
Triple-A said attackers stole $11.8M from corporate wallets across seven chains. Client funds held in segregated trust accounts were untouched. The breach forced a three-hour platform suspension.
A Singapore-based cryptocurrency payment processor, Triple-A, said Monday that attackers drained $11.8 million from its corporate treasury wallets over the weekend, forcing a three-hour suspension of some platform functions.
The breach first surfaced Friday when blockchain security researcher Specter flagged suspicious outflows of roughly $9.3 million. By Monday morning, the total had climbed to $11.8 million as the attackers continued pulling funds across seven blockchains – Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin – according to on-chain analysis from Specter and cybersecurity firm PeckShield.
Triple-A said no client funds were touched. The company's business model does not involve holding customer digital assets. Those sit in segregated trust accounts managed by independent custodians, a structure that follows Singapore's Payment Services Regulations, updated in October 2024 to require licensed crypto payment firms to keep customer holdings on separate blockchain addresses from operational funds.
The company became aware of the breach Saturday and suspended certain functions for about three hours to deploy emergency security protocols, it said in a statement. Operations have since resumed, with all payment processing working normally.
Triple-A has not disclosed how the attackers got in or how much remained in the compromised wallets. The $11.8 million figure comes from blockchain analysis, not from the company's own books.
PeckShield tracked the stolen assets to a single Ethereum wallet that accumulated more than 5,226 ETH – worth about $9.73 million at the time – across eight transactions between late Friday and early Saturday UTC. Specter noted that the compromised wallets kept receiving new deposits even 31 hours after the first large withdrawals, with each fresh deposit immediately swept by the attacker.
Triple-A holds a license from the Monetary Authority of Singapore and payment service authorization in France through its European subsidiary, Paytop SAS. It also has money services business registrations in the United States and Canada.
The company said it has hired cybersecurity consultants, blockchain forensics specialists, and the Singapore Police Force to investigate and attempt asset recovery. It has not published the update it promised Saturday. The press section of its website still shows a July 15 announcement about preliminary regulatory approval from Dubai's Virtual Assets Regulatory Authority.
The incident is one of three notable crypto exploits this week. AFX Trade lost roughly $24.15 million through a vulnerability in its Arbitrum custody bridge. The Verus-Ethereum bridge suffered a $7.54 million breach on the same day – its second major security failure since May.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.