Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Triple-A Hack Losses Reach $11.8M as Deposits Drained for 31 Hours

Triple-A says client funds are safe and the incident is contained, even as on-chain trackers recorded losses rising from an initial $9.3 million to about $11.8 million.

Written By Dhara Chavda
Edited by Divya Mistry
Published 2026-07-27·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
Triple-A Hack Losses Reach $11.8M as Deposits Drained for 31 Hours
AI Summary
Show
Triple-A confirmed unauthorized access on July 25, securing infrastructure within three hours
On-chain analysts reported a longer timeline, with funds being drained over 31 hours, totaling $11.8 million
The breach occurred amid a series of crypto security incidents, with $75.87 million lost in 40 hacks in June alone

Losses from the breach of Singapore payment firm Triple-A have climbed to about $11.8 million, and the gap between the company’s account and the on-chain record has become the central question of the incident.

The Company’s Timeline

In a statement posted July 25, Triple-A said it identified unauthorized access to certain wallets holding the company’s own digital assets. It described placing certain services into maintenance mode for approximately three hours while it secured the affected infrastructure, after which all services were restored and settlements resumed across all markets.

On 25 July 2026, Triple-A identified unauthorized access to certain wallets containing the company’s own digital assets.

Client funds were not affected. Triple-A does not provide digital assets custody on behalf of its clients, and client funds are held separately in trust… pic.twitter.com/CPQmMXAaOP

— Triple-A (@TripleAHQ) July 27, 2026

The company was firm on scope. It said the incident affected only its own treasury assets, that it remains well capitalized and able to meet all liabilities, and that the financial impact is limited to specific operational accounts and is being absorbed from its treasury reserves. It added that it is working with cybersecurity experts, blockchain forensics specialists, and the Singapore Police Force to trace the funds.

The On-Chain Timeline

Investigators describe a longer event. On-chain analyst Specter first flagged the draining on July 24, estimating that more than $9.3 million had been pulled from Triple-A hot wallets and bridged to Ethereum. Security firm PeckShield later put the figure above $9.7 million, with roughly 5,227 ETH consolidated into a single address.

The losses did not stop there. Specter reported that new deposits were still arriving and being swept roughly 31 hours after the first alert, taking the running total to about $11.8 million. According to that account, deposits were never disabled during the window; a detail that sits awkwardly beside the company’s description of a three-hour maintenance pause.

31 hours after pic.twitter.com/W04XoRrldv

— Specter (@SpecterAnalyst) July 26, 2026

The two timelines are not necessarily contradictory. Pausing certain front-end services is not the same as disabling on-chain deposit addresses, and Triple-A has not detailed which systems went into maintenance. But the practical result the chain records, funds continuing to flow into compromised wallets for more than a day, is the part the statement does not address.

The Question the Statement Leaves Open

The tighter question is what “only our own treasury assets” means for a payment processor. Triple-A operates a fiat-to-crypto gateway for more than 20,000 merchants, and its hot wallets exist to move a rotating pool of liquid assets as payments settle. When investigators say fresh deposits kept being drained, those inbound funds are the settlement flow the business runs on.

On the other side of the ledger, Triple-A’s client-funds-safe claim rests on a real obligation. As a firm regulated under Singapore’s Payment Services Act, it is required to safeguard customer money separately from its own, in trust accounts or under bank guarantee, the structure its statement points to.

Regulation Governs Custody, Not Hot-Wallet Keys

That regulatory standing is what makes the breach notable. Triple-A holds a Major Payment Institution license from the Monetary Authority of Singapore (MAS), No. PS20200525 and was the first digital-currency payment company MAS licensed. It also carries a Banque de France payment license passported across the EU and is registered with the US FinCEN and has long marketed itself as among the most regulated firms in its category.

None of that governs the security of an always-online hot wallet. Security researchers describe the root cause not as a smart-contract flaw but as a hot-wallet compromise — a failure of key management or access control, the same vector behind a run of 2026 infrastructure drains. Licensing sets standards for custody, anti-money-laundering, and safeguarding; it does not harden the operational keys an attacker actually reached here.

One point of fairness on attribution: Triple-A uses Fireblocks as part of its digital asset infrastructure, but neither on-chain researchers nor the company has linked the breach to Fireblocks, and there is no evidence its technology was compromised.

A Punishing Stretch for Crypto Security

The Triple-A breach lands in one of the worst runs of the year. Two days earlier, three separate attacks on July 23 drained $35.55 million, led by a $24.15 million loss at AFX Trade, and on July 27 WEMIX was hit again for $6.25 million. PeckShield counted $75.87 million lost across 40 hacks in June alone.

For now, the recovery hinges on tracing. The stolen funds sit largely consolidated on Ethereum, and with the Singapore Police Force engaged and forensics firms tracking the consolidation address, the next signal will be whether any of it moves toward mixers or off-ramps before it can be frozen.

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

SlowMist Exposes Liquid Network Flaw: How a Cache Collision Minted 3,998 Unbacked L-BTC
SlowMist Exposes Liquid Network Flaw: How a Cache Collision Minted 3,998 Unbacked L-BTC
Gold Ethereum coin positioned in front of a trading chart screen.
Ethereum Price Today: ETH Reclaims $2,600 After August CPI as Fed Rate Decision Looms
Gold Bitcoin coin with wooden "CPI" blocks, framed by the U.S. Capitol building and a green stock chart.
Bitcoin Reclaims $78K After US Inflation Data Meets Expectations
Ethena coin in front of an illuminated TRON wall logo.
Ethena Brings USDe and sUSDe to TRON as USDT Dominates 
Laptop displaying the Tether logo next to a gavel, with the U.S. Department of Justice seal in the background.
Tether Assists DOJ in $52M Global Scam Enforcement

Find Us on Socials

You may also like

Metaplanet Slashes Executive Option Pool by 41% Following Shareholder Pushback, Increasing Bitcoin-Per-Share Yield

Metaplanet Cuts Executive Warrant Pool by 41%, Boosting Bitcoin per Share 8.8%

Orange 3D text spelling "Strategy" with a stylized Bitcoin symbol forming the final letter "y" on a reflective dark surface

Michael Saylor’s Strategy (MSTR) Surpasses Dorsey’s Block Inc. in Market Cap

Hooded figure in dark clothing sitting behind a laptop screen with the green octopus logo and text for "Symbiosis" illuminated in the background

Symbiosis Bridge Exploit: Hacker Mints 368.9 Billion Synthetic Bitcoin

Smartphone screen showing "PumpFun" with a "Not Available" message stating "This app is currently not available in your country or region" set against blurred American and Indian flags

Pump.fun App Vanishes From Apple’s US and India Stores, Funds Remain Safe

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information