Singapore’s Triple-A Reports $11.8M Cryptocurrency Treasury Breach

Wait 5 sec.

Key TakeawaysTriple-A, a Singapore-registered cryptocurrency payments provider, disclosed unauthorized treasury wallet access over the weekendTotal losses climbed to $11.8 million, exceeding early estimates of $9.3 millionCompromised wallets continued receiving and losing deposits more than 31 hours after initial detectionCustomer assets remained secure due to separate custody arrangements in trust accountsAuthorities including Singapore Police Force and blockchain security experts are now involved in the investigationA Singapore-based cryptocurrency payment processor, Triple-A, publicly acknowledged on Monday that its treasury wallets fell victim to a sophisticated attack over the weekend, resulting in the theft of $11.8 million worth of company-controlled digital currencies.Triple-A Hit by $9.7M Hot Wallet HackCrypto payment gateway Triple-A (@TripleAHQ) has been drained of ~$9.7M in a multi-chain exploit, flagged by on-chain analyst Specter & PeckShield.What we know: Funds drained across TRON, Ethereum + more chains Attacker swapped… pic.twitter.com/vrTYYeCT2O— Crypto Patel (@CryptoPatel) July 25, 2026The security incident first came to light Friday when blockchain security researcher Specter identified suspicious outflows totaling approximately $9.3 million. However, as the weekend progressed, the total damage escalated to $11.8 million with continuous unauthorized withdrawals from the compromised infrastructure.According to Triple-A’s statement, the company became aware of the security breach on Saturday and temporarily suspended certain platform functions for approximately three hours to implement emergency security protocols and safeguard remaining assets.Operations have been fully reinstated since the incident, with the company confirming that all payment processing capabilities are functioning as expected.Customer Assets Remained Isolated and ProtectedTriple-A emphasized that no client-owned assets were compromised during the security breach. The payment firm’s business model does not involve custody of customer digital assets. Rather, all client funds are maintained in segregated trust accounts managed by independent safeguarding entities.This segregation framework aligns with Singapore’s Payment Services Regulations, which were updated in October 2024 to mandate that licensed cryptocurrency payment service providers maintain customer holdings in distinct blockchain addresses separate from operational funds.Triple-A has not disclosed technical details regarding the attack vector or the total holdings in the affected treasury wallets. The $11.8 million loss figure originates from blockchain analysis conducted by Specter and cybersecurity firm PeckShield rather than official company statements.Stolen Assets Distributed Across Seven Blockchain NetworksThe attackers orchestrated the theft across seven different blockchain ecosystems, including Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin.Stolen assets were consolidated into a single Ethereum wallet address. Analysis from PeckShield revealed this address accumulated more than 5,226 ETH—valued at approximately $9.73 million—through eight separate transactions executed between late Friday evening and early Saturday morning in UTC timezone.Notably, Specter observed that the compromised wallets continued to receive new incoming deposits that were immediately redirected by the attackers, even 31 hours following the initial large-scale withdrawals.Triple-A operates under a license issued by the Monetary Authority of Singapore and maintains payment service authorization in France via its European subsidiary, Paytop SAS. The firm also holds money services business registrations in both the United States and Canada.The payment processor stated it has engaged cybersecurity consultants, blockchain forensics specialists, and the Singapore Police Force to investigate the breach, identify the perpetrators, and attempt asset recovery.As of publication, Triple-A has not released the comprehensive update it committed to providing on Saturday. The company’s press section still displays a July 15 announcement regarding preliminary regulatory approval from Dubai’s Virtual Assets Regulatory Authority.This incident represents one of three significant cryptocurrency exploits documented this week. AFX Trade suffered losses approximating $24.15 million through a vulnerability in its Arbitrum custody bridge. Meanwhile, the Verus-Ethereum bridge experienced a roughly $7.54 million breach on the same day—the project’s second major security failure since May.The post Singapore’s Triple-A Reports $11.8M Cryptocurrency Treasury Breach appeared first on Blockonomi.