Triple-A, a Singapore-based crypto payments firm, has seen losses from a hot-wallet exploit escalate to $11.8 million, with attackers reportedly continuing to sweep newly deposited funds in real time. The firm stated customer funds are unaffected but has not provided a detailed public incident report, raising transparency concerns. The attack's persistence suggests compromised key-management infrastructure rather than a one-time breach.
Armada's crypto-repo desk relies on Fireblocks for custody of BTC, ETH, SOL, and HYPE collateral, with a firm no-rehypothecation policy. The Triple-A incident is a direct operational analogue: hot-wallet sweep attacks are most dangerous when key-management controls lack real-time anomaly detection. Armada should confirm with Fireblocks that MPC threshold policies and transaction velocity limits would block a comparable sweep pattern, and validate that the incident-response runbook covers ongoing drain scenarios.