ARTFEED — Contemporary Art Intelligence

Triple-A Treasury Wallet Exploit: $11.8M Stolen, Client Funds Safe

digital · 2026-07-28

On July 25, 2026, Triple-A, a crypto payments company based in Singapore, experienced unauthorized access to its treasury wallets, leading to an estimated theft of $11.8 million in digital assets. The firm assured that customer funds remained secure due to its segregated custody model, which keeps client assets in separate trust accounts with regulated financial institutions. The incident was confined to wallets managed by Triple A Technologies Pte. Ltd. and did not impact other operations. Services were briefly halted for three hours for security measures, after which normal operations resumed. Blockchain security analysts, including Specter and PeckShield, traced the stolen assets across various platforms. Triple-A is collaborating with cybersecurity teams, forensic experts, and the Singapore Police Force to investigate the breach, which highlights the critical nature of fund segregation in crypto payments. However, concerns linger regarding the security of treasury wallets, as the company has not revealed the number of affected wallets or any assets that have been recovered.

Key facts

  • Triple-A treasury wallet exploit occurred on July 25, 2026
  • Estimated $11.8 million in digital assets stolen
  • Customer funds were not compromised due to segregated custody model
  • Client assets held in separate trust accounts with regulated financial institutions
  • Services paused for three hours, then resumed
  • Stolen assets moved across Ethereum, TRON, Polygon, Arbitrum, Solana, and TON
  • Attacker consolidated funds into wallet holding 5,227 ETH
  • Investigation involves Singapore Police Force and blockchain forensic experts

Entities

Institutions

  • Triple-A
  • Triple A Technologies Pte. Ltd.
  • PeckShield
  • Singapore Police Force
  • NFT Plazas

Locations

  • Singapore

Sources