A Singapore-based crypto payments firm just watched $11.8 million in company-owned digital assets disappear from its treasury wallets — and what makes it worse is that the draining didn’t stop once it was detected. The Triple-A treasury hack, confirmed by the company on Monday, is one of the more unsettling breaches in recent memory: not because of its scale alone, but because attackers kept pulling funds for more than a day after the first alarms went off.
Summary
Key takeaways
- Triple-A confirmed unauthorized access to its treasury wallets, with losses reaching $11.8 million, revised up from an initial estimate of $9.3 million.
- Funds were still being actively drained 31 hours after the first outflows were detected, according to onchain investigator Specter.
- Client funds were not affected — they are held in separate trust accounts under Singapore’s Payment Services Regulations.
- Stolen assets were moved across seven blockchain networks and consolidated at a single Ethereum address holding over 5,226 ETH (approximately $9.73 million), according to PeckShield.
- Triple-A is working with cybersecurity firms, blockchain forensics teams, and the Singapore Police Force to trace and recover the stolen assets.
Triple-A Treasury Hack Confirmed With Growing Losses
The breach was first flagged on Friday by onchain investigator Specter, who identified unusual outflows from wallets linked to Triple-A and put the initial damage at $9.3 million. By Sunday, that number had climbed to $11.8 million as transfers continued. Triple-A officially acknowledged the incident on Monday, stating that attackers gained unauthorized access to wallets holding the company’s own digital assets on July 25.
Continuous Draining of Wallets Post-Detection
The detail that stands out most in Specter’s analysis is also the most troubling. New deposits were still arriving at the compromised wallets and being swept immediately — 31 hours after the first large outflows were detected. Specter noted at the time that the team did not appear to be aware, as deposits had not been disabled.
Triple-A said it did detect the breach on Saturday and briefly placed certain services into maintenance mode for approximately three hours to secure the affected infrastructure and complete security checks. All services have since been restored, with transactions and settlements processing normally across all markets, according to the company’s statement.
What this timeline reveals is a gap between early external detection by onchain researchers and the company’s own internal response window — a dynamic that increasingly defines how crypto incidents unfold in public before firms can contain them.
Client Funds Protected Under Singapore Regulations
Despite the severity of the breach, customer funds were never at risk. Triple-A does not provide digital asset custody services on behalf of its clients. Instead, client assets are held separately in trust accounts maintained at independent safeguarding institutions, which were not touched by the incident.
Regulatory Compliance and Licensing
This segregation is not just internal policy — it reflects a regulatory requirement. Singapore’s Payment Services Regulations, updated in October 2024, mandate that licensed crypto payment firms keep customer assets in separate blockchain addresses. Triple-A is licensed by the Monetary Authority of Singapore and also holds payment licenses in France through its European arm, Paytop SAS. It is registered as a money services business in both the US and Canada.
The company also confirmed it remains well capitalized and can meet all of its liabilities. The financial impact, it said, will be absorbed through its treasury reserves.
That distinction matters beyond just reassuring customers. It also shapes how regulators and market observers will assess the breach. A licensed, compliant firm losing its own operational capital is a fundamentally different incident from one that loses client deposits — though the reputational weight of a prolonged, multi-chain treasury drain is significant regardless.
Complex Movement of Stolen Funds Across Multiple Blockchains
Tracing the stolen assets is where the challenge deepens. The attackers moved funds across seven separate blockchain networks: Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin — a deliberate multi-chain approach that significantly complicates forensic tracking and any recovery effort.
Consolidation at a Single Ethereum Address
Despite the breadth of networks involved, the proceeds were funneled toward a single destination. Blockchain security firm PeckShield identified a single Ethereum address that accumulated over 5,226 ETH, worth approximately $9.73 million, transferred in eight transactions between Friday evening and early Saturday morning UTC.
Neither Triple-A nor investigators have publicly identified a suspected attacker, and there has been no confirmation that the assets were subsequently moved to an exchange, a mixer, or any other service after reaching that Ethereum address. The cause of the breach — whether compromised credentials, infrastructure weakness, or another vector — has also not been disclosed. That silence is notable, and the investigation is still active.
Response and Recovery Efforts
Triple-A said it is collaborating with cybersecurity specialists, blockchain forensics firms, and the Singapore Police Force to trace the stolen funds and support recovery. The combination of law enforcement and on-chain forensics is now standard practice in major crypto incidents, though the cross-chain movement of the funds presents a real obstacle to any quick resolution.
Where Things Stand
The company had promised a formal update on Saturday. As of the time of reporting, its newsroom page still showed a July 15 post about receiving in-principle approval from Dubai’s Virtual Assets Regulatory Authority — a reminder of how quickly operational crises can outpace public communications.
The breach also doesn’t exist in isolation. It lands in the same week that saw AFX Trade lose approximately $24.15 million through its Arbitrum custody bridge, and the Verus-Ethereum bridge lose roughly $7.54 million — that bridge’s second exploit since May. The pattern suggests the pressure on crypto infrastructure security isn’t easing.
For Triple-A, the immediate operational story may be contained. But the harder question — how attackers drained a licensed, regulated payments firm’s wallets across seven chains for more than 31 hours — is one the company’s investigators still need to answer publicly.
FAQ
Did Triple-A confirm the treasury wallet hack?
Yes. Triple-A confirmed on Monday that unauthorized access to its treasury wallets resulted in the loss of company-owned crypto assets, first detected on July 25.
Were customer funds affected by the hack?
No. Customer funds were not affected. Triple-A does not hold digital assets on behalf of clients — client funds are held separately in trust accounts at independent safeguarding institutions, in compliance with Singapore’s Payment Services Regulations.
How much was lost in the Triple-A treasury hack?
Onchain investigator Specter initially estimated losses at $9.3 million, later revising the figure upward. By Sunday, the estimated total had reached $11.8 million. Triple-A has not independently disclosed the exact total amount lost.
What steps is Triple-A taking to recover the stolen assets?
Triple-A is working with cybersecurity specialists, blockchain forensics firms, and the Singapore Police Force to trace the stolen funds and support recovery efforts. The company has also stated it remains well capitalized and can meet all of its liabilities.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

