The attacker behind Triple-A’s July treasury breach has transferred 4,970 ETH worth approximately $12.4 million into Tornado Cash, according to blockchain security firm Salus. Summary 4,970 ETH entered Tornado Cash on Oct. 9 through 56 deposits, according to Salus. The attacker combined funds from two intermediary addresses through a single wallet before depositing them. Triple-A said the July breach affected company treasury assets, while customer funds remained untouched. The company attributed the attack to social engineering and engaged specialists to trace the stolen assets. Salus said its Tornado monitoring system tracked 49 deposits of 100 ETH and seven deposits of 10 ETH linked to the Triple-A attacker on Oct. 9. In its account of the transactions, the security firm described two streams of funds that passed through separate intermediary addresses before reaching one wallet. Salus said the attacker used that wallet to make the Tornado Cash deposits, with one stream containing funds from earlier withdrawals from the mixer. The firm valued the combined deposits at approximately $12.4 million. Its tracing account placed the transfers after the attacker had moved assets across blockchains to Ethereum, exchanged the tokens, and divided the funds between two addresses on Sep. 6. Triple-A attacker combined two fund streams before depositing ETH According to Salus, the Sep. 6 transfers separated the funds into two intermediary wallets after the cross-chain movements and asset swaps. The attacker later routed both streams through a single address before depositing the Ether into Tornado Cash. In the post, Salus stated: “One stream included funds from earlier withdrawals.” The firm’s transaction breakdown puts 4,900 ETH in the 49 larger deposits and another 70 ETH in the seven smaller deposits. Its account links the activity to the attacker responsible for stealing Triple-A’s own treasury assets in July, when public estimates placed the loss at approximately $11.8 million. Earlier tracing had already identified Ethereum as a destination for assets removed from wallets associated with the payments company. On July 25, crypto.news reported the wallet drain, citing researchers who put the receiving address’s balance at approximately 5,226.66 ETH, worth about $9.7 million at the time. In that initial reporting, blockchain investigator Specter estimated that more than $9.3 million had been removed, exchanged, and bridged to Ethereum. PeckShield subsequently drew attention to the transactions, while later estimates put the suspected loss above $9.7 million. Triple-A said the July breach affected its treasury assets By July 27, Triple-A had confirmed unauthorized wallet access and said the financial impact would be absorbed through its treasury reserves. The report attributed the approximately $11.8 million loss estimate to Specter. In its official statement, the company said it detected unauthorized access on July 25 and temporarily placed certain services into maintenance mode for approximately three hours while securing the affected infrastructure. Triple-A said the compromised wallets belonged to Triple A Technologies Pte. Ltd., its Singapore entity. According to the statement, no other company entities or operations were affected, and transactions and settlements resumed normally across all markets after security checks. Addressing its financial position, Triple-A stated: “Triple-A remains well capitalised, is able to meet all its liabilities.” The company also said customer funds were held separately in trust accounts maintained with safeguarding institutions. According to Triple-A, those accounts were not exposed because it did not provide digital asset custody on behalf of its clients. In the same statement, the payments provider identified internal and external cybersecurity experts, blockchain forensic specialists, and Singapore police as participants in its investigation and asset-recovery efforts. Social engineering gave the attacker access to operational systems In an Aug. 21 post-mortem, Triple-A said the attack began with social engineering against an engineering employee. According to the company, the approach involved impersonation, communications across different channels, and a live call. After compromising credentials, the attacker obtained elevated system permissions, deployed malware, accessed production databases, and abused API credentials to execute cryptocurrency withdrawals, the report said. The company identified affected operational wallets on TRON, Ethereum, Polygon, and Arbitrum. Its post-mortem said customer money remained in separate trust accounts with institutions including DBS and Standard Chartered. For the investigation, Triple-A engaged Sygnia to conduct forensic work and strengthen security controls, while zeroShadow handled asset tracing and supported recovery efforts. The company said it notified the Monetary Authority of Singapore and Singapore police immediately after detecting the incident. According to the report, remediation included tighter access and approval requirements, credential restrictions, separation of operational environments, expanded monitoring, and reviews of wallet exposure limits. Triple-A said active attacker access had been removed and identified persistence mechanisms eliminated, while tracing and potential freezing actions remained in progress. Tornado Cash sanctions were removed while U.S. proceedings continued In March 2025, the U.S. Treasury removed Tornado Cash sanctions, reversing the designation imposed in August 2022. Treasury’s delisting announcement said the decision followed its review of legal and policy questions concerning financial sanctions and evolving technology. The department nevertheless said it would continue monitoring transactions that could benefit malicious cyber actors or North Korea. Separately, an Aug. 26 report detailed how a U.S. judge had postponed Roman Storm’s retrial until April 26, 2027. According to the Aug. 25 court order, Judge Katherine Polk Failla granted the Tornado Cash co-founder’s request after his defense cited scheduling conflicts and a pending acquittal motion. The report said Storm’s first jury convicted him in August 2025 of conspiracy to operate an unlicensed money transmitting business but deadlocked on money laundering and sanctions conspiracy charges. Under the revised calendar, the final pretrial conference was scheduled for April 20, 2027, six days before the retrial.
