Key Takeaways
- Hackers gained unauthorized entry to Triple-A’s treasury wallets, a Singapore-based crypto payments company
- Total losses climbed to $11.8 million, exceeding early projections of $9.3 million
- Compromised wallets continued receiving and losing deposits 31 hours post-initial detection
- Customer deposits remained secure in segregated trust accounts
- Company collaborating with blockchain analysts, security experts, and local law enforcement
On Monday, Triple-A, a Singapore-domiciled stablecoin payment processor, acknowledged that unauthorized parties infiltrated its treasury wallets during the weekend, siphoning off $11.8 million in corporate digital holdings.
Onchain investigator Specter initially raised the alarm on Friday, estimating damages at $9.3 million. However, by Sunday, the total had escalated to $11.8 million as the drainage persisted.
According to Triple-A, the intrusion was identified on Saturday, prompting the firm to temporarily suspend certain operations for approximately three hours while implementing security measures.
The organization reports that all platforms have resumed full functionality and payment processing has returned to standard operations.
Customer Assets Held in Segregated Accounts
Triple-A emphasized that no client assets were compromised. The firm doesn’t maintain custody of customer digital currencies. Rather, client deposits are maintained in trust arrangements with independent safeguarding entities.
This framework aligns with Singapore’s Payment Services Regulations, which mandated from October 2024 that licensed cryptocurrency payment providers maintain customer holdings in distinct blockchain addresses.
Triple-A hasn’t disclosed the method of unauthorized access or the total value stored in the compromised accounts. The $11.8 million assessment derives from blockchain analysis conducted by Specter and security platform PeckShield, rather than official company disclosure.
Stolen Assets Transferred Across Multiple Blockchains
The illicit transfers occurred across multiple blockchain ecosystems, encompassing Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin.
The stolen assets were consolidated at one Ethereum wallet address. PeckShield’s monitoring revealed this address contained more than 5,226 ETH, valued at approximately $9.73 million, accumulated through eight separate transfers occurring between Friday night and Saturday morning in UTC time.
Specter observed that incoming deposits to the breached wallets were being instantly transferred out even 31 hours following the detection of the first significant withdrawals.
Triple-A operates under a license from the Monetary Authority of Singapore and maintains payment authorization in France via its European subsidiary, Paytop SAS. The company is also registered as a money services operator in both the United States and Canada.
The firm stated it’s coordinating with cybersecurity professionals, blockchain forensic analysts, and the Singapore Police Force to track the stolen funds and facilitate recovery operations.
Triple-A has yet to release the comprehensive statement it committed to providing on Saturday. Its press center currently displays a July 15 announcement regarding preliminary approval from Dubai’s Virtual Assets Regulatory Authority.
This incident represents one of three significant cryptocurrency exploits documented this week. AFX Trade suffered approximately $24.15 million in losses through its Arbitrum custody bridge. The Verus-Ethereum bridge experienced losses of about $7.54 million on the same day, representing its second security breach since May.


