TL;DR
- Triple-A confirmed unauthorized access to treasury wallets holding company-owned assets, while customer funds remained unaffected because they were maintained separately in protected trust accounts.
- Onchain investigator Specter estimated losses near $11.8 million, although Triple-A did not disclose the amount or explain how attackers compromised the affected wallets.
- The company restored services after maintenance and is working with cybersecurity experts, forensics firms, and Singapore authorities to trace assets and pursue recovery.
Triple-A has confirmed that unauthorized access to its treasury wallets resulted in the loss of company-owned digital assets, turning an otherwise routine weekend into a sharp security test for the Singapore-based stablecoin payments firm. The breach was detected on Saturday, prompting the company to place certain services into maintenance mode for roughly three hours across its operations while affected infrastructure was secured. The incident reached corporate reserves rather than customer balances, but the lack of detail about how the wallets were compromised leaves an unsettling gap around the attack’s origin, method, and potential warning signs.
Client protections contain the damage as investigators seek answers
The company said client funds were not affected because it does not custody digital assets on behalf of customers. Instead, customer money is kept separately in trust accounts with safeguarding institutions, creating a structural boundary between operational treasury holdings and client assets. That separation appears to have contained the direct financial damage to Triple-A itself in practice, an important distinction during a wallet breach involving a payments provider. Still, the incident raises an obvious question: if internal treasury infrastructure was accessible, what prevented the same intrusion from reaching other systems before maintenance controls were activated?
Triple-A did not disclose the value of the stolen assets, and it has not explained the specific pathway used to gain access. However, onchain investigator Specter estimated the losses at approximately $11.8 million. The company described the impact as limited to selected operational accounts and said the shortfall would be absorbed through its treasury reserves without drawing on client money. The reported loss is therefore substantial but internally contained, at least according to the company’s current account. All services have since been restored, with transactions and settlements reportedly processing normally after the temporary disruption ended.
The response has now moved from containment toward investigation and recovery. Triple-A said it is working with cybersecurity specialists, blockchain forensics firms, and relevant authorities, including the Singapore Police Force, to determine what happened, trace the digital assets, and support recovery efforts. The next critical test is whether investigators can explain the compromise and recover meaningful funds for now, because operational restoration alone does not resolve the unanswered security questions. Until more technical details emerge, the breach remains a peculiar case in which customer protections apparently worked, yet a multimillion-dollar treasury loss still slipped through.





