Singapore payments firm Triple-A confirmed unauthorized access to its treasury wallets cost $11.8M, with new deposits still being drained 31 hours after the first outflows.
Singapore-based stablecoin payments firm Triple-A confirmed on July 26 that unauthorized access to its treasury wallets resulted in the loss of company-owned digital assets. The company said client funds were not affected and that it would absorb the financial impact through its treasury reserves.
Triple-A said it detected the breach on July 26 and placed certain services into maintenance mode for roughly three hours while it secured the compromised infrastructure. The company did not disclose how the wallets were accessed or specify the total amount lost in its official statement.
Losses Climbed Across Multiple Networks
On-chain investigator Specter first flagged the drain at 9:18 pm UTC on July 24, estimating losses at more than $9.3 million and reporting that the attacker had swapped the stolen assets and bridged them to Ethereum. Blockchain security firm PeckShield, citing Specter, raised that figure to more than $9.7 million roughly four and a half hours later.
By July 26, Specter put total losses at approximately $11.8 million, noting that a further $1.8 million had been taken across the Bitcoin and TRON networks. Specter also reported that new deposits were still arriving at the affected wallets and being drained more than 31 hours after the first large outflows appeared. Bitcoin had not been named among the affected networks in earlier reports, which had covered Ethereum, TRON, Polygon, Arbitrum, Solana and The Open Network.
A screenshot published alongside PeckShield's alert showed the proceeds pooled at a single Ethereum address holding 5,226.67 ETH, worth approximately $9.73 million at the time. The address recorded eight incoming transfers between 8:35 pm UTC on July 24 and 3:03 am UTC on July 25, with the largest single transfer totaling roughly 4,140 ETH.
Related Article: Allbridge Core Suffers 2nd Flash Loan Vault Exploit, Loses $1.65M on Solana
Regulators and Investigators Involved
Triple-A said it was working with cybersecurity specialists, blockchain forensics firms, and the Singapore Police Force to investigate the incident, trace the stolen assets, and support recovery efforts. The company holds a major payment institution license from the Monetary Authority of Singapore and processes stablecoin payments for merchants that settle in local currency. Its European arm, Paytop SAS, holds payment institution and crypto-asset service provider licenses in France, and the group is registered as a money services business in both the United States and Canada.
Under Singapore's Payment Services Regulations, which took effect Oct. 4, 2024, licensed digital payment token service providers are required to safeguard customer assets in trust accounts held separately from the firm's own holdings. Triple-A said client funds are kept in trust accounts with safeguarding institutions and are not custodied on behalf of customers, which it cited as the reason client assets were unaffected.
The breach follows two other large crypto exploits disclosed the same week. AFX Trade, a protocol on Arbitrum, lost approximately $24.15 million in USDC through its custody bridge in an exploit disclosed July 22. The Verus-Ethereum bridge lost roughly $7.54 million the same day, marking its second breach since May. Triple-A had not published a formal update in its newsroom as of publication time, with its most recent entry remaining a July 15 announcement about receiving in-principle approval from Dubai's Virtual Assets Regulatory Authority for broker-dealer services.
