Singapore-based stablecoin payments company Triple-A has confirmed unauthorized access to wallets holding its own digital assets, following reports that the incident caused losses estimated at $11.8 million. The company said it identified the breach on July 25, 2026, contained the incident, and restored normal operations after temporarily restricting certain services. Triple-A stressed that client funds were not affected because the compromised wallets contained treasury assets rather than money held on behalf of customers.
Unauthorized Access Limited to Treasury Assets
Triple-A said the security incident affected specific operational wallets managed by Triple A Technologies Pte. Ltd., its Singapore entity. According to the company, no other group entities or business operations were exposed, and the financial impact will be absorbed through its treasury reserves. The firm also stated that it remains well capitalized, can meet its liabilities, and continues to provide services globally at normal operating levels.
Reported Loss Estimate Reaches $11.8 Million
Media reports have placed the estimated value of the stolen assets at approximately $11.8 million, citing blockchain analysis of suspicious transfers from wallets associated with Triple-A. Earlier estimates were lower, but on-chain investigators reportedly revised the figure after identifying additional unauthorized movements across multiple blockchain networks. Triple-A did not disclose a precise loss amount in its official statement, meaning the $11.8 million total remains an externally calculated estimate rather than a company-confirmed figure.
Client Funds Remained Segregated
The company emphasized that it does not provide digital asset custody for its clients and that customer money is maintained separately from corporate treasury holdings. Client funds are held in trust accounts with safeguarding institutions, which Triple-A said were not connected to or exposed by the compromised infrastructure. This separation appears to have prevented the breach from affecting customer balances, transactions, or settlement obligations despite the significant reported treasury loss.
Temporary Maintenance and Service Restoration
As a precaution, Triple-A placed certain services into maintenance mode for about three hours while it secured the affected systems and carried out security checks. The company said all services have since been restored, with transactions and settlements processing normally across its markets. The limited interruption was intended to reduce further exposure while technical teams assessed the incident and confirmed that the broader payment platform could continue operating safely.
Investigation and Recovery Efforts
Triple-A is working with internal security teams, external cybersecurity specialists, blockchain forensics experts, and relevant authorities to investigate how the unauthorized access occurred. The company specifically confirmed its cooperation with the Singapore Police Force as it seeks to trace the affected assets and support potential recovery efforts. It has not publicly identified the attacker, explained the initial point of compromise, or provided a timeline for completing the investigation.
Broader Significance for Stablecoin Infrastructure
The incident highlights the operational risks facing payment companies that connect traditional financial systems with blockchain-based settlement networks. Although customer safeguards limited the direct impact on clients, the reported loss underscores the importance of treasury wallet controls, transaction monitoring, and rapid incident response for regulated digital payment providers. Triple-A serves more than 1,000 enterprise customers through a platform that enables businesses to send, receive, and convert funds using stablecoin and conventional payment rails.
Triple-A’s confirmation provides reassurance that customer funds and core services remained protected, but important questions about the breach and the final financial impact remain unanswered. The company’s decision to absorb the loss from its own reserves limits immediate consequences for clients, while the continuing investigation will determine whether any assets can be recovered. Further disclosure about the attack method and subsequent security measures will be important for assessing how effectively Triple-A has addressed the underlying vulnerability.