Jul 27, 2026 · 11:06 AM
Subscribe
Home Crypto

Triple-A's $11.8 million treasury drain shows licensed crypto payments firms are no safer than anyone else

Singapore's Triple-A, a MAS-licensed crypto payments processor, confirmed an $11.8 million hot wallet breach across seven blockchains, with attackers draining new customer deposits for over 31 hours after the first security alert. The company says client funds are unaffected, but hasn't explained how the attacker accessed private keys across seven chains simultaneously.

Elroy Fernandes
· 4 min read · 547 reads
Triple-A's $11.8 million treasury drain shows licensed crypto payments firms are no safer than anyone else

Singapore's Triple-A, a MAS-licensed crypto payments processor handling over $10 billion in transactions last year, confirmed an $11.8 million breach of its hot wallets across seven blockchains, with new customer deposits still being swept more than 31 hours after the first alert.

The breach was flagged by on-chain investigator Specter and blockchain security firm PeckShield before Triple-A said a word publicly. By the time the company acknowledged what had happened, the attacker had already moved across Ethereum, TRON, Polygon, Arbitrum, Solana, TON, and Bitcoin, swapping and bridging the proceeds until roughly 5,227 ETH sat in a single consolidation address: 0x01F8...53b1. The opening estimate was $9.7 million. It climbed to $11.8 million as deposits continued to flow into still-compromised wallets. That detail is the one that stings.

Triple-A has not disclosed how the attacker got in. What the mechanics make clear, though, is that this was not a smart contract bug. Draining hot wallets simultaneously across seven separate blockchain networks requires control over the private keys managing those wallets, whether through a compromised key management system or someone on the inside with access to the wallet infrastructure layer. The company said it is working with the Singapore Police Force, blockchain forensics firms, and cybersecurity specialists. It has not said which line of investigation it is pursuing most seriously.

Triple-A is not some fly-by-night exchange. It was the first digital currency payment company licensed by the Monetary Authority of Singapore. It raised a $10 million Series A from Peak XV and Shorooq Partners. Its enterprise client list runs through Southeast Asia and includes merchants like Farfetch, Charles and Keith, and the Singapore Red Cross. When it processed over $10 billion in crypto payments in 2024, the pitch to every one of those clients was built on compliance, on institutional-grade infrastructure, on being the safe option in a space known for losing money.

That pitch just took a significant hit. Not because client funds were affected , Triple-A says they weren't, held in segregated trust accounts managed by independent safeguarding entities , but because the attacker had 31 hours of uninterrupted access to incoming deposits after the first security alert. That is the gap that will be hard to explain away. A licensed, compliance-heavy payments processor with enterprise clients and a $10 billion annual throughput either couldn't detect the drain fast enough to stop new deposits from being swept, or detected it and couldn't respond in time. Neither answer is reassuring.

The broader context makes it worse. As The Block reported, industry losses from hacks in 2026 had already surpassed $750 million by mid-year, making this one of the worst stretches on record. Triple-A joins a list that includes Bybit's $1.5 billion North Korean-attributed breach in early 2025, which remains the largest single crypto theft in history. Institutional credentials have not proven to be much of a deterrent.

The hot wallet problem hasn't been solved

Every crypto firm that processes real-time payments faces the same structural tension. Hot wallets, connected to the internet to enable instant settlement, are operationally necessary. They are also the attack surface. Cold storage is safer but too slow for a payments business that needs to move funds in seconds. The industry has known this for years. Triple-A's breach is proof that knowing the problem and solving it are different things.

What makes the multi-chain dimension particularly notable here is the coordination it implies. An attacker who can drain wallets across Ethereum, TRON, Polygon, Arbitrum, Solana, TON, and Bitcoin in a single operation has access to keys or credentials at a layer above any individual chain. That points toward centralized key management infrastructure as the point of failure , the very system designed to make running a multi-chain payments business manageable is also the system that, if compromised, hands an attacker everything at once.

Triple-A says it can meet all its liabilities and that the financial impact will be absorbed through treasury reserves. That may be true. But the harder question for enterprise clients isn't whether Triple-A can cover the loss. It's whether the company's infrastructure is now demonstrably safer than it was on July 24, and on that question, the company has offered nothing yet. Frankly, a statement saying client funds are fine and investigators are on the case is the minimum a company can say in this situation. It is not the same as an answer.

Also read: Visa built the stablecoin rails so your bank doesn't have toGarden Finance shuts down after a $450,000 exploit hits its solver layer, not its protocolSamsung is putting stablecoin support in Galaxy Wallet and 241 million phones are the distribution play

TOPICS
Elroy is a digital marketer and developer from Goa, with over a decade of experience web development and marketing. He has been associated with several startups and serves currently as an Editor to the Asia Pacific Industrial magazine. He occasionally writes on Startup Fortune about technology and automation.
Related Articles
More posts →
Loading next article…
You're all caught up