Armada Daily Repo Summary Archive
Custody / SOC 2

Triple-A hot wallet exploit reaches $11.8M as ongoing sweeps drain new deposits

The Block · Jul 26, 2026 6:38 PM EDT

Triple-A, a Singapore-based crypto payments firm, has seen losses from a hot-wallet exploit escalate to $11.8 million, with attackers reportedly continuing to sweep newly deposited funds in real time. The firm stated customer funds are unaffected but has not provided a detailed public incident report, raising transparency concerns. The attack's persistence suggests compromised key-management infrastructure rather than a one-time breach.

Armada's crypto-repo desk relies on Fireblocks for custody of BTC, ETH, SOL, and HYPE collateral, with a firm no-rehypothecation policy. The Triple-A incident is a direct operational analogue: hot-wallet sweep attacks are most dangerous when key-management controls lack real-time anomaly detection. Armada should confirm with Fireblocks that MPC threshold policies and transaction velocity limits would block a comparable sweep pattern, and validate that the incident-response runbook covers ongoing drain scenarios.

Suggested action Confirm Fireblocks MSA covers sweep-attack vectors; review operational runbook for detecting unauthorized collateral movements in real time.
Read the original article →