TLDR
- Singapore crypto payments firm Triple-A confirmed unauthorized access to its treasury wallets
- Losses reached $11.8 million, up from an initial estimate of $9.3 million
- New deposits were still being drained 31 hours after the first outflows were detected
- Client funds were not affected as they are held separately in trust accounts
- Triple-A is working with cybersecurity firms, blockchain forensics teams, and Singapore police
Triple-A, a Singapore-based stablecoin payments company, confirmed on Monday that hackers broke into its treasury wallets over the weekend, draining $11.8 million in company-owned crypto assets.
Triple-A Hit by $9.7M Hot Wallet Hack
Crypto payment gateway Triple-A (@TripleAHQ) has been drained of ~$9.7M in a multi-chain exploit, flagged by on-chain analyst Specter & PeckShield.
What we know:
✅ Funds drained across TRON, Ethereum + more chains
✅ Attacker swapped… pic.twitter.com/vrTYYeCT2O— Crypto Patel (@CryptoPatel) July 25, 2026
The breach was first flagged on Friday by onchain investigator Specter, who put initial losses at $9.3 million. By Sunday, that figure had grown to $11.8 million as funds continued to flow out of the affected wallets.
Triple-A said it detected the unauthorized access on Saturday and briefly placed some services into maintenance mode for around three hours while it secured its infrastructure.
The company said all services have since been restored and transactions are processing normally.
Client Funds Were Kept Separate
Triple-A was clear that customer funds were not touched. The company does not hold digital assets on behalf of clients. Instead, customer funds are kept in trust accounts at separate safeguarding institutions.
This structure is in line with Singapore’s Payment Services Regulations, which since October 2024 have required licensed crypto payment firms to keep customer assets in separate blockchain addresses.
Triple-A has not publicly explained how the wallets were accessed or how much was held in the affected accounts. The $11.8 million figure comes from onchain data tracked by Specter and blockchain security firm PeckShield, not from Triple-A directly.
Attacker Moved Funds Across Multiple Networks
The stolen funds were taken across several blockchain networks including Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin.
Proceeds were pooled at a single Ethereum address. PeckShield’s alert showed that address holding over 5,226 ETH, worth around $9.73 million, transferred in eight transactions between Friday evening and early Saturday morning UTC.
Specter noted that new deposits were still arriving at the compromised wallets and being immediately swept 31 hours after the first large outflows were detected.
Triple-A is licensed by the Monetary Authority of Singapore and also holds payment licenses in France through its European arm, Paytop SAS. It is registered as a money services business in the US and Canada.
The company said it is working with cybersecurity specialists, blockchain forensics firms, and the Singapore Police Force to trace the funds and support recovery efforts.
Triple-A has not yet published the formal update it promised on Saturday. Its newsroom still shows a July 15 post about receiving in-principle approval from Dubai’s Virtual Assets Regulatory Authority.
The breach is one of three major crypto exploits reported this week. AFX Trade lost around $24.15 million through its Arbitrum custody bridge. The Verus-Ethereum bridge lost roughly $7.54 million on the same day, marking its second breach since May.







