Triple-A Hot Wallets Drained of $9.7 Million Across Six Chains

ETH0.58%
TRX0.57%
ARB-0.73%
SOL0.81%
Key Takeaways
  • Triple-A lost over $9.7 million from hot wallets across six blockchains in a reported breach Saturday.
  • The attacker consolidated approximately 5,227 ETH worth $9.7 million in a single Ethereum address beginning with 0x01F8.
  • Triple-A issued no official statement more than eight hours after the breach was flagged by Peckshield.

Triple-A, a Singapore-based fiat-to-crypto payment gateway, lost over $9.7 million from hot wallets across six blockchains, according to a Peckshield alert published Saturday. Onchain investigator Specter first reported the incident, which saw funds drained from wallets on Ethereum, Tron, Polygon, Arbitrum, Solana, and The Open Network (TON). The attacker swapped stolen stablecoins and other liquid assets on decentralized exchanges before bridging the proceeds to Ethereum, consolidating roughly 5,227 ETH in a single address beginning with 0x01F8. Hot wallets remain connected to the internet to process transactions quickly, a tradeoff that exposes them to greater risk than offline cold storage. More than eight hours after the breach was flagged, Triple-A had issued no public statement acknowledging the exploit or detailing affected customer funds.

Attacker Consolidated 5,227 ETH in Single Ethereum Address

Onchain data reviewed by security researchers shows the attacker swapped stolen stablecoins and other liquid assets on decentralized exchanges before bridging the proceeds to Ethereum. The funds landed in a single address beginning with 0x01F8, which held roughly 5,227 ETH, worth about $9.7 million, as of Saturday. The consolidated wallet received the stolen assets in several tranches rather than one lump transfer. Peckshield has flagged similar bridge-to-Ethereum consolidation before, including a suspected exploit that saw $5.25 million bridged from Hedera to Ethereum just a couple of weeks ago.

Crypto Payment Processors Face $75.87 Million in June Hacks

Triple-A joins a growing list of crypto payment processors and exchanges targeted for hot wallet compromises this year. The cybersecurity giant found that the industry lost $75.87 million to 40 separate hacks just in June alone, a 7.13% drop from May's $81.7 million. Hot wallet compromises remain among the most common attack vectors alongside smart contract bugs and private key leaks. A mirror identical playbook was witnessed when the Gravity Bridge was drained of $5.4 million in May, with the attacker routing stolen funds through Binance to obscure the trail.

Triple-A Issues No Statement Eight Hours After Breach

More than eight hours after the breach was first flagged, Triple-A is yet to issue an official statement acknowledging the exploit or detailing what customer funds, if any, were affected. The silence leaves open questions about whether merchants using Triple-A's payment rails experienced any disruption to settlement, and whether the company holds reserves sufficient to make affected users whole. Triple-A operates payment infrastructure that lets merchants accept cryptocurrency and settle in fiat currency, meaning its hot wallets hold a rotating pool of customer funds and liquid stablecoins to process transactions quickly.

FAQ

What happened to Triple-A's hot wallets on Saturday? Triple-A lost over $9.7 million from hot wallets across Ethereum, Tron, Polygon, Arbitrum, Solana, and The Open Network (TON), according to a Peckshield alert published Saturday. The attacker swapped stolen stablecoins on decentralized exchanges and bridged the proceeds to Ethereum, consolidating roughly 5,227 ETH in a single address beginning with 0x01F8.

How much did the crypto industry lose to hacks in June? The industry lost $75.87 million to 40 separate hacks in June alone, a 7.13% drop from May's $81.7 million, per Peckshield. Hot wallet compromises remain among the most common attack vectors alongside smart contract bugs and private key leaks.

Did Triple-A issue a statement about the breach? More than eight hours after the breach was first flagged, Triple-A had issued no official statement acknowledging the exploit or detailing what customer funds, if any, were affected.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments