Key Takeaways
- A major security breach hit Singapore’s Triple-A crypto payments platform, targeting treasury wallets
- Total stolen funds now stand at $11.8 million, exceeding early estimates of $9.3 million
- Wallet draining continued more than 31 hours after initial detection of suspicious activity
- Customer deposits remained secure, maintained in segregated trust accounts per regulations
- Authorities and blockchain forensics experts are collaborating on fund recovery efforts
Triple-A, a prominent Singapore-registered cryptocurrency payments provider, officially acknowledged on Monday that malicious actors successfully compromised its corporate treasury wallets during the weekend, resulting in the theft of $11.8 million worth of digital assets owned by the company.
The security incident was initially identified on Friday by blockchain sleuth Specter, who estimated early losses at approximately $9.3 million. However, as the weekend progressed into Sunday, the total damage escalated to $11.8 million as cryptocurrency continued flowing out of the compromised wallets.
According to Triple-A’s statement, the company identified the unauthorized intrusion on Saturday and temporarily suspended certain platform services for approximately three hours as emergency security measures were implemented to protect remaining infrastructure.
All operational services have now been fully restored, with the firm reporting that transaction processing has returned to normal operations.
Customer Assets Remained Protected
Triple-A emphasized that no client deposits were compromised during the incident. The platform maintains a clear operational separationâit does not custody digital assets for customers. All client funds are maintained in dedicated trust accounts managed by independent safeguarding institutions.
This segregated custody model aligns with Singapore’s Payment Services Regulations, which mandated from October 2024 that licensed cryptocurrency payment service providers must store customer assets in distinct blockchain addresses.
The company has not disclosed specific details regarding the attack vector used to gain wallet access or the total holdings in the compromised accounts. The $11.8 million loss figure originates from blockchain analysis conducted by Specter and security monitoring platform PeckShield rather than official company disclosures.
Cross-Chain Movement of Stolen Assets
The perpetrators moved the misappropriated funds across multiple blockchain ecosystems, including Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin.
The stolen cryptocurrency was consolidated into a single Ethereum wallet address. According to PeckShield’s monitoring systems, this address accumulated more than 5,226 ETHâvalued at approximately $9.73 millionâreceived through eight separate transactions spanning from Friday evening through early Saturday morning in UTC time.
Notably, Specter observed that new incoming deposits to the breached wallets were still being automatically siphoned away 31 hours after the initial major withdrawals were first detected.
Triple-A operates under a license from the Monetary Authority of Singapore and maintains payment institution authorization in France via its European subsidiary, Paytop SAS. The firm also holds money services business registrations in both the United States and Canada.
The payment processor stated it has engaged cybersecurity consultants, blockchain forensics specialists, and the Singapore Police Force to track the stolen assets and assist with potential recovery operations.
As of publication, Triple-A has not released the comprehensive update it committed to providing on Saturday. The company’s news section continues to display a July 15 announcement regarding in-principle regulatory approval from Dubai’s Virtual Assets Regulatory Authority.
This treasury breach represents one of three significant cryptocurrency exploits documented this week. AFX Trade suffered losses of approximately $24.15 million through its Arbitrum-based custody bridge. Additionally, the Verus-Ethereum bridge experienced a security failure resulting in roughly $7.54 million in losses on the same day, representing its second compromise since May.





