Singapore payment company Triple-A confirmed on Monday that attackers gained unauthorized access to wallets holding its own digital assets, an incident on-chain investigators estimate drained roughly $11.8 million across seven blockchain networks. The company said in an official statement that it detected the intrusion on July 25, placed some services into maintenance mode for about three hours, and restored normal settlement afterward. Triple-A did not disclose the amount lost or how attackers got in. The gap between that account and what blockchain records show is now the sharpest question in the case: independent analysts say compromised addresses kept receiving and losing deposits for more than 31 hours after the first alert.
A hot wallet is an always-online crypto wallet a business uses to move funds quickly, as opposed to offline cold storage that holds reserves.
Key takeaways
- Triple-A confirmed unauthorized access to its own treasury wallets on July 25, disclosing it publicly on July 27.
- On-chain analyst Specter put losses at about $11.8 million, revised up from an initial $9.3 million estimate.
- Funds moved across Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin, with roughly 5,227 ETH consolidated into one Ethereum address.
- Client money was untouched because Singapore’s Payment Services Act requires it to sit in segregated trust accounts.
Published: July 27, 2026, 16:30 UTC
What the on-chain record shows
The blockchain timeline is longer than the company’s. On-chain analyst Specter flagged the draining on July 24, estimating that more than $9.3 million had already been pulled from Triple-A hot wallets and bridged to Ethereum. Security firm PeckShield later raised that to above $9.7 million and tracked roughly 5,227 ETH consolidating into a single address.
Specter then reported that fresh deposits were still arriving at the compromised wallets and being swept about 31 hours after the initial alert, pushing the running total to roughly $11.8 million. By that account, on-chain deposit addresses were never disabled during the window.
Those two versions can both be true. Pausing customer-facing services is not the same as retiring a compromised deposit address, and Triple-A has not specified which systems went into maintenance. The company’s statement does not address the continued inflows.

Why a licence did not prevent this
Triple-A is one of the most heavily licensed firms in crypto payments, which is exactly what makes the breach worth reading closely. It holds a Major Payment Institution licence from the Monetary Authority of Singapore and was the first digital-currency payment company MAS approved. Through its Paytop SAS entity it carries an EU payment institution licence and crypto-asset service provider registration, and it is registered with FinCEN in the United States and FINTRAC in Canada.
None of those regimes govern the security of an operational hot wallet. Licensing sets rules for safeguarding customer money, anti-money-laundering controls, and custody arrangements. Researchers describe this incident as a key-management or access-control failure rather than a smart contract bug, the same category behind several 2026 infrastructure drains including the $35 million bridge attacks on July 23.
The safeguarding rules did do their job on the customer side. Triple-A said it does not custody client digital assets and that client funds sit separately in trust accounts with third-party safeguarding institutions, a structure the Payment Services Act requires. The company said it remains well capitalised, that the impact is confined to specific operational accounts, and that it will absorb the cost from treasury reserves.
One caveat on attribution: Triple-A uses Fireblocks as part of its digital asset infrastructure, but neither the company nor on-chain researchers have connected the breach to Fireblocks, and there is no evidence its technology was involved.
What happens next
Recovery now depends on tracing. The stolen assets sit largely consolidated on Ethereum, and Triple-A said it is working with external cybersecurity experts, blockchain forensics specialists, and the Singapore Police Force. The signal to watch is whether the consolidation address starts moving funds toward mixers or off-ramps before exchanges can freeze them.
For merchants, the practical exposure is settlement timing rather than balances. Triple-A provides stablecoin payment rails to more than 1,000 enterprise customers and partners including Coinbase, Crypto.com, and Circle’s Payments Network, letting businesses accept and convert crypto without holding it. Payments that were mid-flight during the drain window are the ones worth reconciling.
The incident also lands in a punishing stretch. Three separate attacks on July 23 cost $35.55 million, led by a $24.15 million loss at AFX Trade, and WEMIX halted its bridges on Monday after a $6.25 million stablecoin exploit. PeckShield counted $75.87 million lost across 40 hacks in June alone. As stablecoin payment rails move into mainstream commerce, operational key security is becoming the binding constraint, not regulatory approval.
Frequently asked questions
Were Triple-A customer funds stolen?
No. Triple-A said the breach hit wallets holding the company’s own digital assets. It does not custody client crypto, and client money is held in segregated trust accounts with third-party safeguarding institutions, as required under Singapore’s Payment Services Act.
How much was actually taken?
Triple-A has not published a figure. On-chain analyst Specter estimates about $11.8 million, revised up from $9.3 million, while PeckShield tracked more than $9.7 million including roughly 5,227 ETH consolidated into a single Ethereum address.
Why did the losses keep growing after the company secured its systems?
Investigators say new deposits continued arriving at compromised addresses and were swept for about 31 hours. Pausing customer-facing services does not stop funds already routed to an on-chain address that an attacker controls.








