Another set of hot wallets has been emptied. On-chain investigator Specter reported an ongoing security incident involving the hot wallets of Triple-A, a Singapore-based payments firm, with attackers draining assets across four separate blockchains and consolidating the proceeds on Ethereum.
Security firm PeckShield amplified the warning, and the figures cited by the two range from roughly $9.3 million to more than $9.7 million.
What is known so far
According to Specter’s alert, the drain touched hot wallets across TRON, Ethereum, TON, and Solana, a multichain spread indicating the attacker gained access to wallet infrastructure controlling funds on several networks simultaneously, rather than exploiting a single-chain smart-contract bug. Specter said more than $9.3 million had been drained, swapped and bridged to Ethereum, and published a primary Ethereum consolidation address along with several additional addresses tied to the flow.
PeckShield, amplifying the report shortly afterward, put the figure at more than $9.7 million across multiple chains, and noted that 5,227 ETH, the bridged proceeds, was being consolidated at a single Ethereum address beginning 0x01F8. Specter said it had flagged the activity roughly an hour earlier via its Telegram channel before posting publicly, and issued a brief warning to users: “Stay smart.”
One point of caution accompanied the disclosure: Specter noted that the correct project handle is TripleAHQ, an early clarification that matters in fast-moving incidents where impersonation and mistaken attribution are common. As of publication, Triple-A had not issued a public incident report, the exact attack vector had not been confirmed, and the figures remain preliminary on-chain estimates rather than a final accounting.
The signature: Many chains, one destination
The mechanics on display are, by now, grimly familiar. Funds scattered across TRON, TON, Solana, and Ethereum were rapidly swapped and pushed through cross-chain bridges into a single Ethereum wallet.
That consolidation-on-Ethereum pattern is the standard closing move of a hot-wallet compromise, and it happens for practical reasons. Ethereum hosts the deepest liquidity and the widest set of bridges and mixing tools, making it the natural staging ground for converting a messy spread of stolen tokens into a single, liquid, launder-ready position, typically ETH. Once assets are consolidated, attackers commonly route them through mixing services to sever the on-chain trail before attempting to cash out.
The speed is the point. Because the funds are pooled and bridged within hours, the window for exchanges, bridge operators or the project itself to freeze anything is extremely narrow.
A brutal month for hot wallets
The Triple-A incident does not stand alone. It is at least the latest in a string of remarkably similar drains flagged over the past few weeks, most surfaced by the same investigators and following the same bridge-to-Ethereum signature.
In mid-July, Hedera-based lender Bonzo saw about $9 million drained with $5.25 million bridged to Ethereum, in an incident Specter flagged first. The bridge protocol TeleSwap suffered suspicious outflows of over $735,000 from its Bitcoin hot wallet, with funds later moved toward Tornado Cash. And the broader tally is stark: on-chain trackers have described the recent stretch as one of the most hack-intensive in crypto’s history, with the industry’s 2026 losses already well past $750 million by mid-year.
The recurring thread across many of these is not a clever protocol exploit but the compromise of hot wallets and executor keys, the always-online infrastructure that projects use to move funds and validate cross-chain transfers. When those keys are exposed, no smart-contract audit helps; the attacker simply signs transactions as if they were the project. It is the least glamorous and most persistent attack surface in crypto, and it is having a moment.
What users should do
For merchants and users integrating with Triple-A:
- Revoke API Key & Deposit Approvals: Temporarily pause active API connections or deposit integrations associated with the platform.
- Avoid Further Settlements: Do not route customer settlement deposits to Triple-A wallet addresses until an official resolution statement is issued.
- Beware of Impersonation: Ignore unofficial “support” or “wallet recovery” links on X and Telegram claiming to offer asset restoration.
This is a developing story. Figures are preliminary on-chain estimates and may be revised as investigators and the project provide further details.
Also Read: Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit
