Triple-A's $11.8M Hot Wallet Breach Exposes Risks of Centralized Key Management
Singapore's Triple-A, a licensed crypto payments processor that handled over $10 billion in transactions last year, suffered an $11.8 million breach of its hot wallets across seven blockchains.
The attack was first flagged by on-chain investigator Specter and blockchain security firm PeckShield before the company publicly acknowledged it.
Triple-A said new customer deposits continued to flow into still-compromised wallets for over 31 hours after the initial alert, allowing the attacker to drain $11.8 million from its hot wallets across Ethereum, TRON, Polygon, Arbitrum, Solana, TON, and Bitcoin.
The company has not disclosed how the attacker gained access to the wallets, but experts believe it was due to a compromised key management system or someone with access to the wallet infrastructure layer.