Triple-A Says Treasury Wallet Hack Caused $11.8 Million Loss, Client Funds Unaffected
Key Takeaways
- •Triple-A said the affected wallets contained company treasury assets, not client funds.
- •The reported loss rose from early estimates of about $9.7 million to $11.8 million before the company confirmed the incident.
- •On-chain analysts said funds were drained across Ethereum, TRON, Polygon, Arbitrum, Solana and TON before being consolidated into about 5,227 ETH.
- •Triple-A said certain services were placed in maintenance mode for around three hours and have since resumed normal operations.
- •The incident underscores due diligence questions for fintechs using stablecoin payment rails, including hot-wallet exposure, fund segregation and reserve capacity.

Triple-A, the Singapore-based payments infrastructure company that enables merchants to accept crypto payments and settle in fiat currency, has confirmed unauthorized access to its treasury wallets, reportedly resulting in the loss of $11.8 million in company-owned digital assets.
The confirmation followed nearly three days of public speculation, during which on-chain security firms tracked the reported losses rising from about $9.3 million to $9.7 million and then to a figure closer to $12 million before the company issued its statement.
In an official statement, Triple-A said it identified the unauthorized access on 25 July. The affected wallets held the company’s own digital assets, according to the firm.
“Client funds were not affected. Triple-A does not provide digital asset custody on behalf of its clients, and client funds are held separately in trust accounts maintained with safeguarding institutions that were not exposed,” the company said.
Triple-A said it moved certain services into maintenance mode for about three hours as a precaution while it secured the affected infrastructure. The company said all services have since returned to normal operation across its markets.
The firm described the incident as limited to specific operational accounts and said the loss can be absorbed from its treasury reserves. Triple-A also said it remains well-capitalized and able to meet its liabilities.
The company said it is working with internal and external cybersecurity teams, blockchain forensics specialists, and law enforcement agencies, including the Singapore Police Force, to trace the funds and seek recovery.
On-chain analyst Specter first reported unusual outflows from wallets linked to Triple-A on 24 and 25 July. PeckShield later followed the activity, and the two firms placed the early estimated loss at just over $9.7 million. The funds were drained across six networks: Ethereum, TRON, Polygon, Arbitrum, Solana, and TON.
After obtaining access, the attacker stole stablecoins and other liquid assets, rapidly swapped them on decentralized exchanges, and then bridged the proceeds to Ethereum. The funds were consolidated into a single address holding about 5,227 ETH.
The pattern resembles laundering methods seen in multiple exploits this year, in which a multi-chain set of stolen assets is converted into one liquid position. Ethereum is commonly used in such flows because it has deep bridge and swap liquidity.
Specter’s alert also said the transfers took place in multiple tranches rather than as one single withdrawal. It added that deposits were not disabled while funds continued to be swept out, suggesting the wallet operators may not have recognized the draining activity in real time.
Triple-A’s statement that the incident affected treasury assets rather than client money is significant for merchants using the platform. However, the event also raises questions about how a Major Payment Institution licensed by the Monetary Authority of Singapore, with EU authorization and in-principle approval from Dubai’s VARA, had close to $12 million in internet-connected wallets over a weekend while the funds were being removed.
The case also matters outside Singapore because Triple-A operates in a part of the payments stack that is important to stablecoin adoption: infrastructure that lets merchants accept USDC or USDT and receive settlement in fiat currency without directly using a crypto exchange. That places it in the same broad category as stablecoin-to-fiat providers that Nigerian and pan-African fintech companies increasingly connect to for cross-border settlement.
The incident highlights a risk in the stablecoin payments model: operational treasury funds can remain in hot wallets and be drained quickly if security controls fail. Licensing and custody partnerships did not prevent this breach. What protected Triple-A’s clients, according to the company, was the structure of its fund separation, with client money held outside the exposed wallets in trust accounts maintained with safeguarding institutions.
For African fintechs using or evaluating similar rails, the incident underscores the need for due diligence on payments partners. Key questions include how much value is held in hot wallets compared with cold storage, how client funds are legally separated from operational treasury assets, and whether a provider’s reserves can absorb a similar loss without service disruption.