Skip to main content
Sign in
Triple-A1 decision on this page

Audit log

Every state-changing event for Triple-A: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-26 12:07:42Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    GFwffJebaPB6…WMygc8wnsha256 → base58
    verifying row…
    canonical bytes (19223 B) ▸
    {"actor":"system:backfill","investigation_id":"65207d30-5c8e-4200-9ae0-987fe4256102","kind":"publish","page_slug":"triple-a","published_at":"2026-07-26T12:07:41.951Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Triple-A","sections":[{"content":"Triple-A Technologies Pte. Ltd., operating as Triple-A, is a Singapore-based digital currency payments company founded in 2017 by serial fintech entrepreneur Eric Barbier. Barbier previously co-founded Thunes, a cross-border payments platform now valued at over $900 million, and sold his earlier company Mobile 365 to Sybase in 2006. Triple-A enables businesses to accept cryptocurrency and stablecoin payments globally, settling merchants in fiat currency to eliminate volatility exposure. The company reports serving more than 20,000 businesses across e-commerce, gaming, creator economy, and financial services sectors in over 140 countries. Known merchant relationships include Farfetch, Razer, and the Singapore Red Cross. Triple-A uses Fireblocks as its digital asset custody infrastructure provider, a partnership marketed for its multi-party computation (MPC) security architecture.","heading":"Company Overview","severity":"low","sources":[{"credibility":1,"name":"Triple-A raises $10M Series A from Peak XV and Shorooq Partners","type":"official","url":"https://www.triple-a.io/newsroom/triple-a-raises-10m-series-a-from-peak-xv-and-shorooq-partners-to-be-the-most-regulated-payments-institution-for-digital-currency-worldwide"},{"credibility":1,"name":"Triple-A gets funding from Peak XV to help more businesses use crypto — TechCrunch","type":"news_article","url":"https://techcrunch.com/2023/10/24/triple-a/"},{"credibility":2,"name":"How Triple-A Scales Crypto Payments Securely with Fireblocks","type":"other","url":"https://www.fireblocks.com/customers/triple-a"}]},{"content":"Triple-A holds a Major Payment Institution licence from the Monetary Authority of Singapore (MAS) under Licence No. PS20200525, covering Digital Payment Token Services, Domestic Money Transfer Services, Cross-Border Money Transfer Services, and Merchant Acquisition Services. The company was reportedly the first digital currency payment provider to receive a MAS Digital Payment Token licence. Triple-A additionally holds a licence from Banque de France's ACPR in Europe and is registered with the United States Financial Crimes Enforcement Network (FinCEN). Under Singapore's Payment Services Act 2019, licensed Major Payment Institutions are required to safeguard customer funds in segregated trust accounts, report suspicious activities and incidents of fraud to MAS, and comply with MAS Technology Risk Management (TRM) guidelines. The July 2026 security incident creates potential regulatory exposure because, as of the date of this report, the company had not issued a public incident report and had not halted deposits — conduct that may conflict with MAS incident reporting obligations.","heading":"Regulatory Standing","severity":"high","sources":[{"credibility":1,"name":"Triple-A — First Digital Currency Payment Company Licensed by MAS","type":"official","url":"https://www.triple-a.io/newsroom/triplea-the-first-digital-currency-payment-company-to-be-licenced-by-mas"},{"credibility":1,"name":"MAS — Circular on Financial Institution Incident Reporting","type":"regulatory","url":"https://www.mas.gov.sg/regulation/circulars/circular-on-financial-institution-incident-reporting"},{"credibility":1,"name":"PSN03 — MAS Notice on Reporting of Suspicious Activities and Incidents of Fraud","type":"regulatory","url":"https://www.mas.gov.sg/regulation/notices/psn03-notice-on-reporting-of-suspicious-activities-and-incidents-of-fraud"},{"credibility":1,"name":"Crypto Payments Company TripleA Grabs MAS License — PYMNTS","type":"news_article","url":"https://www.pymnts.com/cryptocurrency/2021/crypto-payments-company-triplea-grabs-monetary-authority-singapore-license/"}]},{"content":"On July 24-25, 2026, attackers drained approximately $9.3-9.7 million from Triple-A's hot wallets across multiple blockchain networks. The incident was first publicly flagged by on-chain analyst Specter via Telegram and X (formerly Twitter), approximately one hour before broader media coverage on July 25. Blockchain security firm PeckShield subsequently confirmed the findings, with total damage estimates rising from an initial $9.3 million to $9.7 million as additional transactions were identified. Affected networks include Ethereum, TRON, TON (The Open Network), and Solana, with some researchers also identifying activity on Polygon and Arbitrum, potentially expanding the compromised surface to six blockchain networks. The stolen assets were rapidly swapped and bridged to Ethereum via cross-chain infrastructure, and the proceeds were consolidated into a single Ethereum address — 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1 — holding approximately 5,226.66 ETH, valued at roughly $9.7 million at the time of consolidation. The multichain spread of the attack, spanning networks with distinct signing schemes and transaction formats, is consistent with compromise of shared wallet infrastructure or private key management systems rather than exploitation of a single-chain smart contract vulnerability. The CryptoTimes noted that the compromise appeared to involve 'hot wallets and executor keys' rather than smart-contract logic, with one researcher observing: 'When those keys are exposed, no smart-contract audit helps; the attacker simply signs transactions as if they were the project.' The identity of the attacker and the precise access mechanism had not been publicly confirmed as of July 25, 2026. Some community observers speculated the breach may involve an insider or former developer with access to key material, but this claim is unverified and has not been corroborated by any named researcher or official statement.","heading":"July 2026 Hot Wallet Exploit","severity":"critical","sources":[{"credibility":2,"name":"Triple-A Hot Wallets Drained of $9.3M Across TRON, Ethereum, TON and Solana — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/25/triple-a-hot-wallets-drained-of-9-3m-across-tron-ethereum-ton-solana/"},{"credibility":2,"name":"$9.7M Drained Across Ethereum, Solana, TRON, and TON in Triple-A Exploit — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/9-7m-drained-across-ethereum-solana-tron-and-ton-in-triple-a-exploit/"},{"credibility":2,"name":"Triple-A exploit drains $9.7M across 4 chains — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/triple-a-exploit-drains-9-7mln-across-4-chains-what-we-know-so-far/"},{"credibility":2,"name":"Triple-A hot wallets lose $9.7M in suspected exploit — crypto.news","type":"news_article","url":"https://crypto.news/triple-a-hot-wallets-lose-9-7m-in-suspected-exploit/"},{"credibility":2,"name":"PeckShieldAlert — X post confirming wallet drain and attacker address","type":"on_chain","url":"https://x.com/PeckShieldAlert/status/2080833993633866106"},{"credibility":2,"name":"Crypto Payments Firm Triple-A Hit by $9.7 Million Wallet Drain — BeInCrypto","type":"news_article","url":"https://beincrypto.com/triple-a-exploit-9m-wallet-drain/"}]},{"content":"As of July 25, 2026 — more than eight hours after initial on-chain detection — Triple-A had not issued any public acknowledgment of the security incident. The company did not pause inbound deposits following the breach detection, meaning that new customer funds continued to be deposited into compromised infrastructure and were subsequently drained by the attacker, according to reporting by AMBCrypto and crypto.news. Triple-A had not disclosed: the mechanism of unauthorized access; a confirmed timeline of suspicious activity; whether the drained assets belonged to Triple-A, its business customers, or end-user payment recipients; or any reimbursement plan. This absence of public communication is notable given the company's position as a MAS-licensed Major Payment Institution with explicit regulatory obligations to report material incidents. MAS's Technology Risk Management guidelines and MAS Notice PSN03 require licensed payment service providers to report incidents that affect safety, soundness, or reputation. The failure to halt live deposits after the exploit was underway represents an additional operational concern beyond the initial breach.","heading":"Transparency and Incident Response Failures","severity":"critical","sources":[{"credibility":2,"name":"Triple-A exploit drains $9.7M across 4 chains — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/triple-a-exploit-drains-9-7mln-across-4-chains-what-we-know-so-far/"},{"credibility":2,"name":"Triple-A hot wallets lose $9.7M in suspected exploit — crypto.news","type":"news_article","url":"https://crypto.news/triple-a-hot-wallets-lose-9-7m-in-suspected-exploit/"},{"credibility":1,"name":"PSN03 — MAS Notice on Reporting of Suspicious Activities and Incidents of Fraud","type":"regulatory","url":"https://www.mas.gov.sg/regulation/notices/psn03-notice-on-reporting-of-suspicious-activities-and-incidents-of-fraud"}]},{"content":"According to on-chain data reported by PeckShield and Specter, the attacker consolidated the stolen assets into Ethereum wallet address 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1, which held approximately 5,226.66 ETH as of the date of public reporting. The rapid cross-chain bridging and consolidation technique — draining assets from multiple networks, swapping to ETH, and aggregating into a single wallet — is a recognized pattern in large hot wallet compromises designed to simplify asset management and potentially prepare for further laundering through exchanges or privacy protocols. As of July 25, 2026, no subsequent movement of funds from the consolidation wallet had been publicly reported, and no blockchain analytics firm had publicly linked the attacker to a known threat actor. The identity of the attacker remained unconfirmed.","heading":"On-Chain Fund Movement and Attacker Profile","severity":"high","sources":[{"credibility":2,"name":"PeckShieldAlert — X post confirming wallet drain and attacker address","type":"on_chain","url":"https://x.com/PeckShieldAlert/status/2080833993633866106"},{"credibility":2,"name":"Crypto Payments Firm Triple-A Hit by $9.7 Million Wallet Drain — BeInCrypto","type":"news_article","url":"https://beincrypto.com/triple-a-exploit-9m-wallet-drain/"},{"credibility":2,"name":"Triple-A Crypto Payment Provider Hit by $9.7M Multi-Blockchain Security Breach — Blockonomi","type":"news_article","url":"https://blockonomi.com/triple-a-crypto-payment-provider-hit-by-9-7m-multi-blockchain-security-breach"}]},{"content":"Triple-A raised a $4 million seed round in June 2022 from investors including 1982 Ventures, 8i Ventures, Boleh Ventures, RaliCap, Rapyd Ventures, Razer Inc., and Sequoia Capital. In October 2023, the company raised a $10 million Series A led by Peak XV Partners (formerly Sequoia India and South East Asia), with additional backing from Shorooq Partners and 1982 Ventures. The company's stated goal in the Series A round was to become the most regulated payments institution for digital currency worldwide. No prior security incidents or regulatory enforcement actions against Triple-A have been identified in publicly available records prior to the July 2026 breach.","heading":"Funding and Investor Background","severity":"low","sources":[{"credibility":2,"name":"Singapore's Triple-A raises $10M Series A from Peak XV and Shorooq Partners — TechNode Global","type":"news_article","url":"https://technode.global/2023/10/25/singapores-triple-a-raises-10m-series-a-funding-from-peak-xv-and-shorooq-partners/"},{"credibility":1,"name":"Triple-A gets funding from Peak XV — TechCrunch","type":"news_article","url":"https://techcrunch.com/2023/10/24/triple-a/"},{"credibility":2,"name":"Triple-A Raises $10M Series A From Peak XV, Shorooq Partners and 1982 Ventures","type":"news_article","url":"https://www.1982.vc/post/triple-a-raises-10m-series-a-from-peak-xv-shorooq-partners-and-1982-ventures"}]},{"content":"The Triple-A incident occurred during a period of elevated hacking activity in the crypto sector. According to reporting by crypto.news, the broader crypto market lost approximately $106 million to hacks in July 2026, with the Triple-A exploit bringing the weekly total at the time to approximately $41.83 million. The incident follows a pattern of multi-chain hot wallet compromises that have increasingly targeted payment infrastructure and custody providers rather than individual smart contracts or DeFi protocols. The use of cross-chain bridges and rapid ETH consolidation mirrors techniques observed in multiple 2025-2026 exchange and payment provider hacks.","heading":"Broader Context: July 2026 Crypto Hack Landscape","severity":"medium","sources":[{"credibility":2,"name":"Triple-A hot wallets lose $9.7M in suspected exploit — crypto.news","type":"news_article","url":"https://crypto.news/triple-a-hot-wallets-lose-9-7m-in-suspected-exploit/"},{"credibility":2,"name":"Crypto Payments Firm Triple-A Suffers $9.7 Million Multi-Chain Wallet Drain — CryptoMeter","type":"news_article","url":"https://www.cryptometer.io/news/crypto-payments-firm-triple-a-suffers-9-7-million-multi-chain-wallet-drain/"}]}],"sources_used":[{"credibility":2,"name":"Triple-A Hot Wallets Drained of $9.3M Across TRON, Ethereum, TON and Solana — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/25/triple-a-hot-wallets-drained-of-9-3m-across-tron-ethereum-ton-solana/"},{"credibility":2,"name":"$9.7M Drained Across Ethereum, Solana, TRON, and TON in Triple-A Exploit — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/9-7m-drained-across-ethereum-solana-tron-and-ton-in-triple-a-exploit/"},{"credibility":2,"name":"Triple-A exploit drains $9.7M across 4 chains — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/triple-a-exploit-drains-9-7mln-across-4-chains-what-we-know-so-far/"},{"credibility":2,"name":"Crypto Payments Firm Triple-A Hit by $9.7 Million Wallet Drain — BeInCrypto","type":"news_article","url":"https://beincrypto.com/triple-a-exploit-9m-wallet-drain/"},{"credibility":2,"name":"Triple-A hot wallets lose $9.7M in suspected exploit — crypto.news","type":"news_article","url":"https://crypto.news/triple-a-hot-wallets-lose-9-7m-in-suspected-exploit/"},{"credibility":2,"name":"Triple-A Crypto Payment Provider Hit by $9.7M Multi-Blockchain Security Breach — Blockonomi","type":"news_article","url":"https://blockonomi.com/triple-a-crypto-payment-provider-hit-by-9-7m-multi-blockchain-security-breach"},{"credibility":2,"name":"PeckShieldAlert — X post confirming wallet drain and attacker address","type":"on_chain","url":"https://x.com/PeckShieldAlert/status/2080833993633866106"},{"credibility":1,"name":"Triple-A raises $10M Series A from Peak XV and Shorooq Partners — TechCrunch","type":"news_article","url":"https://techcrunch.com/2023/10/24/triple-a/"},{"credibility":1,"name":"Triple-A — First Digital Currency Payment Company Licensed by MAS (official)","type":"official","url":"https://www.triple-a.io/newsroom/triplea-the-first-digital-currency-payment-company-to-be-licenced-by-mas"},{"credibility":1,"name":"MAS — Circular on Financial Institution Incident Reporting","type":"regulatory","url":"https://www.mas.gov.sg/regulation/circulars/circular-on-financial-institution-incident-reporting"},{"credibility":1,"name":"PSN03 — MAS Notice on Reporting of Suspicious Activities and Incidents of Fraud","type":"regulatory","url":"https://www.mas.gov.sg/regulation/notices/psn03-notice-on-reporting-of-suspicious-activities-and-incidents-of-fraud"},{"credibility":2,"name":"How Triple-A Scales Crypto Payments Securely with Fireblocks","type":"other","url":"https://www.fireblocks.com/customers/triple-a"},{"credibility":2,"name":"Crypto Payments Firm Triple-A Suffers $9.7M Multi-Chain Wallet Drain — CryptoMeter","type":"news_article","url":"https://www.cryptometer.io/news/crypto-payments-firm-triple-a-suffers-9-7-million-multi-chain-wallet-drain/"},{"credibility":2,"name":"Singapore's Triple-A raises $10M Series A — TechNode Global","type":"news_article","url":"https://technode.global/2023/10/25/singapores-triple-a-raises-10m-series-a-funding-from-peak-xv-and-shorooq-partners/"}],"summary":"Triple-A (Triple-A Technologies Pte. Ltd.) is a Singapore-headquartered crypto payments company founded in 2017 and licensed as a Major Payment Institution by the Monetary Authority of Singapore (MAS). On July 24-25, 2026, attackers drained approximately $9.7 million from the company's hot wallets across at least four blockchain networks, with stolen funds consolidated into a single Ethereum address. As of the date of this report, Triple-A had issued no public acknowledgment of the breach despite continuing to accept live deposits, raising concerns about transparency obligations under its MAS licence.","timeline":[{"date":"2017-01-01","event":"Triple-A Technologies Pte. Ltd. founded in Singapore by Eric Barbier.","source":"TechCrunch","source_url":"https://techcrunch.com/2023/10/24/triple-a/"},{"date":"2021-09-01","event":"Triple-A receives Digital Payment Token licence from MAS (Licence No. PS20200525), becoming the first digital currency payment company licensed by MAS.","source":"Triple-A official newsroom","source_url":"https://www.triple-a.io/newsroom/triplea-the-first-digital-currency-payment-company-to-be-licenced-by-mas"},{"date":"2022-06-01","event":"Triple-A raises $4 million seed round from 1982 Ventures, 8i Ventures, Sequoia Capital, Razer Inc., and others.","source":"1982 Ventures","source_url":"https://www.1982.vc/post/triple-a-raises-10m-series-a-from-peak-xv-shorooq-partners-and-1982-ventures"},{"date":"2023-10-24","event":"Triple-A raises $10 million Series A led by Peak XV Partners (formerly Sequoia India and South East Asia) with Shorooq Partners.","source":"TechCrunch","source_url":"https://techcrunch.com/2023/10/24/triple-a/"},{"date":"2026-07-24","event":"Attackers begin draining Triple-A hot wallets across Ethereum, TRON, TON, and Solana blockchain networks.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/25/triple-a-hot-wallets-drained-of-9-3m-across-tron-ethereum-ton-solana/"},{"date":"2026-07-25","event":"On-chain analyst Specter publicly flags the suspicious wallet drains. PeckShield confirms findings. Initial loss estimate of $9.3 million rises to $9.7 million as additional transactions are identified. Stolen funds consolidated into Ethereum address 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1 holding approximately 5,227 ETH.","source":"PeckShieldAlert via X; AMBCrypto","source_url":"https://x.com/PeckShieldAlert/status/2080833993633866106"},{"date":"2026-07-25","event":"Triple-A issues no public statement. Live deposits remain active, with new funds reportedly continuing to be drained into the compromised infrastructure as of time of reporting.","source":"AMBCrypto; crypto.news","source_url":"https://ambcrypto.com/triple-a-exploit-drains-9-7mln-across-4-chains-what-we-know-so-far/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision a392c8a1-ba5e-4ea3-b6e8-108b35ddd837
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.