Singapore based crypto payments firm Triple-A has confirmed that unauthorized actors gained access to several of its treasury wallets, resulting in the loss of company owned digital assets. While the company has not disclosed the total amount stolen, blockchain investigators estimate the losses have risen to approximately $11.8 million.
Triple-A said the breach affected only its operational treasury accounts and did not impact customer assets. The company stressed that client funds remain protected because they are held separately in trust accounts and are not custodied within the compromised wallets.
Key Takeaways
- Triple-A confirmed unauthorized access to its treasury wallets on July 25.
- Blockchain investigators estimate total losses have increased to approximately $11.8 million.
- The company said customer funds were not affected because they are held separately in safeguarded trust accounts.
- Triple-A temporarily placed certain services into maintenance for about three hours before restoring operations.
- An investigation involving cybersecurity experts, blockchain forensic specialists, and the Singapore Police Force is underway.
Triple-a Confirms Wallet Compromise
Triple-A announced that it detected unauthorized access to certain wallets containing the company’s own digital assets on July 25.
As a precaution, the Singapore based payment provider placed parts of its platform into maintenance mode for approximately three hours while it secured the affected infrastructure. After completing its response, the company restored all services and resumed transaction processing and settlements across its markets.
In its statement, Triple-A emphasized that the incident was limited to operational treasury accounts and did not affect customer funds. The company said it remains well capitalized, can meet all of its financial obligations, and will absorb the losses using its own treasury reserves.
Onchain Analysis Points to Larger Losses
Although Triple-A did not disclose the value of the stolen assets, blockchain investigators have provided estimates based on onchain activity.
Blockchain analyst Specter initially estimated that attackers had drained more than $9.3 million from the company’s hot wallets before bridging the assets to Ethereum.
Blockchain security firm PeckShield later increased the estimate to more than $9.7 million, reporting that approximately 5,227 ETH had been consolidated into a single Ethereum wallet. Subsequent analysis by Specter suggested that the attack continued beyond the initial compromise. The investigator estimated total losses had reached approximately $11.8 million, noting that additional deposits continued to enter the compromised wallets and were immediately transferred out for roughly 31 hours after the first suspicious transactions were detected.
The stolen assets were reportedly moved across multiple blockchain networks, including Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin.
Company Statement Leaves Unanswered Questions
Triple-A’s statement described a three-hour maintenance period during which infrastructure was secured, but it did not explain why blockchain data appeared to show assets continuing to flow into compromised wallets for more than a day after the initial breach.
The two timelines are not necessarily inconsistent, as temporarily disabling customer-facing services does not automatically prevent deposits from reaching existing blockchain wallet addresses.
However, the company has not provided additional details regarding which systems were placed into maintenance or whether deposit addresses remained active throughout the incident.
Customer Assets Remain Protected
Triple-A repeatedly emphasized that customer funds were not exposed during the breach. The company explained that it does not provide digital asset custody on behalf of clients and instead safeguards customer funds through separate trust accounts maintained with regulated institutions.
As a licensed payment provider operating under Singapore’s Payment Services Act, Triple-A is required to segregate customer assets from its own operational funds. The company stated that the financial impact is limited solely to its treasury accounts and that customers continue to receive normal settlement services following the restoration of operations.
Investigation Underway
Triple-A said it is working with internal security teams, external cybersecurity specialists, blockchain forensic firms, and the Singapore Police Force to investigate the incident. The company is attempting to trace the stolen assets and support potential recovery efforts but has not disclosed the attack vector or how unauthorized access to the treasury wallets was obtained.
Triple-A also clarified that although it uses Fireblocks as part of its digital asset infrastructure, there is currently no evidence linking the breach to Fireblocks or indicating that the platform itself was compromised.
Security Challenges Continue Across the Industry
The incident adds to a series of major cryptocurrency security breaches reported in recent weeks.
The Triple-A breach follows other significant exploits, including attacks on AFX Trade and WEMIX, contributing to a period of elevated losses across the digital asset industry. According to blockchain security firm PeckShield, cryptocurrency hacks resulted in $75.87 million in losses across 40 incidents during June alone. The latest attack highlights that even highly regulated digital asset service providers remain exposed to operational security risks involving online treasury wallets.
Conclusion
Triple-A’s confirmation of unauthorized access to its treasury wallets provides reassurance that customer assets remain protected, but the incident has raised questions about the management of operational wallets after blockchain investigators estimated losses at approximately $11.8 million. While the company maintains that the breach was contained within hours, onchain data suggests attackers continued draining assets for an extended period after the initial compromise.
As forensic investigators and law enforcement continue tracing the stolen funds, the incident serves as another reminder that strong regulatory oversight and customer asset segregation do not eliminate the operational risks associated with managing internet-connected cryptocurrency wallets.
