On-chain researchers have discovered a large amount of abnormal outflows from a hot wallet associated with stablecoin payment infrastructure provider Triple-A, totaling over $9.7 million. These funds involved multiple public blockchains and were subsequently exchanged and transferred across blockchains to Ethereum.
At least four networks are involved.
The first to issue a warning was on-chain analyst Specter, who initially estimated that the abnormal outflow of assets exceeded $9.3 million. Subsequently, blockchain security firm PeckShield forwarded the , and later revised the suspected losses to over $9.7 million.
The networks currently named include at least Ethereum, Solana, TRON, and TON. Some tracking results also mention Polygon and Arbitrum, meaning the affected scope could extend to six chains.
As of press time, Triple-A has not publicly confirmed the attack, nor has it explained when the abnormal transfers began, how the wallet was accessed, or whether the affected assets belong to the company's own funds, corporate clients, or the payment recipients.
Funds have been pooled into Ethereum.
Security researchers, citing on-chain data, stated that after these assets left the relevant wallets, they were first exchanged and then transferred to Ethereum via cross-chain methods. The receiving address held approximately 5,226.66 ETH at the time, worth about $9.7 million based on the price at the time of the .
Researchers have not yet publicly confirmed the attacker's identity, nor have they stated whether the address is linked to past attacks. Current information also does not indicate that the funds, after entering Ethereum, flowed into exchanges, mixing services, or other platforms.
The discrepancy between Specter's initial estimate of $9.3 million and the subsequent estimate of $9.7 million is believed to be related to new transfers or changes in the price of ETH. The final scale of the loss still needs to be verified by Triple-A on a transaction-by-transaction basis regarding the affected wallets.
Payment services and regulatory information are attracting attention.
Triple-A, headquartered in Singapore, specializes in stablecoin payment infrastructure, with services covering merchant collections, corporate payments, local withdrawals, and cross-border settlements. The company claims to hold relevant licenses in the United States, Europe, and Singapore, including a large payment institution license issued by the Monetary Authority of Singapore.
In March of this year, Triple-A joined the Circle Payments Network to support settlements between stablecoins and local fiat currencies. Given the company's licensed operations in the US, whether this incident involves regulated payment processes has become a key focus of attention. However, there is currently no evidence that US customers or US businesses have suffered losses.
The report also mentioned that Triple-A uses Fireblocks in its digital asset infrastructure. However, neither on-chain researchers nor Triple-A have attributed the suspected intrusion to Fireblocks, nor is there any evidence that the custody service provider itself was compromised.
This is not related to the Across incident.
This incident comes shortly after another security breach in the cross-chain infrastructure space. On July 17, attackers forged 1,627 Solana deposit events targeting Across Protocol relayers and requested a total of $41.7 million in payments across 18 target chains.
Across completed 581 of these requests before suspending Solana-related operations. According to subsequent reports, the actual losses were kept below $4 million.
There is currently no indication that the Across and Triple-A cases are directly related. However, both cases involve multi-chain fund transfers, increasing the complexity of wallet management, transaction systems, and monitoring processes.
Triple-A has not yet stated whether it has suspended deposits, withdrawals, or cross-chain services. The market's focus will now be on the final amount of losses, the scope of affected assets, the source of the intrusion, and whether compensation will be offered to customers.












