July 27, 2026 ChainGPT

Triple-A Suffers Multi-Chain Treasury Heist (~$10–12M) — Client Funds Unaffected

Triple-A Suffers Multi-Chain Treasury Heist (~$10–12M) — Client Funds Unaffected
Singapore-based stablecoin payments firm Triple-A says an unauthorized intrusion into its treasury wallets on July 25 led to the loss of company-owned digital assets — but stressed that client funds and payment operations were not affected. Triple-A temporarily put some services into maintenance for roughly three hours after detecting the breach, while it secured infrastructure and ran additional checks. The company says all services have been restored, transactions and settlements are processing normally across markets, and the incident impacted only its treasury assets. Triple-A added the financial hit was confined to specific operational accounts and will be absorbed by its treasury reserves. It also emphasized it does not custody customer crypto — client funds are held separately in trust accounts with safeguarding institutions that were not touched. Blockchain investigators flagged the suspicious activity before Triple-A’s public update. On-chain sleuth Specter initially reported more than $9.3 million drained from wallets linked to Triple-A, later revising that figure to $9.7 million and eventually estimating losses at about $11.8 million as additional transfers were uncovered. PeckShield also drew attention to the unusual transfers. Triple-A has not confirmed the total amount lost. Investigators say the wallet-draining activity spanned multiple chains — Ethereum, Solana, TRON and TON — with some reports also noting Polygon and Arbitrum transactions. According to on-chain analysis, funds were swapped and bridged to Ethereum after leaving the affected wallets; one receiving address reportedly accumulated roughly 5,226.66 ETH (about $9.7 million at the time the activity was first detected). There is no public confirmation that the funds were moved to an exchange, a mixer, or another laundering service, and no suspect has been publicly named. Triple-A has not disclosed how the breach occurred — whether via compromised credentials, an infrastructure flaw, or another attack vector — and the cause remains under investigation. The company said it’s working with internal and external cybersecurity experts, blockchain forensics specialists and relevant authorities, including the Singapore Police Force, to trace assets and support recovery efforts. It also reiterated that it remains well capitalized and can meet all liabilities, continuing to operate globally at normal service levels. No timeline was provided for concluding the probe, and Triple-A has not said whether any stolen funds have been frozen or recovered. This incident arrives amid a wave of DeFi and crypto-platform attacks in 2026. Last week, Lien Finance disclosed a loss of about 542,144.63 USDC after attackers exploited flaws in bond validation and pricing logic — a breach researchers likened to valuation failures rather than a classic smart contract exploit. Security firms tracking DeFi incidents estimate cumulative losses above $630 million in the first seven months of 2026, with common attack methods including oracle manipulation, pricing exploits, compromised credentials and bridge validation issues. Separately, wallets linked to the $285 million Drift Protocol exploit resumed moving funds after months of dormancy; on-chain records show over 23,095 ETH (roughly $44.4 million) flowed into Tornado Cash, complicating tracing and recovery efforts. As investigators continue to follow the Triple-A trail, the case highlights the persistent cross-chain risks facing treasury operations and the importance of segregated custody arrangements for client assets. Expect further updates as forensics and law enforcement push to determine the breach vector and whether any recovery or freezes are possible. Read more AI-generated news on: undefined/news