Triple-A hack: the stolen ether went into DAI, back into ether, and through Tornado Cash twice

PublicAML · On-chain investigation · 10 October 2026

In July an attacker took about $11.8 million from the treasury of Triple-A, a Singapore crypto payments company, after tricking an engineer. On 9 October 4,970 ETH from the theft went into Tornado Cash. We read the Ethereum side from the first consolidation to that deposit. The attacker sold all 5,287 ETH for DAI three days after the theft, bought ether back two weeks later, and sent part of it through Tornado Cash twice: 1,414 ETH taken out of the mixer on 10 August went straight back in on 9 October. Nothing is left on the attacker’s Ethereum wallets.

7,672 ETH

deposited into Tornado Cash in three rounds: 6 Aug, 11 Sep, 9 Oct

1,414 ETH

withdrawn on 10 Aug and deposited again on 9 Oct — counted twice in that total

9.87M DAI

what 5,287 stolen ETH were sold for on 28 July

0 ETH

left on the 16 attacker wallets we followed, 10 Oct

What is known

Triple-A said in late July that its treasury hot wallets were drained on 24–25 July after an engineer was targeted with impersonation, messages on several channels and a live call; the attacker then used malware and API credentials to withdraw. Losses were about $11.8 million on Tron, Ethereum, Polygon, Arbitrum, Solana and TON. Client funds were not affected. PeckShield found the Ethereum consolidation address, 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1, with about 5,287 ETH.

On 9 October Salus reported that 4,970 ETH from the theft went into Tornado Cash in 56 deposits. Below is the path between those two points, read by us on 10 October 2026. We followed Ethereum only.

Out of ether, into DAI

On 28 July the consolidation address sent its 5,287 ETH to a second wallet, 0x9d358e54f405e120807D7a07B2895cE77Fe7d53D, which sold all of it through Uniswap and a swap aggregator in 27 trades within an hour and sent 9.87 million DAI back. The same morning a second stream did the same: 1,003 ETH collected on a separate wallet, 0x20f774Ae0C053CBc4fB12da30B0e15fcf02de245, was sold for about 1.87 million DAI.

Holding DAI rather than ether kept the money out of the one asset Tornado Cash takes in large pools, but it also kept it in a token whose issuer can freeze wallets. It was not frozen.

Back into ether, and into Tornado Cash

On 6 August 5.0 million DAI went to a fresh wallet, 0x33DfbC8B52596EcC7D2057F6b1DaD88AF8CbDe82, which bought ether and paid 2,620 ETH into Tornado Cash in 28 deposits between 03:20 and 07:37 UTC.

On 11 August the rest of the DAI was bought back into ether through three fresh wallets: 2,589 ETH returned to the consolidation address, and 995 ETH to the second stream’s wallet.

On 11 September another 82 ETH went into Tornado Cash from a side wallet, in ten deposits.

The round trip

On 10 August, between 15:32 and 16:07 UTC, a fresh wallet 0xd432925EC435823eF16c3BA5bB9D3e33D6E1a176 withdrew 1,414 ETH from Tornado Cash — fourteen 100 ETH notes and two 10 ETH notes. Minutes later it passed everything to another fresh wallet, and the next morning that wallet paid it into 0x20f774Ae0C053CBc4fB12da30B0e15fcf02de245, the second stream’s wallet, which had been the attacker’s since 26 July.

So the mixer did not break the link: money that came out of Tornado Cash landed on a wallet already tied to the theft. On 6 September both wallets moved their ether into two new holding wallets (2,642.9 ETH and 2,409.4 ETH). On 9 October both were emptied into one more fresh wallet, 0x4610Fc066be8AA647e134283aFeDeDc051bD66f0, which made the 56 deposits Salus reported — 4,970 ETH, 08:35 to 16:49 UTC — including the 1,414 ETH that had already been through the mixer once.

When (UTC)FromToAmountTx
28 Jul0x01F83B…5253b10x9d358e…e7d53D5,287 ETH
all stolen ETH sent to be sold for DAI
—
6 Aug0x33DfbC…CbDe820xd90e2f…24F31b2,620 ETH
first Tornado round, 28 deposits
—
10 Aug0xd43292…E1a1760xab9D61…E2C4071,413.8 ETH
withdrawn from Tornado Cash
—
11 Aug0xab9D61…E2C4070x20f774…2de2451,413.9 ETH
lands on a wallet already tied to the theft
—
6 Sep0x01F83B…5253b10xcFa210…F7165e2,642.9 ETH
stream one parked
—
6 Sep0x20f774…2de2450xc6Bbd4…64901B2,409.4 ETH
stream two parked, mixer money included
—
9 Oct0x4610Fc…bD66f00xd90e2f…24F31b4,970 ETH
second Tornado round, 56 deposits
—

What we did

We marked 16 Ethereum addresses in our database as connected to this theft: the consolidation address, the swap wallets, the two holding wallets, the Tornado depositors and the withdrawal wallet. None of them was marked before; the consolidation address had been scored as an ordinary sweeping wallet. We did not mark Uniswap, the swap aggregator, the bridges or Tornado Cash.

All 16 are empty. The other five chains we have not traced; if you hold the attacker’s Tron or Solana addresses, tell us. To check an address yourself, use the address check.

What this page does not say

It does not say who the attacker is. It does not say that Triple-A, Uniswap, the swap aggregator or any bridge did anything unlawful. The size of the theft and the attack method are Triple-A’s and PeckShield’s; the 9 October deposit was first reported by Salus. The path, the DAI detour and the round trip are ours, read on 10 October 2026.

Check an address yourself

Free, no sign-up. Paste any address to see whether it is linked to this or any other incident:

Sources: Triple-A’s statement of July 2026; PeckShield on the consolidation address; Salus on the 9 October deposit; Ethereum chain data via Blockscout, read by PublicAML on 10 October 2026. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.