Triple-A, a stablecoin payments provider, confirmed a crypto breach that resulted in the loss of around $11.8 million from its corporate treasury wallets. The Singapore-based firm detected unauthorized access on Saturday and temporarily paused select services to secure its systems. Despite the significant theft, Triple-A reassured that client funds remained untouched due to segregation from operational accounts.
Details of the Incident
The breach targeted specific operational wallets holding company-owned digital assets. Triple-A acted quickly, restricting services for approximately three hours to mitigate damage and restore normal operations. The company stated that treasury reserves would absorb the financial impact, highlighting an internal buffer against such attacks.
Neither the method of the wallet compromise nor the credentials involved were disclosed. Triple-A also withheld wallet addresses and the exact breakdown of stolen assets, making independent verification challenging. Blockchain tracking by onchain investigator Specter estimated the loss near $11.8 million, while PeckShield's earlier analysis placed losses above $9.7 million across multiple blockchains including Ethereum, Solana, and Polygon. Differences arise from token price fluctuations and transaction timings during ongoing investigations.
Client Asset Protection and Transparency Concerns
Unlike some crypto firms, Triple-A does not custody client digital assets directly. Instead, it uses safeguarding institutions and trust accounts to isolate customer funds, which reportedly kept client assets safe during the attack. However, no public audit or regulatory confirmation has validated these claims so far.
The incident exposes vulnerabilities in operational wallet security at regulated stablecoin payment providers, raising questions about transparency around wallet controls and breach disclosures.
This article is informational and does not constitute financial advice.



