Triple-A Says Treasury Wallet Incident Affected Only Company Assets, Not Client Funds
Key Takeaways
- •Triple-A said the incident affected only company-owned treasury wallets and did not involve customer funds.
- •The company identified the unauthorized access on July 25 and later restored normal operations after a brief maintenance period.
- •Public Ethereum records show 5,287.08568411 ETH moved into a single cited address linked to the activity.
- •Triple-A has not disclosed the total treasury loss or explained how the affected wallets were accessed.
- •The company said it is cooperating with cybersecurity specialists, blockchain forensics experts and authorities in the investigation.

Triple-A, the Singapore-based stablecoin payments firm, said it identified an unauthorized access incident on July 25 involving wallets holding the company’s own digital assets. On-chain records showed 5,287.08568411 ETH moving into a single cited Ethereum address, but the company has not disclosed the total treasury loss or explained how the affected wallets were accessed.
Triple-A said client funds were not affected because customer assets are held separately in trust accounts with safeguarding institutions that were not exposed. The company said it has restored normal operations after securing the affected infrastructure.
What happened during the Triple-A wallet breach?
The incident involved unauthorized access to wallets operated by Triple A Technologies Pte. Ltd., Triple-A’s Singapore entity, which contained the company’s treasury assets. Triple-A said the breach affected only its company-owned digital assets and did not involve customer funds.
The firm said it does not provide digital asset custody services for clients. Instead, client funds are maintained separately in trust accounts with safeguarding institutions.
Triple-A identified the incident on July 25 and said it contained the issue after securing the affected infrastructure and completing security checks. As a precaution, certain services were placed into maintenance mode for approximately three hours. The company later said all services were restored and that transactions and settlements were processing normally across all markets.
Triple-A said the financial impact was limited to specific operational accounts and would be fully absorbed from treasury reserves. It also stated that it remains well capitalised, can meet all of its liabilities and continues to operate globally at normal service levels. The company added that no other Triple-A entities or operations were affected.
What do on-chain records show?
Public Ethereum records show a large movement of funds into a single address linked to the incident, although the data does not establish the full timeline or source of the transactions. On-chain analyst Specter identified the Ethereum address 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1 as the address where funds connected to the activity were being consolidated.
Etherscan records show 12 inbound transfers of more than 0.01 ETH on July 24 and July 25, totaling 5,287.08568411 ETH. The wallet movements confirm that funds entered the cited Ethereum address. However, the public data does not confirm when unauthorized access began, which source wallets were involved, or the exact amount of assets lost by Triple-A.
Triple-A has not confirmed the cited address, disclosed the affected wallet addresses, or provided an asset list or loss figure related to the incident. The public wallet trail does not contradict Triple-A’s statement that customer funds were segregated from the affected wallets, but the blockchain data cannot independently verify that segregation.
How much was reportedly lost?
Triple-A has not officially disclosed the financial impact of the incident. Specter reported suspicious outflows from wallets associated with Triple-A across multiple networks, including TRON, Ethereum, TON and Solana. The analyst said the assets were swapped and bridged before being consolidated on Ethereum.
Specter initially estimated that more than $9.3 million had been drained. After additional transactions were identified, the estimate was raised to about $11.8 million. The later figure included additional withdrawals involving Bitcoin and TRON networks.
Specter also said the activity continued for more than 31 hours and alleged that new deposits reaching affected Triple-A addresses were withdrawn shortly after arrival. These figures are based on blockchain analysis and have not been confirmed by Triple-A. The company has not disclosed the size of its treasury loss or provided details about the assets involved.
How is Triple-A responding?
Triple-A said it is working with cybersecurity specialists, blockchain forensics experts and authorities to investigate the incident and trace affected assets. The company said it is cooperating with the Singapore Police Force and other relevant authorities as part of its investigation and recovery efforts.
The company has not provided a timeline for completing the investigation or confirmed whether any assets have been recovered. It said its focus remains on understanding the unauthorized access, tracking the movement of affected assets and supporting recovery efforts while maintaining normal business operations.
What is Triple-A’s regulatory status?
Triple A Technologies Pte. Ltd. is listed by the Monetary Authority of Singapore as a Major Payment Institution authorised for domestic and cross-border transfers, merchant acquisition and digital payment token services. Institutions operating under this licence category must comply with customer money protection requirements.
The regulatory listing confirms the company’s obligations but does not independently determine whether those requirements were satisfied during this incident. Triple-A has maintained that customer funds were not exposed because client assets were held separately from the affected treasury wallets.
Conclusion
The Triple-A wallet breach continues to raise questions about the scale of the treasury impact and the circumstances behind the unauthorized access. Triple-A has confirmed that company-owned digital assets were affected while stating that customer funds, payment operations and other group entities remained unaffected.
Public Ethereum records show 5,287.08568411 ETH moving into a single address, but they do not confirm the total loss amount or the source of the wallet compromise. The ongoing investigation involving cybersecurity experts, blockchain specialists and authorities is expected to provide further clarity on the affected assets, access method and possible recovery of funds.