Singapore-based stablecoin payment firm Triple-A confirmed unauthorized access to its treasury wallet on Monday, July 27, 2026. The breach was first detected on the preceding Saturday. Following the initial detection alert, the company’s internal security team immediately placed specific services into maintenance mode for approximately three hours to prevent further losses.
The exact total amount lost remains a topic of debate among crypto security trackers. On-chain investigator Specter estimated the stolen operational funds reached $11.8 million. Meanwhile, blockchain security firm PeckShield published an initial analysis estimating a slightly lower figure of around $9.7 million. To date, Triple-A management has remained tight-lipped and declined to disclose the exact stolen amount. They have also not revealed the technical methods used by the hacker to breach the company’s treasury defenses.
Why Client Funds Remained Untouched
The incident affecting one of the major players in the B2B (business-to-business) crypto payment ecosystem understandably sparked concerns among its corporate clients. However, Triple-A possesses a structural shock absorber that immediately limited the impact: the firm does not custody or hold digital assets on behalf of customers.
All client funds are held separately in trust accounts. Due to this segregated architecture, last weekend’s attack only breached a single targeted layer. Losses were strictly confined to specific corporate operational accounts, without touching a single coin or cent of customer funds.
Who Bears the Loss
With client funds confirmed to be unaffected, the multi-million-dollar loss will be fully absorbed by the company. Management emphasized that they will cover the financial shortfall through internal treasury reserves already allocated for such contingencies.
Swift action to sever connections proved effective in containing the scope of the problem. Following three hours in emergency maintenance mode on Saturday, the platform’s full suite of services has since been restored. Inter-company transactions and daily fund settlements have resumed normally without further delays.
Tracing the Perpetrators Begins
With daily operations back on track, internal focus has turned to investigation and law enforcement. Triple-A has engaged independent cybersecurity specialists and blockchain forensics firms to trace the hacker’s on-chain movements and track where the stolen funds were transferred.
Given that the payment provider is headquartered in Singapore, it also immediately involved local law enforcement authorities. The Singapore Police Force has joined the joint team investigating the case. The weekend attack leaves a valuable lesson for the B2B crypto payment industry: hackers may find security vulnerabilities, but segregating operational accounts from customer funds remains the ultimate safeguard when alarm bells ring.
Reported by Cointelegraph.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




