← Triple-A Treasury Hack (July 2026)1 decision on this page
Audit log
Every state-changing event for Triple-A Treasury Hack (July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-29 12:35:39ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
9w7kiFbDDtYf…qb8K3k9Csha256 → base58
verifying row…canonical bytes (20557 B) ▸
{"actor":"system:backfill","investigation_id":"25b13922-977d-4211-a52e-e95f7d52bd0f","kind":"publish","page_slug":"triple-a-treasury-hack-july-2026","published_at":"2026-07-29T12:35:39.696Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Triple-A Treasury Hack (July 2026)","sections":[{"content":"Triple-A, incorporated in Singapore and licensed by the Monetary Authority of Singapore (MAS) as a Major Payment Institution — and reportedly the first digital-currency payment company to receive that designation — disclosed on approximately July 27, 2026 that it had identified unauthorized access to wallets holding the company's own digital assets. The company stated the incident was identified and contained, and that client funds were not affected at any point. Blockchain security researchers and on-chain analysts, including PeckShield and the on-chain analyst known as Specter, had begun flagging suspicious outflows from Triple-A-linked wallets beginning on July 24, 2026, prior to the company's public disclosure. On-chain data indicated the drain continued for approximately 31 hours, a timeline that contradicts the company's initial characterization of a rapid containment window of approximately three hours.","heading":"Incident Overview","severity":"high","sources":[{"credibility":2,"name":"Singapore crypto payments firm Triple-A says own digital assets hit by unauthorized access - TNGlobal","type":"news_article","url":"https://technode.global/2026/07/28/singapore-crypto-payments-firm-triple-a-says-own-digital-assets-hit-by-unauthorized-access/"},{"credibility":2,"name":"Triple-A Hack Losses Reach $11.8M as Deposits Drained for 31 Hours - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/triple-a-hack-losses-reach-11-8m-as-deposits-drained-for-31-hours/"},{"credibility":2,"name":"Stablecoin Payments Firm Triple-A Confirms $11.8M Crypto Hack - CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/8d237-stablecoin-payments-firm-triple-a-confirms-11-8m-crypto-hack"}]},{"content":"Security researchers characterized the root cause as a hot-wallet compromise rather than a smart-contract vulnerability. The attacker allegedly obtained persistent authenticated access to Triple-A's wallet management infrastructure, enabling systematic withdrawal of assets across multiple networks simultaneously. The attacker then swapped the stolen assets for liquid tokens on decentralized exchanges on each respective chain, before bridging the proceeds cross-chain into Ethereum, where the funds were consolidated at a single address. On-chain data from Etherscan recorded 12 inbound transfers totaling approximately 5,287.09 ETH into the destination address (0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1) on July 24 and July 25, 2026. Triple-A did not publicly disclose the precise attack vector. Crypto Briefing noted the possible causes include a compromised private key, a vulnerability in the wallet management layer, or an insider threat, but no official attribution of root cause had been made at the time of reporting.","heading":"Attack Vector and Methodology","severity":"critical","sources":[{"credibility":2,"name":"On-chain data shows 5,280 ETH draining into single address following quiet Triple-A wallet breach - CryptoSlate","type":"on_chain","url":"https://cryptoslate.com/onchain-data-shows-5280-eth-draining-into-single-address-following-quiet-triple-a-wallet-breach/"},{"credibility":2,"name":"Triple-A Hot Wallets Drained of $9.7 Million Across Six Chains: Here's What Peckshield Found - Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/triple-a-hot-wallet-exploit-9-7-million-peckshield/"},{"credibility":2,"name":"Triple-A hot wallet losses reach $12M amid security incident - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/triple-a-hot-wallet-12m-security-breach/"},{"credibility":3,"name":"Crypto Patel on X — attacker wallet 0x01F8...53b1, PeckShield and Specter findings","type":"social_media","url":"https://x.com/CryptoPatel/status/2081054369970086247"}]},{"content":"On-chain analysts estimated total losses between approximately $9.7 million (PeckShield's initial estimate) and $11.8 million (later revised estimates). Triple-A did not officially confirm a dollar-denominated loss figure. The attack touched hot wallets across at least six to seven blockchain networks: Ethereum, TRON, The Open Network (TON), Solana, Polygon, Arbitrum, and Bitcoin, depending on the source. Assets were first swapped for liquid tokens on decentralized exchanges on each native chain, then bridged to Ethereum. Approximately 5,227 to 5,287 ETH was ultimately consolidated at the Ethereum address 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1. Triple-A withheld specific details regarding the number of wallets compromised, the precise asset composition before swaps, and whether any funds had been recovered.","heading":"Funds Lost and Chains Affected","severity":"high","sources":[{"credibility":2,"name":"Triple-A Hot Wallets Drained of $9.3M Across TRON, Ethereum, TON & Solana - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/25/triple-a-hot-wallets-drained-of-9-3m-across-tron-ethereum-ton-solana/"},{"credibility":2,"name":"On-chain data shows 5,280 ETH draining into single address - CryptoSlate","type":"on_chain","url":"https://cryptoslate.com/onchain-data-shows-5280-eth-draining-into-single-address-following-quiet-triple-a-wallet-breach/"},{"credibility":2,"name":"Triple-A Treasury Wallets Drained $11.8M Across Seven Chains in 31-Hour Attack - TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321654/20260727/triple-treasury-wallets-drained-118m-across-seven-chains-31-hour-attack.htm"},{"credibility":2,"name":"PeckShield Estimates Triple-A Hack Stole Approximately $9.7 Million - BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/peckshield-triple-a-hack-estimate-9-7-million-crypto/"}]},{"content":"Triple-A stated that client funds were held in segregated trust accounts maintained with independent safeguarding institutions, in compliance with Singapore's Payment Services Regulations as updated in October 2024, which mandate that licensed Major Payment Institutions keep customer holdings in distinct blockchain addresses separate from operational and treasury funds. The company confirmed client funds were not affected at any point during the incident. Triple-A also stated that it 'remains well capitalized, can meet all of its liabilities, and continues to operate globally at normal service levels,' and that the financial impact of the breach would be absorbed through the company's own treasury reserves. Services were suspended for approximately three hours during containment before being restored.","heading":"Client Fund Segregation and Solvency","severity":"medium","sources":[{"credibility":2,"name":"Triple A says it can meet all liabilities after treasury wallet exploit - Crypto.news","type":"news_article","url":"https://crypto.news/triple-a-says-it-can-meet-all-liabilities-after-treasury-wallet-exploit/"},{"credibility":2,"name":"Triple-A Says It Can Meet All Liabilities After Treasury Wallet Exploit - NFT Plazas","type":"news_article","url":"https://nftplazas.com/triple-a-treasury-wallet-exploit-client-funds-safe/"},{"credibility":2,"name":"Singapore stablecoin payments firm Triple-A loses $11.8M - Technext24","type":"news_article","url":"https://technext24.com/news/triple-a-treasury-wallet-hack-11-8-million/"}]},{"content":"On-chain analysts flagged suspicious outflows from Triple-A-linked wallets beginning July 24, 2026. On-chain analyst Specter allegedly observed that deposit flows into the compromised wallets were still active even as the company later claimed containment. Triple-A issued a formal statement on approximately July 27, 2026 — roughly two to three days after the initial on-chain signals. The company acknowledged the incident but declined to disclose the attack vector, the number of compromised wallets, the exact monetary loss, the asset breakdown, or source wallet addresses, citing the ongoing investigation. This information gap was noted by multiple crypto media outlets as a transparency concern given Triple-A's position as a regulated payment institution. MAS had not issued any public enforcement action or statement as of the time of reporting.","heading":"Disclosure Timeline and Transparency Concerns","severity":"medium","sources":[{"credibility":2,"name":"Triple-A Hack Losses Reach $11.8M as Deposits Drained for 31 Hours - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/triple-a-hack-losses-reach-11-8m-as-deposits-drained-for-31-hours/"},{"credibility":2,"name":"Triple-A Treasury Hack Exposes Major Crypto Asset Theft - Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/27/triple-a-treasury-hack/"},{"credibility":3,"name":"Crypto Patel on X — Specter flagged deposits still live during alleged containment","type":"social_media","url":"https://x.com/CryptoPatel/status/2081054369970086247"}]},{"content":"Triple-A holds a Major Payment Institution license from the Monetary Authority of Singapore and is reportedly the first digital-currency payment company to receive MAS licensing. Following the incident, Triple-A stated it was working with internal and external cybersecurity experts, blockchain forensics specialists, and the Singapore Police Force. No formal enforcement actions, public statements, or investigative disclosures from MAS or the Singapore Police Force had been reported as of July 28, 2026. Crypto Briefing noted that regulators in Singapore and other jurisdictions would likely scrutinize Triple-A's disclosure practices and remediation approach.","heading":"Regulatory and Law Enforcement Response","severity":"medium","sources":[{"credibility":2,"name":"Singapore crypto payments firm Triple-A says own digital assets hit by unauthorized access - TNGlobal","type":"news_article","url":"https://technode.global/2026/07/28/singapore-crypto-payments-firm-triple-a-says-own-digital-assets-hit-by-unauthorized-access/"},{"credibility":2,"name":"Triple-A hot wallet losses reach $12M amid security incident - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/triple-a-hot-wallet-12m-security-breach/"},{"credibility":2,"name":"Triple A says it can meet all liabilities after treasury wallet exploit - Crypto.news","type":"news_article","url":"https://crypto.news/triple-a-says-it-can-meet-all-liabilities-after-treasury-wallet-exploit/"}]},{"content":"The Triple-A incident was noted alongside other contemporaneous crypto security events, including an exploit affecting WEMIX, as indicative of persistent hot-wallet and key-management vulnerabilities across the industry. Security researchers emphasized that the attack was not a smart-contract exploit, which typically requires a code vulnerability, but instead targeted wallet infrastructure access controls — a class of attack that has affected multiple centralized and semi-centralized crypto platforms. The simultaneous multi-chain nature of the drain, affecting at least six to seven networks, suggests the attacker had access to a wallet management layer or key management system with broad cross-chain permissions rather than targeting individual blockchain deployments in sequence.","heading":"Broader Security Context","severity":"medium","sources":[{"credibility":2,"name":"Triple-A Hack and WEMIX Exploit Highlight Crypto Security Risks - Coin Edition","type":"news_article","url":"https://coinedition.com/triple-a-hack-and-wemix-exploit-highlight-crypto-security-risks/"},{"credibility":2,"name":"Triple-A hot wallets drained $9.7M across six chains - GNCrypto","type":"news_article","url":"https://www.gncrypto.news/news/triple-a-hot-wallets-drained-9-7m-six-chains/"}]}],"sources_used":[{"credibility":2,"name":"Singapore crypto payments firm Triple-A says own digital assets hit by unauthorized access - TNGlobal","type":"news_article","url":"https://technode.global/2026/07/28/singapore-crypto-payments-firm-triple-a-says-own-digital-assets-hit-by-unauthorized-access/"},{"credibility":2,"name":"Stablecoin Payments Firm Triple-A Confirms $11.8M Crypto Hack - CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/8d237-stablecoin-payments-firm-triple-a-confirms-11-8m-crypto-hack"},{"credibility":2,"name":"Triple-A Treasury Wallets Drained $11.8M Across Seven Chains in 31-Hour Attack - TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321654/20260727/triple-treasury-wallets-drained-118m-across-seven-chains-31-hour-attack.htm"},{"credibility":2,"name":"Stablecoin Payments Firm Triple-A Confirms $11.8M Crypto Hack - The Coin Republic","type":"news_article","url":"https://www.thecoinrepublic.com/2026/07/27/stablecoin-payments-firm-triple-a-confirms-11-8m-crypto-hack/"},{"credibility":2,"name":"Triple-A Hack Losses Reach $11.8M as Deposits Drained for 31 Hours - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/triple-a-hack-losses-reach-11-8m-as-deposits-drained-for-31-hours/"},{"credibility":2,"name":"Triple-A Treasury Hack Exposes Major Crypto Asset Theft - Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/27/triple-a-treasury-hack/"},{"credibility":2,"name":"Singapore stablecoin payments firm Triple-A loses $11.8M - Technext24","type":"news_article","url":"https://technext24.com/news/triple-a-treasury-wallet-hack-11-8-million/"},{"credibility":2,"name":"Singapore's Triple-A Reports $11.8M Cryptocurrency Treasury Breach - Blockonomi","type":"news_article","url":"https://blockonomi.com/singapores-triple-a-reports-11-8m-cryptocurrency-treasury-breach"},{"credibility":2,"name":"Triple-A Says It Can Meet All Liabilities After Treasury Wallet Exploit - NFT Plazas","type":"news_article","url":"https://nftplazas.com/triple-a-treasury-wallet-exploit-client-funds-safe/"},{"credibility":2,"name":"Triple A says it can meet all liabilities after treasury wallet exploit - Crypto.news","type":"news_article","url":"https://crypto.news/triple-a-says-it-can-meet-all-liabilities-after-treasury-wallet-exploit/"},{"credibility":2,"name":"Triple-A Hack Losses Rise to $11.8M - ForkLog","type":"news_article","url":"https://forklog.com/en/triple-a-hack-losses-rise-to-11-8m/"},{"credibility":2,"name":"On-chain data shows 5,280 ETH draining into single address - CryptoSlate","type":"on_chain","url":"https://cryptoslate.com/onchain-data-shows-5280-eth-draining-into-single-address-following-quiet-triple-a-wallet-breach/"},{"credibility":2,"name":"Triple-A Hot Wallets Drained of $9.7 Million Across Six Chains - Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/triple-a-hot-wallet-exploit-9-7-million-peckshield/"},{"credibility":2,"name":"PeckShield Estimates Triple-A Hack Stole Approximately $9.7 Million - BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/peckshield-triple-a-hack-estimate-9-7-million-crypto/"},{"credibility":2,"name":"Triple-A Hot Wallets Drained of $9.3M Across TRON, Ethereum, TON & Solana - CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/25/triple-a-hot-wallets-drained-of-9-3m-across-tron-ethereum-ton-solana/"},{"credibility":2,"name":"Triple-A hot wallet losses reach $12M amid security incident - Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/triple-a-hot-wallet-12m-security-breach/"},{"credibility":2,"name":"Triple-A Hack and WEMIX Exploit Highlight Crypto Security Risks - Coin Edition","type":"news_article","url":"https://coinedition.com/triple-a-hack-and-wemix-exploit-highlight-crypto-security-risks/"},{"credibility":2,"name":"Crypto Payments Firm Triple-A Hit by $9.7 Million Wallet Drain - BeInCrypto","type":"news_article","url":"https://beincrypto.com/triple-a-exploit-9m-wallet-drain/"},{"credibility":2,"name":"$9.7M Drained Across Ethereum, Solana, TRON, and TON in Triple-A Exploit - TradingView News","type":"news_article","url":"https://www.tradingview.com/news/coinpedia:74695d8dd094b:0-9-7m-drained-across-ethereum-solana-tron-and-ton-in-triple-a-exploit/"},{"credibility":3,"name":"Crypto Patel on X — attacker wallet, PeckShield and Specter attribution","type":"social_media","url":"https://x.com/CryptoPatel/status/2081054369970086247"},{"credibility":2,"name":"Triple-A Hack Losses Rise to $11.8 Million - HTX Insights","type":"news_article","url":"https://www.htx.com/news/triple-a-hack-losses-rise-to-118-million-0EIrmTV6/"},{"credibility":2,"name":"TripleA Wallet Hacked, Over $9.7 Million in Crypto Assets Lost - KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/triplea-wallet-hacked-over-9-7m-in-crypto-assets-lost"},{"credibility":2,"name":"Triple-A hot wallets lose $9.7M in suspected exploit - Ground News","type":"news_article","url":"https://ground.news/article/triple-a-hot-wallets-lose-97m-in-suspected-exploit_cc1fed"}],"summary":"Triple-A, a Singapore-based crypto payment platform holding a Major Payment Institution license from the Monetary Authority of Singapore (MAS), suffered an unauthorized access event beginning approximately July 24, 2026, in which approximately $11.8 million in company treasury assets was drained across seven blockchain networks over roughly 31 hours. The attacker consolidated stolen funds as approximately 5,287 ETH at a single Ethereum address. Triple-A stated that client funds were entirely segregated and unaffected, and that the company remained solvent and able to meet all liabilities.","timeline":[{"date":"2026-07-24","event":"On-chain analysts Specter and PeckShield begin flagging suspicious outflows from Triple-A hot wallets across multiple chains. More than $9.3 million had already been drained, swapped, and bridged to Ethereum by the time analysts raised the alarm.","source":"CryptoTimes, Bitcoin.com News","source_url":"https://www.cryptotimes.io/2026/07/25/triple-a-hot-wallets-drained-of-9-3m-across-tron-ethereum-ton-solana/"},{"date":"2026-07-24","event":"Attacker begins consolidating stolen assets at Ethereum address 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1. Etherscan records show 12 inbound transfers totaling approximately 5,287 ETH on July 24 and 25.","source":"CryptoSlate on-chain analysis","source_url":"https://cryptoslate.com/onchain-data-shows-5280-eth-draining-into-single-address-following-quiet-triple-a-wallet-breach/"},{"date":"2026-07-25","event":"Triple-A identifies the unauthorized access incident internally. On-chain analyst Specter alleges deposits were still flowing into compromised wallets at this time, suggesting active drainage continued past the company's claimed detection window.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/27/triple-a-hack-losses-reach-11-8m-as-deposits-drained-for-31-hours/"},{"date":"2026-07-25","event":"PeckShield publishes an initial estimate of approximately $9.7 million in losses across six chains: Ethereum, TRON, TON, Solana, Polygon, and Arbitrum.","source":"Bitcoin.com News, BitcoinWorld","source_url":"https://news.bitcoin.com/triple-a-hot-wallet-exploit-9-7-million-peckshield/"},{"date":"2026-07-27","event":"Triple-A issues a formal public statement confirming unauthorized access to treasury wallets, asserting client funds were unaffected, and announcing engagement with the Singapore Police Force and cybersecurity forensics specialists. Loss estimate revised upward to approximately $11.8 million.","source":"CryptoRank, The Coin Republic","source_url":"https://cryptorank.io/news/feed/8d237-stablecoin-payments-firm-triple-a-confirms-11-8m-crypto-hack"},{"date":"2026-07-27","event":"Triple-A states it remains well capitalized, can meet all liabilities, and that the financial impact will be absorbed by treasury reserves. Services, which had been paused for approximately three hours, are restored to normal.","source":"Crypto.news, NFT Plazas","source_url":"https://crypto.news/triple-a-says-it-can-meet-all-liabilities-after-treasury-wallet-exploit/"},{"date":"2026-07-28","event":"TNGlobal and additional outlets report Triple-A's disclosure. MAS had not issued any public statement or enforcement action as of this date.","source":"TNGlobal","source_url":"https://technode.global/2026/07/28/singapore-crypto-payments-firm-triple-a-says-own-digital-assets-hit-by-unauthorized-access/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 2b9677fc-348f-4e56-856e-06bdf85abfc4
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.