Singapore-based payments infrastructure firm Triple-A has confirmed the loss of $11.8 million due to unauthorised access to its treasury wallets. The breach occurred on 25 July, with initial outflows detected as early as 24 July, affecting wallets holding company-owned digital assets across six blockchain networks: Ethereum, TRON, Polygon, Arbitrum, Solana and TON. On-chain analysts Specter and PeckShield tracked the stolen funds as they were rapidly swapped and bridged to Ethereum, where approximately 5,227 ETH were consolidated in a single address, following a laundering pattern seen in multiple 2024 exploits.

Triple-A stated that client funds were not impacted, as it does not provide digital asset custody and keeps client money in separate trust accounts with safeguarding institutions. Services were briefly placed in maintenance mode for about three hours while the company secured its infrastructure, with full operations now restored. The firm emphasized that the loss is contained to internal operational accounts and can be absorbed by its treasury reserves, maintaining it remains well-capitalised. Triple-A is collaborating with cybersecurity teams, blockchain forensics experts, and the Singapore Police Force to trace and recover the stolen assets.

💡 NaijaBuzz Take

The breach reveals how quickly a licensed payments firm can lose millions when treasury funds are left in internet-connected wallets. African merchants relying on similar stablecoin rails should question how such exposure is managed if a company's security lapses go unnoticed for hours.

Editorial note: AI-assisted opinion, not established fact. Full disclaimer →