Singapore-based crypto payments firm Triple-A says it remains fully capitalized and capable of meeting all liabilities after unauthorized access to wallets containing company-owned digital assets, emphasizing that customer funds were never at risk due to its segregated custody model.
The company identified the incident on July 25, 2026, and said the breach affected only its treasury wallets. While Triple-A has not disclosed the financial loss, blockchain security researchers estimate that approximately $11.8 million in digital assets was stolen.
Treasury Wallets Breached
In a newsroom statement, Triple-A confirmed unauthorized access to wallets holding its own digital assets. The company said the breach was limited to wallets operated by Triple A Technologies Pte. Ltd., its Singapore entity, and did not affect other business operations.
According to Triple-A, the financial impact was confined to specific operational accounts and is being fully absorbed using the company’s treasury reserves.
“The financial impact is limited to specific operational accounts and is being fully absorbed from Triple-A’s treasury reserves” the company said.
The company added that it remains “well capitalized and able to meet all its liabilities” although it did not disclose the value of the stolen assets.

Triple-A update on the incident (Source: X)
Client Assets Remained Protected
Triple-A stressed that no customer funds were compromised because it does not custody clients’ digital assets.
Instead, client funds are held separately in safeguarded trust accounts maintained with regulated financial institutions that were not exposed to the attack.
The company temporarily placed certain services into maintenance mode for approximately three hours while engineers secured the affected infrastructure. Normal payment processing and settlements have since resumed across all markets.
On-Chain Investigators Estimate $11.8 Million Loss
Although Triple-A has not disclosed the size of the theft, blockchain security researchers tracked suspicious fund movements linked to the company’s wallets.
On-chain analyst Specter first identified unusual transfers before blockchain security firm PeckShield expanded the analysis, estimating losses of roughly $11.8 million.
The stolen assets were reportedly drained across multiple networks, including Ethereum, TRON, Polygon, Arbitrum, Solana and TON.
Researchers said the attacker swapped stablecoins and other liquid assets through decentralized exchanges before bridging the proceeds to Ethereum and consolidating them into a wallet holding roughly 5,227 ETH, a laundering pattern commonly seen in recent crypto exploits.


On-Chain Investigators Estimate $11.8 Million Loss (Source: X)
Investigation Continues
Triple-A said it is working with internal cybersecurity teams, external security specialists, blockchain forensic experts and the Singapore Police Force to investigate the breach, trace the stolen assets and pursue recovery.
However, the company has not disclosed the attack vector, the number of compromised wallets, or whether any funds have been recovered.
Broader Implications for Stablecoin Payment Providers
The incident highlights the importance of segregating customer assets from operational treasury funds.
Triple-A’s custody structure prevented the compromise of its treasury wallets from becoming a client-loss event, demonstrating how fund segregation can limit the impact of security incidents.
At the same time, the breach raises questions about treasury wallet security for regulated crypto payment providers. While licensing helps establish safeguards around customer funds, it does not eliminate cyber risks targeting a company’s own operational assets.
For enterprise customers relying on stablecoin payment infrastructure, the incident reinforces the need to evaluate not only regulatory status but also wallet security, treasury management and reserve strength.
As the investigation progresses, the industry will be watching for further details on how the attackers gained access, whether any assets can be recovered, and what additional security measures Triple-A implements following the exploit.














































