Singapore-based stablecoin payments firm Triple-A says it remains fully able to meet all its liabilities after an unauthorized breach of its treasury wallets led to multimillion‐dollar losses in company-owned digital assets.
The firm confirmed that only its own treasury funds were affected in the incident, which was detected on 25 July, and stressed that client money and day‐to‐day payment operations were untouched.
Triple-A said in a statement on Monday that unusual activity was picked up in wallets holding its proprietary digital assets, triggering an immediate response in which some services were taken into maintenance mode for around three hours while systems were secured and extra checks were run.
The company said all services have now been restored, with transactions and settlements processing as normal across all of its markets. It added that the financial hit is confined to specific operational accounts and will be fully covered by its existing treasury reserves.
According to Triple-A, client assets were never at risk because the company does not act as a custodian for customers’ digital assets. Instead, it said, client funds are kept in segregated trust accounts held with safeguarding institutions that sit outside the infrastructure affected by the breach.
Triple-A said it “remains well capitalized, can meet all of its liabilities, and continues to operate globally at normal service levels” despite the loss of company funds.
On-chain sleuths flagged activity before disclosure
The company’s confirmation came after blockchain investigators had already raised alarms over a series of unusual transactions involving wallets linked to Triple-A over the weekend.
On-chain analyst Specter initially estimated that more than $9.3m had been drained from wallets associated with Triple-A, later revising that figure to over $9.7m as further transfers came to light. A subsequent update from Specter put the apparent losses at about $11.8m, although Triple-A has not publicly disclosed the total value of digital assets lost.
Blockchain security firm PeckShield separately highlighted the suspicious flows after Specter’s first findings.
Before Triple-A issued its statement, researchers had been unable to determine whether the impacted wallets held corporate funds, customer balances or money destined for payment recipients. The company’s clarification that only treasury assets were involved confirmed that customer funds remained segregated from the compromised infrastructure.
Cause of breach still unknown
Triple-A has yet to explain how the attacker gained access to its wallets. The firm has not said whether the incident stemmed from stolen credentials, infrastructure vulnerabilities or another form of compromise, leaving the precise cause of the breach unresolved.
Earlier analysis by Specter suggested that the suspicious activity spanned wallets operating on Ethereum, Solana, TRON and TON, with some reports also pointing to transactions on Polygon and Arbitrum.
According to those on-chain findings, assets leaving the affected wallets were swapped and bridged onto Ethereum. Investigators said the receiving address amassed approximately 5,226.66 ETH, worth around $9.7m when the transfers were first identified.
Neither Triple-A nor independent researchers have named any suspected attacker. At the time of the company’s announcement, there was no public evidence that the funds moved to Ethereum had been deposited into a cryptocurrency exchange, a mixer or another known laundering platform.
Triple-A said it is working alongside internal and external cybersecurity specialists, blockchain forensics experts and “relevant authorities, including the Singapore Police Force” to investigate the attack, trace the stolen assets and support any potential recovery.
The company has not given a timetable for completing its inquiries, nor has it indicated whether any portion of the missing funds has been frozen or retrieved.
Part of wider wave of crypto and DeFi attacks
The incident comes amid a continuing sequence of hacks and exploits targeting cryptocurrency businesses and decentralised finance (DeFi) protocols in 2026.
Last week, DeFi platform Lien Finance reported a loss of about 542,144.63 USDC after attackers abused weaknesses in its bond validation and pricing logic. Security firm SlowMist said the flaw allowed unsupported bond tokens to be created and swapped for genuine USDC liquidity without locking up the necessary collateral.
DefimonAlerts and researcher exvulsec described the Lien Finance incident as a breakdown in protocol validation and valuation mechanisms rather than a traditional smart contract exploit. Analysts drew parallels with an earlier attack on Drift Protocol, noting that both cases centred on failures in asset valuation rather than breaches of cryptographic safeguards.
Researchers monitoring DeFi-related incidents estimate that total losses have surpassed $630m in the first seven months of 2026, with oracle manipulation, pricing errors, stolen credentials and bridge validation weaknesses among the techniques most frequently observed this year.
Separately, investigators are still tracking the aftermath of the $285m Drift Protocol exploit, after wallets linked to that case resumed activity following roughly three months of dormancy. On-chain records show that more than 23,095 ETH, valued at about $44.4m, has since been moved into Tornado Cash, further complicating efforts to trace the stolen funds.
