Hackers drained $11.8 million from Triple-A’s treasury wallets, as identified by blockchain analysts from Specter and blockchain security firm PeckShield. The initial loss estimate of $9.3 million quickly rose over the weekend as the attackers continued emptying the company’s hot wallets more than 30 hours after the first withdrawal was spotted.
Details of the Multichain Attack
The stolen assets migrated through several blockchains including Ethereum, TRON, Polygon, Arbitrum, Solana, The Open Network, and Bitcoin. PeckShield tracked the funds converging into a single Ethereum address holding over 5,226 ETH valued around $9.73 million that moved through multiple transactions within a tight time window.
Despite the ongoing outflows, new deposits were still appearing in the compromised wallets and were immediately swept out 31 hours after the breach detection. Triple-A reacted by temporarily suspending some services for roughly three hours to secure its infrastructure. Normal operations have since resumed.
Customer Asset Safety and Regulatory Context
Triple-A emphasized that client assets were left untouched. Unlike the treasury wallets targeted in the breach, customer funds are safeguarded in separate trust accounts at regulated institutions, complying with Singapore’s Payment Services Regulations introduced in late 2024. This framework mandates that licensed crypto payment providers segregate client assets on distinct blockchain addresses, enhancing protection against theft.
The company has brought in cybersecurity experts, blockchain forensics firms, and the Singapore police to investigate the breach. Triple-A operates under the Monetary Authority of Singapore and holds additional payment licenses in France, the US, and Canada through subsidiaries such as Paytop SAS.



