Triple-A, a Singapore-based crypto payments company, appears to have lost more than $9.7 million in a multichain exploit that compromised its hot wallets across several blockchains. Reports from security analysts say the attacker drained funds from Triple-A wallets on TRON, Polygon, Arbitrum and Ethereum, highlighting how payment systems that span multiple chains can be exposed through hot wallet security.

The evidence so far indicates that Arbitrum was not the source of the exploit itself. Instead, it was one of the networks used to move the stolen assets. After the wallets were compromised, the attacker reportedly moved liquid assets across chains, swapped them, and then bridged the proceeds onto Ethereum, where the funds were ultimately consolidated into a single wallet. That final step matters because Ethereum offers deep liquidity for swapping and onward transfers.

Triple-A has not yet detailed exactly how its wallets were compromised or confirmed the final loss amount. The next key checkpoint will be whether the company explains how the exploit was executed, and whether any of the stolen funds are later traced from that Ethereum wallet into mixers or exchanges.