On-chain security firm PeckShield reported that the hot wallet infrastructure of the crypto payment platform Triple-A was attacked, affecting multiple networks including Ethereum, Solana, TRON, TON, Polygon, and Arbitrum. After transferring assets, the attackers quickly exchanged them and transferred them across chains to Ethereum. Currently, the relevant addresses contain approximately 5,226.66 ETH, worth about $9.72 million according to the report.
Funds are transferred to a single address
Public blockchain records show that most of the transfers occurred on July 24 and 25. One particularly large transfer was 4,140 ETH, followed by several other transfers of 615, 157, 112, 100, 72, and 23 ETH.
These funds were ultimately consolidated into a single Ethereum address, 0x01F…253b1. The report mentions that the attackers first transferred assets across multiple blockchains, then completed the exchange through decentralized exchanges, and subsequently bridged the funds to Ethereum for unified consolidation and subsequent transfer.
The attack path targets hot wallet infrastructure.
According to initial assessments by security researchers, attackers may have first gained control of the Triple-A online hot wallet. Such wallets are typically used to process customer payments more quickly, thus requiring constant internet connectivity for greater convenience, but also making them easier targets.
After gaining access, attackers prioritize transferring stablecoins and other highly liquid assets, then quickly complete on-chain exchanges and cross-chain operations. This approach typically helps to shorten the tracing window and reduce the management complexity of assets spread across multiple chains.
The platform has not yet released an official statement.

As of the time of this report, Triple-A has not yet issued an official statement regarding this multi-chain security incident, nor has it explained the cause of the vulnerability or the scope of its impact. Currently, the outside world is primarily reconstructing the incident based on on-chain data and the tracking results of security agencies.
This incident once again demonstrates that platforms holding customer funds face significantly increased operational risks if they retain a large amount of assets in online wallets for extended periods. Hot wallet access control, private key protection, and online asset size control remain the most direct security aspects for such platforms.












