Losses from the breach of Singapore payment firm Triple-A have climbed to about $11.8 million, and the gap between the company’s account and the on-chain record has become the central question of the incident.
The Company’s Timeline
In a statement posted July 25, Triple-A said it identified unauthorized access to certain wallets holding the company’s own digital assets. It described placing certain services into maintenance mode for approximately three hours while it secured the affected infrastructure, after which all services were restored and settlements resumed across all markets.
The company was firm on scope. It said the incident affected only its own treasury assets, that it remains well capitalized and able to meet all liabilities, and that the financial impact is limited to specific operational accounts and is being absorbed from its treasury reserves. It added that it is working with cybersecurity experts, blockchain forensics specialists, and the Singapore Police Force to trace the funds.
The On-Chain Timeline
Investigators describe a longer event. On-chain analyst Specter first flagged the draining on July 24, estimating that more than $9.3 million had been pulled from Triple-A hot wallets and bridged to Ethereum. Security firm PeckShield later put the figure above $9.7 million, with roughly 5,227 ETH consolidated into a single address.
The losses did not stop there. Specter reported that new deposits were still arriving and being swept roughly 31 hours after the first alert, taking the running total to about $11.8 million. According to that account, deposits were never disabled during the window; a detail that sits awkwardly beside the company’s description of a three-hour maintenance pause.
The two timelines are not necessarily contradictory. Pausing certain front-end services is not the same as disabling on-chain deposit addresses, and Triple-A has not detailed which systems went into maintenance. But the practical result the chain records, funds continuing to flow into compromised wallets for more than a day, is the part the statement does not address.
The Question the Statement Leaves Open
The tighter question is what “only our own treasury assets” means for a payment processor. Triple-A operates a fiat-to-crypto gateway for more than 20,000 merchants, and its hot wallets exist to move a rotating pool of liquid assets as payments settle. When investigators say fresh deposits kept being drained, those inbound funds are the settlement flow the business runs on.
On the other side of the ledger, Triple-A’s client-funds-safe claim rests on a real obligation. As a firm regulated under Singapore’s Payment Services Act, it is required to safeguard customer money separately from its own, in trust accounts or under bank guarantee, the structure its statement points to.
Regulation Governs Custody, Not Hot-Wallet Keys
That regulatory standing is what makes the breach notable. Triple-A holds a Major Payment Institution license from the Monetary Authority of Singapore (MAS), No. PS20200525 and was the first digital-currency payment company MAS licensed. It also carries a Banque de France payment license passported across the EU and is registered with the US FinCEN and has long marketed itself as among the most regulated firms in its category.
None of that governs the security of an always-online hot wallet. Security researchers describe the root cause not as a smart-contract flaw but as a hot-wallet compromise — a failure of key management or access control, the same vector behind a run of 2026 infrastructure drains. Licensing sets standards for custody, anti-money-laundering, and safeguarding; it does not harden the operational keys an attacker actually reached here.
One point of fairness on attribution: Triple-A uses Fireblocks as part of its digital asset infrastructure, but neither on-chain researchers nor the company has linked the breach to Fireblocks, and there is no evidence its technology was compromised.
A Punishing Stretch for Crypto Security
The Triple-A breach lands in one of the worst runs of the year. Two days earlier, three separate attacks on July 23 drained $35.55 million, led by a $24.15 million loss at AFX Trade, and on July 27 WEMIX was hit again for $6.25 million. PeckShield counted $75.87 million lost across 40 hacks in June alone.
For now, the recovery hinges on tracing. The stolen funds sit largely consolidated on Ethereum, and with the Singapore Police Force engaged and forensics firms tracking the consolidation address, the next signal will be whether any of it moves toward mixers or off-ramps before it can be frozen.
