Crypto
Triple-A's $11.8Million Treasury Wallet Breach: Funds Still Safe
Triple-A confirmed its treasury wallet breach, with losses rising to $11.8 M. While customer funds are safe as investigators track the stolen crypto.
15h ago 4,280

Key Insights:
- Triple-A confirmed unauthorized access to its treasury wallets, with losses now estimated at $11.8 million.
- The company said customer funds and payment services were not affected, as client assets are held separately.
- Singapore Police and blockchain forensic experts are tracking the stolen funds.
After nearly two days of speculation following suspicious on-chain activity, crypto payment provider Triple-A has officially confirmed that its treasury wallets were compromised in a cyberattack.
The company said the breach was limited to its own operational assets and stressed that customer funds remain secure, even as the estimated losses have climbed to $11.8 million.
Triple-A Confirms Treasury Wallet Breach
In its first public statement since the incident, Triple-A acknowledged that attackers gained unauthorized access to certain company controlled digital asset wallets.
The company said the breach has been contained and that all payment services have returned to normal operations.
To reduce any further risk, Triple-A temporarily placed parts of its platform into maintenance mode for around three hours while its security team secured the affected infrastructure and completed additional system checks.
The company emphasized that the attack did not affect client assets because it does not provide digital asset custody for customers. Instead, client funds are held separately in safeguarded trust accounts maintained by external institutions that were not exposed during the incident.
Triple-A also stated that the financial impact was limited to its operational treasury accounts and would be fully absorbed using the company's own reserves, adding that it remains well-capitalized and capable of meeting all financial obligations.
How the Triple-A Exploit Unfolded
The attack first came to light when blockchain security researchers Specter detected unusual transactions involving Triple-A's hot wallet infrastructure.
According to the on-chain investigation, the attacker targeted the company's internet-connected wallets, which are used to process merchant settlements and provide liquidity for crypto payment services across multiple blockchain networks.
Spector believes the attacker gained access by compromising private keys or wallet access controls, although Triple-A has not yet confirmed the exact attack method.
Once inside, automated scripts rapidly drained stablecoins and native digital assets across Ethereum, Solana, TRON, and TON, allowing the attacker to move funds before internal security systems could fully isolate the compromised infrastructure.
Initial estimates placed the losses at around $9.7 million, but updated blockchain data now indicates that approximately 5,227 ETH, worth around $11.8 million, was ultimately stolen.
Where Are the Stolen Funds Now?
The stolen assets have not yet been recovered. Blockchain records show that the attacker consolidated nearly all of the stolen crypto into a single Ethereum wallet (0x01F8...53b1) after moving assets across multiple blockchain networks.
Security researchers believe the attacker bridged funds from Solana, TRON, and TON onto Ethereum before combining them into one address, a technique commonly used to simplify asset management before attempting to launder or cash out the proceeds.
As of now, the wallet continues to hold roughly 5,227 ETH, giving investigators a clear view of the stolen assets as they monitor for any attempt to move the funds through exchanges, mixers, or other privacy services.
Recovery Efforts Are Ongoing
Triple-A said it has launched a full investigation with support from both internal and external cybersecurity specialists.
The company confirmed it is working alongside blockchain forensic experts and the Singapore Police Force to trace the stolen assets and support recovery efforts.
These investigations will focus on tracking wallet activity, identifying the attacker's methods, and determining whether any of the funds can be frozen if they enter regulated trading platforms.
According to the company, the breach was limited to wallets operated by Triple A Technologies Pte. Ltd., its Singapore entity, while all other Triple-A entities and business operations remained unaffected.
How does this read?
Comments · 0
Sign in to comment. Accounts coming soon.
No comments yet
Be the first to share your take when accounts launch.



