MCAP$2.78T-2.64%
BTC$82,794+0.19%ETH$2,494-0.22%SOL$109.46-0.70%XRP$1.40+0.22%
GOLD$4,216+1.43%
OIL$104.72+0.42%
STOCKTSLA$382.70+2.05%STOCKNVDA$229.28-0.52%STOCKAAPL$336.64-1.11%STOCKCOIN$179.39+4.30%STOCKMSTR$154.34+1.90%
BTC DOM59.6%
FEAR & GREED64Greed
Updated
Breaking crypto news, seconds after it happens

Whale alerts, listings and market-moving headlines on Telegram.

Join Telegram
Hacks & Exploits

Triple-A Attacker Routes $12.4M in Ether to Tornado Cash

Blockchain security firm Salus tracked 4,970 ETH sent to the mixer across 56 deposits following the payments firm's July breach.

Triple-A Attacker Routes $12.4M in Ether to Tornado Cash
Image: BullishMarketCap

The attacker responsible for the July treasury breach at crypto payments provider Triple-A transferred 4,970 Ether, valued at roughly $12.4 million, into privacy protocol Tornado Cash on Oct. 9, according to blockchain security firm Salus.

Salus reported that its monitoring system tracked 56 individual deposits into Tornado Cash, comprising 49 transactions of 100 ETH and seven transactions of 10 ETH. The attacker consolidated funds from two separate intermediary addresses through a single wallet before executing the deposits, with one stream including assets from earlier mixer withdrawals.

Get whale alerts first

Instant Telegram notifications for large on-chain moves.

Join Telegram

Fund Tracing and Consolidation

The transfers followed cross-chain movements executed on Sep. 6, during which the attacker bridged assets across blockchains to Ethereum, exchanged the tokens, and split the proceeds across two intermediary addresses. The attacker later funneled both streams through a single wallet before initiating the 56 mixer transactions.

The activity stems from an unauthorized wallet compromise on July 25 targeting Triple A Technologies Pte. Ltd., the company's Singapore entity. Initial tracing by investigators Specter and PeckShield documented more than $9.3 million to $9.7 million removed from wallets on TRON, Ethereum, Polygon, and Arbitrum, with subsequent loss estimates reaching approximately $11.8 million.

Treasury Breach and Remediation

Triple-A confirmed the security breach in late July, stating that the financial impact was absorbed entirely by company treasury reserves. Customer funds remained segregated in trust accounts maintained with safeguarding institutions, including DBS and Standard Chartered, as the firm does not provide digital asset custody.

An Aug. 21 post-mortem revealed the compromise originated from a social engineering attack on an engineering employee via impersonation and a live call. The perpetrator acquired elevated permissions, deployed malware, accessed production databases, and abused API credentials to process withdrawals. Triple-A engaged cybersecurity firm Sygnia for forensic reviews and zeroShadow for asset tracing, while alerting the Monetary Authority of Singapore and local police.

Key facts

  • The Triple-A attacker deposited 4,970 ETH (~$12.4 million) into Tornado Cash across 56 transactions on Oct. 9.
  • Deposits consisted of 49 transfers of 100 ETH and seven transfers of 10 ETH.
  • Triple-A's July breach resulted in an estimated treasury loss of $11.8 million.
  • Customer funds were held in separate trust accounts at DBS and Standard Chartered and were not impacted.
  • The exploit originated from social engineering against an engineer, compromising API credentials and permissions.
$ETH#TripleA#Ethereum#CryptoHacks

Source: crypto.news

This article is for information only and is not investment advice. BullishMarketCap news is produced with AI assistance from public sources and reviewed by our editors; see our editorial policy. Spotted an error? Tell us.

More Hacks & Exploits

View all →