
Triple-A confirmed unauthorized access to its treasury wallets on July 25, resulting in the loss of company-owned digital assets while client funds remained protected. According to the company's statement, the financial impact will be covered by its treasury reserves and normal operations have resumed. The Singapore-based stablecoin payments company temporarily placed some services into maintenance mode for about three hours while securing affected infrastructure and completing additional security checks. The incident represents a significant security failure for a company that prides itself on regulatory compliance and institutional-grade security, with the attackers managing to bypass security layers to drain $11.8 million in assets from a specific treasury wallet used for operational liquidity.
Triple-A emphasized that client assets were not exposed because the company does not provide digital asset custody services on behalf of customers. Client funds are held separately in trust accounts maintained with safeguarding institutions that were not affected by the incident. The company stated it remains well capitalized and can meet all of its liabilities, continuing to operate globally at normal service levels despite the breach. This demonstrates the effectiveness of Triple-A's asset segregation policies, which adhere to industry best practices of keeping client funds in separate, highly secured vaults likely utilizing cold storage or MPC (Multi-Party Computation) technology.
On-chain investigator Specter initially estimated losses at more than $9.3 million before revising the estimate to more than $9.7 million as additional transfers were identified. The investigator later estimated the total losses at about $11.8 million, although Triple-A has not disclosed the exact amount of digital assets lost. According to on-chain findings, the transferred assets were swapped and bridged to Ethereum, with the receiving address accumulating approximately 5,226.66 ETH, valued at roughly $9.7 million when the activity was first identified. Triple-A is working with internal and external cybersecurity experts, blockchain forensics specialists and relevant authorities, including the Singapore Police Force, to investigate the incident and trace affected assets.
The breach underscores recurring vulnerabilities in the 2024 crypto landscape, particularly the risk of "hot" or "warm" wallets even for companies utilizing multi-signature setups. Triple-A is currently working with external cybersecurity experts to determine whether the breach was the result of a technical exploit or social engineering attack targeting internal personnel. The incident serves as a wake-up call for the stablecoin payment gateway sector, highlighting the need for transparency in reporting losses and rigorous security audits to prove that vulnerabilities have been closed. While Triple-A's ability to absorb the loss through treasury reserves demonstrates financial resilience, the long-term impact may affect the company's valuation and ability to attract new institutional partners, as security remains the primary product for B2B crypto services.