Triple-A, the Singapore-based payments infrastructure firm that lets merchants accept crypto and settle in fiat, has confirmed unauthorised access to its treasury wallets, which reportedly le
Triple-A, the Singapore-based payments infrastructure firm that lets merchants accept crypto and settle in fiat, has confirmed unauthorised access to its treasury wallets, which reportedly led to the loss of $11.8 million in company-owned digital assets. The confirmation closes out nearly three days of escalating guesswork, during which on-chain security firms watched the figure climb from roughly $9.3 million to $9.7 million to something closer to $12 million, without a word from the company itself.
In a statement, Triple-A said it identified the unauthorised access on 25 July, affecting wallets holding its own digital assets. The company said, “Client funds were not affected. Triple-A does not provide digital asset custody on behalf of its clients, and client funds are held separately in trust accounts maintained with safeguarding institutions that were not exposed.”
As a precaution, the firm placed certain services into maintenance mode for roughly three hours while it secured the affected infrastructure and says all services have since resumed normal operation across its markets.
Triple-A described the hit as contained to specific operational accounts, one that it can absorb from its own treasury reserves, and said it remains well-capitalised and able to meet its liabilities. It is now working with internal and external cybersecurity teams, blockchain forensics specialists, and law enforcement, including the Singapore Police Force, to trace the funds and pursue recovery.

Triple-A
On-chain analyst Specter first flagged unusual outflows from Triple-A-linked wallets on 24 and 25 July. PeckShield picked up the trail shortly after, and together they put the early damage at just over $9.7 million, drained across six networks: Ethereum, TRON, Polygon, Arbitrum, Solana and TON.
The attacker’s playbook was familiar. After gaining access, the hacker stole stablecoins and other liquid assets, swapped them rapidly on decentralised exchanges, then bridged the proceeds to Ethereum, consolidating everything into a single address holding roughly 5,227 ETH. It is the same laundering logic seen across dozens of exploits this year: turn a messy multi-chain haul into one liquid position, because Ethereum has the deepest bridges and swap liquidity.
Specter’s alert also noted that the transfers arrived in tranches rather than one lump sum and that deposits were not disabled even as funds kept getting swept out, suggesting whoever managed the wallets did not realise the draining was live.
Triple-A’s insistence that this hits treasury assets rather than client money is meaningfully reassuring for merchants on the platform. But it does not answer the harder question: how a Major Payment Institution licensed by Singapore’s Monetary Authority, with EU authorisation and in-principle approval from Dubai’s VARA, ended up with close to $12 million sitting in internet-connected wallets over a weekend, unnoticed as they were being emptied.
Why Triple-A hackmatters beyond Singapore
Triple-A is not a household name in Lagos. Still, it sits in exactly the layer of infrastructure African stablecoin adoption depends on: the plumbing that lets a merchant accept USDC or USDT and get paid out in local currency without ever touching a crypto exchange. It belongs to the same category as the stablecoin-to-fiat players Nigerian and pan-African fintechs increasingly plug into for cross-border settlement.

That is why the incident deserves attention here, not because Triple-A’s African footprint is public, but because the failure mode it exposes, treasury funds sitting in hot wallets and drained faster than anyone noticed, is baked into the business model of every stablecoin payments rail, regardless of licensing. A serious regulator’s approval did not stop this. Neither did a reputable custody partner. What protected Triple-A’s clients was structural: their funds were never in the exposed wallets to begin with.
For African fintechs building on similar rails, the lesson isn’t to avoid stablecoin infrastructure. It’s that licensing and custody arrangements reduce risk without eliminating it, and due diligence on any payments partner now needs to include sharper questions: how much sits in hot wallets versus cold storage, how client funds are legally separated from operational treasury, and whether reserves can absorb a loss like this one without disruption.
Also read: 207 crypto hacks were recorded in H1 2026 as total stolen funds drop by 57% to $972 million