NewsCryptoTriple-A Says Client Funds Unaffected After Treasury Wallet Exploit

Triple-A Says Client Funds Unaffected After Treasury Wallet Exploit

Author: crypto.news·

Key Takeaways

  • •Triple-A said the breach affected only company treasury assets and did not expose client funds held in separate trust accounts.
  • •Some services were placed in maintenance mode for about three hours while the company secured affected infrastructure and completed checks.
  • •On-chain investigator Specter estimated losses at up to about $11.8 million, but Triple-A has not disclosed the total value lost.
  • •Researchers reported that assets moved across chains including Ethereum, Solana, TRON and TON, with funds swapped and bridged to Ethereum.
  • •Triple-A said it remains well capitalized, can meet its liabilities and continues to operate globally at normal service levels.
Triple-A Says Client Funds Unaffected After Treasury Wallet Exploit

Triple-A said unauthorized access to company treasury wallets caused a loss of company-owned digital assets, while client funds and payment operations remained unaffected.

The Singapore-based stablecoin payments company said in a statement on Monday that it detected unauthorized access to certain wallets holding its own digital assets on July 25. Triple-A temporarily placed some services into maintenance mode for about three hours while it secured the affected infrastructure and completed additional security checks.

The company said all services have since been restored, with transactions and settlements processing normally across all markets. It said the incident affected only treasury assets, and that the financial impact was limited to specific operational accounts that will be fully absorbed through the company’s treasury reserves.

Triple-A said client assets were not exposed because it does not provide digital asset custody services on behalf of customers. Instead, client funds are held separately in trust accounts maintained with safeguarding institutions, which the company said were not affected by the incident. That distinction is central to the company’s response because treasury wallets are used for the firm’s own operating assets, while segregated client funds are meant to remain separate from corporate balances and operational infrastructure.

The company also said it remains well capitalized, can meet all of its liabilities, and continues to operate globally at normal service levels despite the breach.

On-chain investigators flagged suspicious activity before company statement

Triple-A’s announcement followed weekend reports from blockchain investigators that identified unusual transactions involving wallets linked to the company before it publicly acknowledged the incident.

On-chain investigator Specter initially estimated that more than $9.3 million had been removed from wallets associated with Triple-A, then revised the estimate to more than $9.7 million as additional transfers were identified. Specter later estimated the losses at about $11.8 million. Triple-A has not disclosed the total amount of digital assets lost.

There appear to be ongoing wallet draining involving @TripleH hot wallets across multiple chains, including TRON, Ethereum, TON, and Solana. So far, more than $9.3M has been drained, swapped, and bridged to Ethereum. The funds are currently being consolidated here: Ethereum… pic.twitter.com/pLKvVwMWav — Specter (@SpecterAnalyst) July 24, 2026

https://x.com/SpecterAnalyst/status/2080764538874462386?ref_src=twsrc%5Etfw

Blockchain security firm PeckShield also drew attention to the suspicious transactions after Specter’s initial findings.

Before Triple-A released its statement, researchers had not determined whether the affected wallets contained company funds, customer assets, or payment recipient balances. The company’s update clarified that only company-owned treasury assets were affected and that customer funds remained segregated from the affected infrastructure.

Triple-A has not disclosed how the unauthorized access occurred or whether the incident resulted from compromised credentials, infrastructure weaknesses, or another attack method. The cause of the breach remains under investigation. Further updates are likely to focus on the attack path, whether any security controls failed, and whether traced assets can be frozen or recovered through exchanges, infrastructure providers or law enforcement channels.

Assets reportedly moved across several blockchains

Earlier analysis from Specter indicated that the suspicious activity involved wallets operating on Ethereum, Solana, TRON and TON. Some reports also identified transactions on Polygon and Arbitrum.

According to the on-chain findings, the transferred assets were swapped and bridged to Ethereum after leaving the affected wallets. Researchers reported that the receiving address accumulated approximately 5,226.66 ETH, valued at roughly $9.7 million when the activity was first identified.

Neither Triple-A nor investigators have publicly identified the suspected attacker. At the time of the company’s announcement, there was also no confirmation that the assets had been transferred to a cryptocurrency exchange, a mixer or another laundering service after reaching Ethereum.

Triple-A said it is working with internal and external cybersecurity experts, blockchain forensics specialists and relevant authorities, including the Singapore Police Force, to investigate the incident, trace the affected assets and support recovery efforts. In incidents involving assets moved across multiple chains, public blockchain records can help investigators follow transfers, but recovery typically depends on identifying counterparties with the ability to freeze or return funds.

The company did not provide a timeline for completing the investigation or say whether any portion of the stolen assets has been frozen or recovered.

Breach follows other crypto security incidents in 2026

The incident comes as blockchain security researchers continue to report attacks targeting cryptocurrency platforms and decentralized finance protocols throughout 2026. The Triple-A case differs from protocol-level exploits in that the company described unauthorized access to treasury wallets rather than a failure in customer custody or payment settlement systems, but it still fits a broader pattern of attackers targeting operational crypto infrastructure.

Last week, decentralized finance protocol Lien Finance disclosed a loss of about 542,144.63 USDC after attackers exploited flaws in its bond validation and pricing logic. Blockchain security firm SlowMist said the exploit allowed unsupported bond tokens to be created and exchanged for real USDC liquidity without consuming the required collateral.

Separate analysis from DefimonAlerts and researcher exvulsec described the Lien Finance attack as a protocol validation and valuation failure rather than a conventional smart contract exploit. Researchers compared parts of the incident with the earlier Drift Protocol attack because both involved weaknesses in asset valuation rather than cryptographic protections.

Researchers tracking decentralized finance attacks have estimated cumulative losses exceeding $630 million during the first seven months of 2026. They identified oracle manipulation, pricing flaws, compromised credentials and bridge validation weaknesses among the most common attack methods recorded this year.

Another major investigation also remained active this week after wallets tied to the $285 million Drift Protocol exploit resumed moving funds following roughly three months of inactivity. On-chain records showed that more than 23,095 ETH, worth about $44.4 million, was transferred into Tornado Cash, making the movement of stolen assets more difficult to trace.