Funds stolen in the Triple-A treasury breach are on the move again after sitting dormant for nearly three months. The hacker transferred 4,970 ETH worth approximately $12.4 million to the Tornado Cash protocol on Oct. 9, 2026. The movement was reported by blockchain security firm Salus after tracking the attacker’s addresses.
The Oct. 9 transfer marks the first activity since the treasury theft in July 2026. Salus discovered that the stolen funds were not sent all at once, but rather split into 49 deposits of 100 ETH each and 7 deposits of 10 ETH.
Winding Route to the Mixer
A total of 49 large deposits totaling 4,900 ETH and 7 small deposits totaling 70 ETH were sent in stages. The funds did not flow directly from the source wallet to Tornado Cash. Salus noted that the assets passed through two separate intermediary routes before being consolidated into a single wallet that executed the deposits into the protocol.
One of the two intermediary routes even contained funds from previous mixer withdrawals. The attacker set up a multi-layered route to break on-chain analytical trails before the funds entered Tornado Cash.
The value of the moved assets now exceeds initial estimates when the incident first came to light. Security firm Specter initially estimated Triple-A’s losses in July at around $11.8 million. On July 25, 2026, the balance at the recipient address was approximately 5,226.66 ETH worth $9.7 million. A rally in Ethereum’s price made the 4,970 ETH moved as of October worth a higher $12.4 million.
Entry Point via Phone Call
An August 2026 post-mortem report revealed the breach’s initial entry vector. The attack began with social engineering targeting engineering personnel. The perpetrator posed as legitimate personnel, used multi-channel communications, and directly called the target to obtain internal system access.
That tactic had fatal consequences. The attacker secured elevated system permissions, deployed malware, accessed production databases, and abused API credentials. Through those vulnerabilities, the hacker drained operational wallets across the TRON, Ethereum, Polygon, and Arbitrum networks.
Triple-A, a Singapore-based crypto payment gateway provider, confirmed unauthorized access on July 25, 2026. Management assured that customer funds remained secure in segregated trust accounts at partner banks such as DBS and Standard Chartered, and stated that the company ‘remains well capitalised.’
Unresolved Legal Status
The transfer of stolen funds to Tornado Cash comes at a time when the privacy protocol’s standing has shifted in the eyes of regulators. The U.S. government lifted sanctions against Tornado Cash in March 2025, restoring the legal status of public interactions with the protocol’s smart contracts.
Although sanctions against the protocol were dropped, legal proceedings against its developers remain ongoing. The retrial for Tornado Cash co-founder Roman Storm has been officially postponed until April 2027. While legal debates over privacy are far from settled in court, on the blockchain, the protocol remains an active tool for laundering stolen funds.
For the crypto industry, the Triple-A case proves that operational wallets can be compromised not through code flaws, but through human interactions that slip past scrutiny.
Via crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




