure.
The exploited funds were consolidated into a single Ethereum address holding roughly 5,227 ETH, according to on-chain data. The breach affected hot wallets on at least six separate chains: Ethereum, TRON, Polygon, Arbitrum, Solana, and TON. While customer funds are unaffected, the incident raises concerns about the security of hot wallets and the potential for insider threats.
Triple-A's cold storage, where the bulk of assets are typically held offline, appears to have been untouched by the breach. However, this has done little to alleviate investor concerns, as the company's integration with Fireblocks, a widely used institutional custody provider, was seen as a mitigation measure rather than a guarantee against such incidents.