Loading market data...

Triple-A Reports Wallet Breach, Says Client Funds Unaffected

Triple-A Reports Wallet Breach, Says Client Funds Unaffected

Singapore-based stablecoin payments firm Triple-A disclosed a wallet breach this week, saying unauthorized parties accessed wallets holding the company's own digital assets. The firm said client funds were not affected because they are held in separate trust accounts.

What happened

On-chain data shows roughly 5,280 ETH — about 5,287.08408568411 ETH — was drained into a single address (0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1) via 12 inbound transfers on July 24-25, 2026. Triple-A identified the incident on July 25 and issued a statement on July 27. Services were put into maintenance mode for about three hours before being restored.

Client money safe

Triple-A stressed that the breach did not touch client money. The company does not custody digital assets for clients; client funds are held in trust accounts with safeguarding institutions. The financial hit was limited to operational accounts and was fully absorbed from treasury reserves, the firm said.

Who's investigating

Triple-A is working with cybersecurity and blockchain-forensics specialists, the Singapore Police Force, and other authorities to trace the stolen assets and support recovery. The company has not confirmed the on-chain address identified by analyst Specter, nor the source wallets or their account roles.

Regulatory context

The Monetary Authority of Singapore (MAS) lists Triple A Technologies Pte. Ltd. as a Major Payment Institution authorized for domestic and cross-border transfers, merchant acquisition, and digital payment token services. That status requires compliance with customer-money protection rules. The company has not disclosed the size of its treasury loss or how the wallets were accessed.

Triple-A has not said whether it expects to recover the funds or when it will provide more details. The investigation is ongoing.