Newsroom
10 October, 2026 / News / AI / Tags: triple, tornado, salus, attacker, breach

Wallets tied to the July treasury theft deposited 4,970 ETH across 56 transactions on Oct. 9 after consolidating funds from two intermediary addresses
Blockchain security firm Salus reported that addresses connected to the attacker behind Triple-A’s July treasury breach moved 4,970 ETH, valued at approximately $12.4 million, into Tornado Cash on Oct. 9. The activity consisted of 49 deposits of 100 ETH each and seven deposits of 10 ETH. Salus tracking showed the attacker first combined two separate fund streams through a single wallet before executing the mixer deposits. One of those streams contained assets from prior withdrawals from the same mixing service.
According to the firm’s analysis, the funds had earlier been moved across blockchains onto Ethereum, converted, and then divided between two intermediary addresses on Sept. 6. Those holdings were later gathered into one address that carried out the Tornado Cash transfers. Salus valued the combined deposits at roughly $12.4 million and linked the wallet activity directly to the individual responsible for the Triple-A theft.
The original incident occurred in late July when unauthorized access drained assets from Triple-A’s operational treasury wallets. Public estimates placed the loss near $11.8 million. Early on-chain analysis identified a receiving address holding about 5,226.66 ETH, then worth roughly $9.7 million, after assets were exchanged and bridged to Ethereum. Later assessments revised the total impact higher.
Triple-A, a payments provider, confirmed the breach on July 27. The company stated that the compromised wallets belonged to its Singapore entity, Triple A Technologies Pte. Ltd., and that no other group entities or operations were affected. Customer funds remained untouched because they were held separately in trust accounts with safeguarding institutions; Triple-A does not provide digital-asset custody for clients.
The firm temporarily placed certain services into maintenance mode for about three hours while securing systems. Transactions and settlements resumed normally across markets once checks were completed. Triple-A notified the Monetary Authority of Singapore and Singapore police and engaged cybersecurity and forensic specialists for investigation and recovery work.
In an Aug. 21 post-mortem, Triple-A described the attack vector as social engineering directed at an engineering employee. The approach involved impersonation, multi-channel communications, and a live call. Once credentials were compromised, the attacker escalated privileges, deployed malware, accessed production databases, and abused API credentials to initiate cryptocurrency withdrawals.
Affected operational wallets spanned TRON, Ethereum, Polygon, and Arbitrum. Customer balances stayed isolated in trust accounts with institutions that included DBS and Standard Chartered. Remediation steps included stricter access controls, credential restrictions, separation of operational environments, expanded monitoring, and reviews of wallet exposure limits. Active attacker access was removed and persistence mechanisms eliminated, while asset tracing and potential freezing actions continued.
Triple-A retained Sygnia for forensic analysis and security hardening and zeroShadow for asset tracing. The company has stated that recovery efforts remain active. The Oct. 9 Tornado Cash deposits represent the most recent confirmed movement of the stolen Ether after months of cross-chain transfers and consolidation.
Tornado Cash had its U.S. sanctions designation removed by the Treasury Department in March 2025 following a review of legal and policy considerations. The department indicated it would continue monitoring transactions that could benefit malicious actors. Separate legal proceedings involving a Tornado Cash co-founder remain ongoing, with a retrial scheduled for April 2027.









