Triple-A, a cryptocurrency payments provider based in Singapore, faced a major security breach over the weekend that led to the theft of $11.8 million from its treasury wallets. The company first noticed suspicious activity on Friday when blockchain analysts spotted outflows around $9.3 million. But the unauthorized withdrawals continued, pushing losses higher as the weekend unfolded.
Triple-A responded by temporarily halting some platform functions on Saturday for about three hours to lock down the system and protect remaining assets. Since then, operations have resumed fully, with payment processing working normally again. Importantly, the firm stressed that customer funds were never at risk because they are held separately in trusted custody accounts, not in the company’s hot wallets.
This separation follows Singapore’s updated regulations from October 2024, which require crypto payment providers to keep customer assets isolated from operational funds in distinct blockchain addresses. While the exact method hackers used to breach the treasury wallets hasn’t been revealed, the stolen $11.8 million figure comes from blockchain tracking by security firms Specter and PeckShield, not from Triple-A itself.
The stolen funds were moved through seven different blockchain networks, complicating efforts to trace and recover the assets. This multi-chain attack highlights how hackers are increasingly exploiting interconnected crypto ecosystems.
Security experts along with local authorities, including the Singapore Police, are now investigating the incident. Such breaches raise concerns about the vulnerabilities in crypto infrastructure, even when client assets remain segregated. For context, other recent incidents like the $6.25 million smart contract hack affecting WEMIX show that crypto firms face constant risks from complex attacks.



