Triple-A Hacker Moves $12.4 Million in Ether to Tornado Cash
Published October 11, 2026, 11:45 PKT. Based on October 10 reporting by crypto.news and TokenPost on blockchain security firm Salus's tracing, Triple-A's July 27 incident statement, and the company's August 21 post-mortem.
The attacker behind July's $11.8 million breach of Singapore payments firm Triple-A moved 4,970 ETH, worth about $12.4 million, into Tornado Cash on October 9 through 56 deposits, according to blockchain security firm Salus. Salus's Tornado monitoring system tracked 49 deposits of 100 ETH and seven deposits of 10 ETH linked to the attacker, the firm reported, with both streams consolidated through a single wallet before hitting the mixer.
The 56 deposits and the two-stream consolidation
According to Salus, the attacker first separated the loot into two intermediary addresses on September 6, after moving assets across blockchains to Ethereum and swapping them into Ether, crypto.news reported. On October 9, both streams were routed through a single wallet and deposited into Tornado Cash. One of the two streams included funds from an earlier withdrawal from a mixer, Salus said, a detail that suggests the attacker had already tested the laundering route before committing the full amount.
The 4,970 ETH figure is slightly larger than the roughly $11.8 million loss publicly estimated at the time of the July breach, a gap consistent with Ether's price appreciation between the theft and the October laundering. Earlier tracing had already identified Ethereum as a destination for the stolen assets: on July 25, researchers put the receiving address's balance at approximately 5,226.66 ETH, worth about $9.7 million at the time, crypto.news reported.
The July breach that started it
Triple-A detected the unauthorized access on July 25 and confirmed it publicly by July 27, saying the compromised wallets belonged to Triple A Technologies Pte. Ltd., its Singapore entity. The company temporarily placed certain services into maintenance mode for about three hours while securing the affected infrastructure, according to its official statement. Customer funds were not affected, Triple-A said, because they sit in separate trust accounts with safeguarding institutions, including DBS and Standard Chartered, and the company does not provide digital asset custody on clients' behalf.
The financial impact was absorbed through Triple-A's treasury reserves. "Triple-A remains well capitalised, is able to meet all its liabilities," the company stated. The firm immediately notified the Monetary Authority of Singapore and Singapore police, and engaged forensic specialist Sygnia plus blockchain tracing firm zeroShadow for the investigation and recovery effort.
How social engineering broke in
In its August 21 post-mortem, Triple-A said the attack began with social engineering against an engineering employee. The approach involved impersonation, communications across different channels, and a live call, the report said. After compromising the employee's credentials, the attacker obtained elevated system permissions, deployed malware, accessed production databases, and abused API credentials to execute cryptocurrency withdrawals.
The post-mortem identified affected operational wallets on TRON, Ethereum, Polygon, and Arbitrum. Triple-A said remediation included tighter access and approval requirements, credential restrictions, separation of operational environments, expanded monitoring, and reviews of wallet exposure limits. Active attacker access was removed and identified persistence mechanisms eliminated, while tracing and potential freezing actions remained in progress, the company said.
The mixer the funds just entered
Tornado Cash is the most scrutinized mixer in crypto. The U.S. Treasury removed its sanctions designation in March 2025, reversing the designation imposed in August 2022, after a review of legal and policy questions around financial sanctions and evolving technology, according to the department's announcement. The department said it would continue monitoring transactions that could benefit malicious cyber actors or North Korea.
Legal pressure continues in parallel. Co-founder Roman Storm's retrial is scheduled for April 26, 2027, after his first jury convicted him in August 2025 of conspiracy to operate an unlicensed money transmitting business but deadlocked on money laundering and sanctions conspiracy charges, crypto.news reported. The October 9 deposits show laundering activity continuing regardless: stolen treasury funds can now move through the mixer at a moment when both its legal status and its court battle remain unresolved.
This article is news reporting and is not investment advice.
Sources
- Blockchain security firm Salus, Tornado Cash monitoring report on the October 9 deposits, via crypto.news, primary source for the 4,970 ETH, 56-deposit and two-stream tracing
- crypto.news, "Triple-A attacker moves $12.4m in ETH to Tornado Cash" (October 10, 2026), primary source for Salus's tracing details and the July 25 initial reporting
- TokenPost, "Triple-A Hack-Linked Wallet Moves $12.4 Million in Ether to Tornado Cash" (October 10, 2026), secondary source
- Triple-A, official incident statement (July 27, 2026), primary source for the detection timeline, the Singapore entity, the treasury absorption, and the MAS/police notification
- Triple-A, post-mortem (August 21, 2026), primary source for the social-engineering attack chain and the remediation measures
MABOnChain Daily Brief
The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.
Prefer chat? Join us on Telegram
Keep reading
France's Crypto Tax Plans Hit a Wall as Finance Committee Rejects Budget 31-3
France's National Assembly Finance Committee rejected the 2027 budget's revenue section 31-3 on October 9, stranding three crypto tax amendments it had just approved: a stablecoin swap tax, an exit tax on crypto over 800,000 euros, and a 10-year loss carryforward. Supporters must table them again when floor debate starts October 13, with a formal vote due October 20.
Ledger Confirms Tampered Hardware Implant in CryptoBilis Wallet Drain Probe
Ledger confirmed on October 10 that a device belonging to one affected CryptoBilis customer contained an unauthorized hardware implant, the first official evidence of physical tampering in the wallet-drain scandal that on-chain trackers now place above $93 million. CryptoBilis has suspended all hardware-wallet sales while Ledger works with authorities and security response group SEAL 911.
Coinbase Gives European Users Until October 30 to Move USDT, PYUSD and DAI Off the Exchange
Coinbase told European Economic Area customers to withdraw USDT, PYUSD, DAI, PAX, GUSD and GYEN by October 30, 2026, after which remaining balances will be automatically converted into USDC, as the exchange gets ahead of the EU's MiCA stablecoin crackdown.


