Triple-A Confirms Treasury Wallet Breach, Losses Estimated at $11.8 Million
Singapore-based stablecoin payments firm says client funds remain secure in segregated accounts as it absorbs the hit from multi-chain hot wallet exploit.
Triple-A, a Singapore-based stablecoin payment infrastructure provider, confirmed a security breach of its company treasury wallets, with on-chain analysts estimating losses at approximately $11.8 million. Client funds remain secure in segregated accounts, with the company absorbing the loss from treasury reserves.
The breach targeted Triple-A's hot wallets across multiple blockchain networks, including Ethereum, Solana, TRON, and TON. Initial estimates ranged from $9.3 million to $9.7 million before on-chain investigator Specter updated the figure to $11.8 million as additional suspicious deposits were tracked. Triple-A has not publicly disclosed an exact figure.
According to Triple-A's official statement, issued after initial reports surfaced, customer assets are held in separate trust accounts and remain unaffected. The financial impact will be absorbed entirely from the company's treasury reserves.
Stolen assets were consolidated into approximately 5,226 to 5,227 ETH on the Ethereum network, according to on-chain analysis. The multi-chain nature of the attack underscores the operational complexity facing payment providers that maintain treasury exposure across diverse blockchain networks.
Triple-A holds payment licenses in Singapore, the United States, and the European Union. The company enables businesses to receive and transmit funds via stablecoins and traditional banking rails. In March 2026, Triple-A integrated with the Circle Payments Network, expanding its institutional payment capabilities.
The incident highlights persistent security risks associated with hot wallet infrastructure, which must remain accessible for operational liquidity while presenting a larger attack surface than cold storage solutions. While Triple-A's ability to absorb the loss from reserves prevents a client-side crisis, the breach serves as a reminder that even licensed payment providers remain vulnerable to sophisticated exploits.
Details surrounding the exact attack vector and timeline of suspicious activity have not been publicly disclosed. Investigators continue to track the movement of stolen funds.