Singapore-based stablecoin payments company Triple A said the unauthorized access to wallets holding its digital assets was contained without affecting customer funds. The company did not disclose the extent of its financial losses or explain how the wallets were accessed.
Triple A announced on July 25 that it had identified the incident. The company said in a statement on July 27 that it does not store customers’ digital assets and stores customer funds separately in trust accounts with custodial institutions that are not exposed.
Certain services were placed in maintenance mode for approximately three hours while the company secured the affected infrastructure and conducted security checks. Triple A has since announced that all services have been restored and trades and payments are being processed normally across all markets.
The company said the financial impact was limited to certain operating accounts and was fully absorbed from financial reserves. It also said the affected wallets were operated by Triple A Technologies Pte. Ltd. Ltd., its Singapore entity, and other group entities and operations were not affected. The statement did not provide a list of assets, wallet addresses or the amount of losses, but said Triple A continues to have the ability to repay its debts.
What the public wallet footprint shows
Identified by on-chain analyst Specter 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1 as the Ethereum address where funds related to the incident were consolidated. Etherscan records show that there were 12 incoming transfers of more than 0.01 ETH to that address on July 24th and July 25th, for a total of 5,287.08568411 ETH.
These transfers establish flow to the cited address, but do not establish when the unauthorized access began or how much Triple A lost. The company does not confirm the address, identify the source wallet, or explain the account’s role or original assets before swapping or bridging. This missing link also means that while Public Flow does not contradict Triple A’s claims about the separation of customers and funds, they cannot be independently verified.
The Monetary Authority of Singapore has listed Triple A Technologies Pte. Ltd. Ltd. is a leading payment institution licensed for domestic and cross-border remittances, merchant acquisition and digital payment token services. MAS states that institutions in its license class must comply with customer financial protection requirements. This directory establishes regulatory obligations, not whether Triple A met them during this incident.
Triple A said it is working with cybersecurity and blockchain forensics experts, the Singapore Police Force and other authorities to trace the assets and assist in their recovery. The two main unknowns are the scale of the Treasury loss and the route to access the wallet.
(Tag Translation) Featured


