Triple-A hack — July 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 27, 2026 |
| Target type | Other |
| Loss | $11,800,000Published estimates range $9,700,000 to $11,800,000Price at time of incident |
| Method | Private key compromiseCompromise of hot wallets holding Triple-A's own corporate digital assets across seven chains. Triple-A has not publicly disclosed the root cause. On-chain analysis characterises the pattern as sustained, authenticated access to the wallet-management layer, pointing to a credential or access compromise rather than a smart contract exploit; Scorechain notes that an MPC arrangement protects the private key itself but does not prevent abuse at the transaction-initiation layer once credentials are compromised. The attacker retained access long enough to sweep newly arriving deposits over roughly 31 hours. |
| Chains | Ethereum, Tron, Polygon, Arbitrum, Solana, TON, Bitcoin |
| Outcome | Unresolved |
What happened
Triple-A, a Singapore-licensed digital payments company, had hot wallets holding its own corporate assets drained across seven blockchains: Ethereum, Tron, Polygon, Arbitrum, Solana, The Open Network and Bitcoin.
On-chain analysis by Scorechain places the start of the unusual outflows at about 19:34 UTC on 24 July 2026. The draining continued for roughly 31 hours, with the attacker sweeping newly arriving deposits during the attack window. That is why published estimates rose across the weekend, from about $9.3 million when the activity was first reported, to $9.7 million, and finally to about $11.8 million; PeckShield's figure of $9.7 million remains the headline in some reporting. PeckShield tracked the attacker swapping stolen assets on decentralised exchanges and bridging proceeds to Ethereum, where roughly 5,227 ETH was consolidated in a single address; Scorechain puts the consolidated hoard slightly higher at about 5,287 ETH, worth close to $9.94 million. Scorechain's trace found roughly 78 percent of the value moved through Relay, Chainflip, deBridge and CoW Swap, and that the consolidated ether was converted into about $9.87 million of DAI on 28 July.
Triple-A confirmed the incident, saying it identified unauthorised access on 25 July 2026 to wallets containing the company's own digital assets, that certain services were placed in maintenance mode for about three hours while the affected infrastructure was secured, and that it is working with internal and external cybersecurity experts, blockchain forensics specialists and the relevant authorities including the Singapore Police Force. The company said client funds were not affected because it does not provide digital asset custody for clients; client money is held separately in trust accounts with safeguarding institutions that were not exposed. The incident was limited to Triple A Technologies Pte. Ltd., its Singapore entity. Triple-A has not published a loss figure of its own, said the financial impact is confined to specific operational accounts and is being absorbed from treasury reserves, and has not disclosed a root cause.
Law enforcement
Triple-A said it is working with the Singapore Police Force alongside internal and external cybersecurity experts and blockchain forensics specialists.
Sources
- Triple-APrimary · retrieved 2026-08-01
- The CryptonomistSecondary · retrieved 2026-08-01
- Bitcoin.com NewsSecondary · retrieved 2026-08-01
- ScorechainOn-chain · retrieved 2026-08-01
Official post-mortem: https://www.triple-a.io/newsroom/official-statement-regarding-recent-wallet-activity
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Triple-A hack — July 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/triple-ahttps://itokenly.com/hacks/triple-aPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.