Wednesday, July 29, 2026

Triple-A hack explained: tracing the $11.8M stablecoin treasury breach on-chain

Global News
By Scorechain Team
Share

Scorechain Research. July 28, 2026.

The Triple-A hack drained roughly $11.8 million from a licensed payment institution's own treasury over a single weekend, moved it across seven blockchains, and today converted it from Ether into the DAI stablecoin. Not one merchant lost a cent. This investigation walks through what happened, how the funds were laundered across bridges, where the money sits right now, and what the incident means for any compliance team running crypto transaction monitoring.

Crypto hack losses in 2026 are increasingly a story about access, not code, and the Triple-A hack is the clearest example yet. Here is the full on-chain picture, traced end to end with Scorechain.

What happened in the Triple-A hack

Triple-A Technologies is a Singapore-based stablecoin payment gateway serving more than 1,000 enterprise merchants. It holds a Major Payment Institution licence from the Monetary Authority of Singapore and is registered as a crypto-asset service provider in Europe. On July 27, 2026, the firm confirmed that attackers had drained its corporate treasury wallets across seven blockchains in a sweep that ran for roughly 31 hours.

The affected networks were Ethereum, Solana, TRON, The Open Network, Polygon, Arbitrum, and Bitcoin, with the stolen value consolidated on Ethereum. On-chain investigators first estimated losses near $9.3 million, then revised the figure to $9.7 million and finally to roughly $11.8 million as more of the outflow was traced across Bitcoin and TRON. Triple-A has said its treasury reserves can absorb the loss and that it can meet all liabilities.

Triple-A hack timeline, July 24 to 28, 2026

The first suspicious outflow left Triple-A's infrastructure on Friday, July 24, 2026, at approximately 19:34 UTC. Sweeping of the treasury wallets continued for about 31 hours. Triple-A identified the intrusion over the weekend, paused services for around three hours to secure affected systems, and confirmed the breach publicly on July 27. On July 28, the attacker took the next step and began converting the stolen Ether into a stablecoin, a development covered in detail below.

Were client funds affected? Why segregation held

The most important finding in the Triple-A hack is also the most reassuring. The $11.8 million belonged to Triple-A, not to its customers. It came from the firm's own operational treasury hot wallets.

Merchant funds sat in segregated trust accounts mandated by the Monetary Authority of Singapore and were untouched throughout the incident, because Triple-A does not custody digital assets on behalf of its merchants. The safeguarding model held exactly as intended, which is why an eight-figure treasury loss produced zero client impact. For any virtual asset service provider or stablecoin issuer, that is the case for client-asset segregation demonstrated in a single event.

How the Triple-A hack happened: an access-layer compromise, not a code exploit

Triple-A has not disclosed the attack vector, but the on-chain behaviour is telling. The attacker maintained access for about 31 hours and repeatedly re-swept newly arriving deposits. That is not a single unauthorized transaction. It is sustained, authenticated access to the wallet-management layer, which points to a credential or access compromise rather than a smart contract exploit or a stolen private key.

Why an MPC wallet did not stop the attack

Triple-A operates with Fireblocks multi-party computation for key management. No researcher has attributed the breach to Fireblocks, and the reason matters. An MPC wallet protects the private key by splitting it so that no single party ever holds it. It does not, on its own, stop an attacker who has obtained the ability to issue valid signing requests. If the compromise sat at the transaction-initiation layer, the MPC setup would sign what it was legitimately asked to sign.

This is the central lesson of the Triple-A hack: key custody and access control are different disciplines. The controls that would have blocked this attack are allowlists, velocity limits, and approval through a separate channel, backed by continuous transaction monitoring on operational treasury wallets, not only on customer flows.

Following the money: cross-chain bridge tracing

The Triple-A hack is a case study in cross-chain laundering, and in why bridge tracing is now a core capability rather than a nice-to-have. Scorechain's multi-hop analysis attributes the $11.23 million that reached the Ethereum consolidation hub to a small set of bridges and decentralized exchange aggregators.

The bridges and DEX aggregators the attacker used

Roughly 78% of the stolen value was routed through four cross-chain services:

  • Relay: 26.1%
  • Chainflip: 24.6%
  • deBridge: 13.4%
  • CoW Swap: 11.2%
  • NEAR Intents: 2.7%
  • Across Protocol: 2.3%

The attacker used chain-hopping aggressively to break the trail, moving value between Ethereum, Solana, TRON, The Open Network, Polygon, Arbitrum, and Bitcoin before consolidating on Ethereum. Following funds across that many bridges by hand is where most investigations stall. Scorechain's Flux Analysis reconstructs the full path visually, hop by hop, so the cross-chain movement resolves into a single, readable flow.

The consolidation hub, hoard wallet, and swap wallet

Scorechain has published a dedicated entity, "Triple-A drainer (07-26)", classified as a hack with a risk score of 1 out of 100, the most severe rating on the scale. The Ethereum cluster comprises six addresses. Four are central to the story:

The consolidation hub (0x8335d258438e47cd8eb1532c04cfe445e011aef6) received $11,235,880 and forwarded almost all of it, leaving a $29 residual across 109 transactions. The sweeper (0x9a28573c8c29ceedcf4193769fac01775b2c946a) processed $612,774 across 163 transactions, consistent with scraping many small merchant-settlement balances. The hoard wallet (0x01f83b5d4fb30e8aa3dac1681b4048d9135253b1) held the bulk of the proceeds. And a swap wallet (0x9d358e54f405e120807d7a07b2895ce77fe7d53d) is where the most recent movement runs through.

From ETH to DAI: the swap that did not break the trail

For roughly three days the hoard wallet sat still, holding about 5,287 ETH worth close to $9.94 million, with no mixer contact. On July 28, 2026, that changed. The attacker routed the 5,287 ETH into a swap wallet (0x9d358e54f405e120807d7a07b2895ce77fe7d53d), converted it into the DAI stablecoin, and forwarded the proceeds. That swap wallet received the full 5,287 ETH, passed 9,870,193 DAI straight through, and now holds effectively nothing (a $0.04 residual). Note the distinction between throughput and balance: the swap wallet shows the full DAI amount in its history because it passed the funds on, not because it holds them.

The value did not disappear. It is now parked as approximately $9.87 million in DAI in the hoard wallet (0x01f83b5d4fb30e8aa3dac1681b4048d9135253b1), which has sent nothing out, still in a single address, still with no exposure to mixers, sanctioned entities, darknet markets, or ransomware infrastructure. Scorechain followed the funds through the ETH-to-DAI conversion without losing the trail, which is the point: a swap into a stablecoin changes the asset, not the traceability.

Converting Ether into DAI is a common de-risking move. It locks in dollar value and can look like ordinary DeFi activity, but with full blockchain analytics it remains fully attributable to the Triple-A drainer cluster.

Can the stolen crypto be recovered?

Recovery prospects in the Triple-A hack are unusually favourable, and time-sensitive. Three factors work in investigators' favour.

First, about $9.87 million now sits as DAI in one wallet with no mixer contact, which keeps it fully traceable. Second, roughly $307,000 has already reached regulated exchanges, including venues attributed to OKX, Bitget, Binance, and Kraken, where it can be frozen and attributed today. Third, the victim is a licensed institution already working with the Singapore Police Force, which shortens the path from on-chain evidence to legal action. This is the stage where crypto investigation and asset recovery work best, while the trail is fresh.

The window will not stay open. The moment the DAI moves toward a mixer or fresh exchange deposit addresses, the calculus changes. Continuous wallet screening and monitoring of the hoard wallet is the single highest-value control right now.

One coverage note: Scorechain currently labels the Ethereum cluster. The attacker addresses on TRON, Bitcoin, Solana, and The Open Network are not yet published, which leaves the difference between the $9.87 million hoard and the $11.8 million estimate, roughly $1.9 million, unlocated by this analysis.

What the Triple-A hack means for crypto compliance and AML teams

The Triple-A hack fits a pattern that has defined 2026. For the third consecutive week, an eight-figure crypto hack has been driven by credential and access compromise rather than by a smart contract exploit. Measured by dollar value, compromised accounts have overtaken code vulnerabilities as the leading cause of large crypto theft. Detection strategies tuned only for contract exploits will miss this entire category.

Transaction monitoring belongs on treasury wallets, not just customer flows

For virtual asset service providers and stablecoin issuers, three practical takeaways stand out. Custody controls and access controls are separate problems, and a strong answer on one does not cover the other. Vendor due diligence should probe transaction-initiation controls specifically, allowlists, velocity limits, and out-of-band approval, not only key-custody architecture. And transaction monitoring should extend to an institution's own treasury movements, because in this incident the treasury was the target.

The reassuring half of the story is that the regulatory model worked. Segregated client accounts under the Monetary Authority of Singapore held. Under the European framework, the Markets in Crypto-Assets Regulation (MiCA) and the Sixth Anti-Money Laundering Directive (AMLD6) push in the same direction: segregation of client assets, robust governance of operational wallets, and traceability of flows under the Financial Action Task Force (FATF) Travel Rule.

How Scorechain traces incidents like the Triple-A hack

Scorechain has published the "Triple-A drainer (07-26)" entity (id 9130207) with full address attribution, risk scoring, and multi-hop, cross-chain fund-flow analysis. Compliance teams can screen the hoard wallet and the wider cluster for direct and indirect exposure, follow the funds through the bridges and the ETH-to-DAI swap, and monitor every address for outbound movement in real time.

If you want to see how blockchain forensics resolves a bridge-heavy laundering path, or assess your own exposure to this entity, book a demo and trace the full cluster on the platform.

Frequently asked questions

What is the Triple-A hack?

The Triple-A hack is a July 2026 breach in which attackers drained roughly $11.8 million from the corporate treasury of Triple-A, a Singapore-based stablecoin payment gateway, across seven blockchains over about 31 hours. Client funds were not affected.

How much was stolen in the Triple-A hack?

On-chain investigators estimate about $11.8 million, revised up from initial figures of $9.3 million and $9.7 million as more of the outflow was traced across Bitcoin and TRON. Triple-A has not published its own figure.

Were Triple-A customer funds affected?

No. The stolen funds came from Triple-A's own treasury. Client funds sat in segregated trust accounts mandated by the Monetary Authority of Singapore and were untouched, because Triple-A does not custody crypto for its merchants.

How were the stolen funds laundered and traced across bridges?

The attacker moved value across seven chains and consolidated it on Ethereum, routing roughly 78% through four bridges and DEX aggregators: Relay, Chainflip, deBridge, and CoW Swap. Scorechain traced every hop across the bridges and found no exposure to mixers, sanctioned entities, or darknet infrastructure.

What is DAI, and why did the attacker swap ETH into it?

DAI is a US-dollar stablecoin. On July 28, 2026, the attacker swapped the stolen 5,287 ETH into roughly $9.87 million in DAI. Converting to a stablecoin locks in dollar value and can resemble ordinary DeFi activity, but the funds remain fully traceable on-chain.

Can the stolen crypto be recovered?

Recovery prospects are unusually favourable but time-sensitive. About $9.87 million sits as DAI in one wallet with no mixer contact, and roughly $307,000 has already reached regulated exchanges where it can be frozen and attributed. The odds fall sharply once the funds move again.

Want to see how Scorechain can help you trace illicit crypto flows and strengthen compliance?

Be the first to get news from Scorechain

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

350+ COMPLIANCE &  DIGITAL ASSET TEAMS TRUST US