NewsCryptoTriple-A Says Treasury Wallet Breach Hit Company Funds, Not Customer Assets

Triple-A Says Treasury Wallet Breach Hit Company Funds, Not Customer Assets

Author: Tron Weekly·

Key Takeaways

  • Triple-A said the breach affected treasury wallets holding company-owned digital assets, not customer funds.
  • The company said client assets were kept in separate trust accounts with safeguarding firms, which limited the impact of the incident.
  • Triple-A detected the unauthorized access on Saturday and placed some services in maintenance mode for about three hours while securing the infrastructure.
  • Blockchain investigators observed suspicious activity across multiple wallets and chains, including TRON, Ethereum, TON, and Solana.
  • Triple-A has not disclosed how the attackers gained access or whether any assets have been recovered.
Triple-A Says Treasury Wallet Breach Hit Company Funds, Not Customer Assets

Triple-A said unauthorized access to its treasury wallets exposed company-owned digital assets, while customer funds remained unaffected. The Singapore-based payments provider said it detected the incident on Saturday and later confirmed on Monday that client assets were kept separate from the compromised infrastructure.

After discovering the access, the company placed certain services in maintenance mode. The maintenance period lasted about three hours, during which Triple-A said its teams secured the affected infrastructure.

Triple-A said it does not hold digital assets on behalf of customers. Instead, client funds are stored in trust accounts with safeguarding firms. The company said that structure prevented the breach from affecting customer funds, underscoring a separation that matters for payment providers handling both operational wallets and client balances.

Blockchain researchers spotted suspicious transactions over the weekend before Triple-A’s public announcement. The activity involved multiple wallets associated with the company. Initially, it was unclear whether the assets in question belonged to Triple-A, its customers, or recipients of payments.

On-chain investigator Specter first estimated that more than $9.3 million had moved out of the linked wallets. That estimate later rose to more than $9.7 million after additional transactions were identified. Specter then estimated that the possible losses could be around $11.8 million, though Triple-A has not confirmed that figure.

There appear to be ongoing wallet draining involving @TripleH hot wallets across multiple chains, including TRON, Ethereum, TON, and Solana. So far, more than $9.3M has been drained, swapped, and bridged to Ethereum. The funds are currently being consolidated here: Ethereum… pic.twitter.com/pLKvVwMWav — Specter (@SpecterAnalyst) July 24, 2026

The company has not disclosed the amount of losses tied to the wallet hack. In its update, Triple-A described the assets as belonging to the company and being held as treasury holdings.

Triple-A has also not explained how the breach occurred. It remains unclear what credentials or other mechanism the attackers used to gain access.

According to the company, it is working with its internal security teams and external cybersecurity firms. Blockchain forensics experts, authorities, and the Singapore Police Force are also involved in the investigation. Triple-A has not given a timeline for when the probe will be completed or when additional findings will be released.

The company also did not say whether any of the assets had been frozen or recovered. It said the investigation includes both tracing and recovery efforts, which often determines whether compromised funds can be tracked across chains before they are moved further.

The incident comes after another recent DeFi security case involving Lien Finance, which reportedly lost 542,144.63 USDC after a vulnerability in its bond validation and pricing logic was exploited.

🚨SlowMist TI Alert🚨 💸 @LienFinance Loss: ~542k USD 🔍 Root Cause: The exchangeEquivalentBonds function in BondMakerCollateralizedEth lacks proper multiset integrity checks. It only counts total exception occurrences instead of verifying each bondID's appearance per group.… — SlowMist (@SlowMist_Team) July 24, 2026

According to SlowMist, the code flaws allowed unsupported bond tokens to be created and exchanged for USDC without any collateral.

Researchers said DeFi attacks had caused more than $630 million in losses in the first seven months of 2026. Common attack methods included oracle manipulation, pricing vulnerabilities, credential compromise, and weak bridge validation. The Triple-A wallet breach adds to that broader list of crypto security incidents.