Triple-A's hot wallets were drained of $9.7 million in an apparent security breach, with new outflows continuing more than 31 hours after the first major withdrawals, according to onchain investigator Specter.

The custodian said customer funds are not affected and that it is investigating the incident. Hot wallets, which hold cryptocurrency readily available for transactions, are a common target for attackers because they are connected to the internet and carry operational liquidity that cold storage does not.

Rain total value locked, last 90 days
Rain total value locked, last 90 days · MSB Intel data desk

Triple-A operates as a institutional custody and wallet infrastructure provider serving over-the-counter desks, exchanges and institutional traders across Asia. The company has processed billions in transaction volume and manages crypto holdings for clients ranging from retail to high-net-worth accounts.

MSB Intel

Onchain data showed deposits being swept from Triple-A's wallets in multiple transactions starting roughly 31 hours before the public disclosure. Specter flagged the outflows on X, drawing attention to the ongoing nature of the drain and the company's statement that the breach had not compromised customer-held assets.

The 31-hour window between first outflows and the company's public response is longer than many institutional custody breaches disclosed in recent years. In June 2022, Celsius Network froze withdrawals within hours of detecting unauthorized access to one of its hot wallets; the firm later disclosed $35 million in losses from the incident. Voyager Digital's 2022 breach surfaced within a day of the unauthorized access of its Ethereum hot wallet, ultimately costing the platform $270 million.

Triple-A's statement that customer funds remain unaffected hinges on the distinction between its own operational wallets and segregated customer custody accounts. The company has not yet disclosed whether the drained funds belong to its operating reserves, customer collateral held in pooled wallets, or a combination. An extended drain window in a custodial environment typically means either a delayed detection system or a gradual exploitation of access rather than a single exploitation event.

The incident occurs as institutional custody providers face intensifying pressure to prove key management and access controls. Regulatory scrutiny of self-custodied and third-party wallet security has accelerated in major jurisdictions, and any breach involving customer funds, even if those funds are later recovered or insured, can trigger withdrawal rushes and client attrition. If Triple-A's customer assets remain genuinely isolated from the breach, the firm's ability to retain clients will depend on how quickly it identifies the entry vector and demonstrates remediation.