Triple-A, a Singapore-based stablecoin payments company, said unauthorized access to wallets containing its own digital assets was contained without affecting customers’ money. The company did not disclose the extent of its cash loss or explain how the wallets were accessed.
Triple-A said it identified the incident on July 25. In its July 27 statement, the company said it did not hold digital assets for its clients and held client funds separately in trust accounts with custodial institutions that were not exposed.
Some services were placed in maintenance mode for approximately three hours while the company secured the affected infrastructure and carried out security checks. Triple-A later said all services had been restored and trading and settlements were proceeding normally in all markets.
The company said the financial impact was limited to specific operating accounts and was fully absorbed by cash reserves. It also said the affected wallets were operated by Triple A Technologies Pte. Ltd., its Singapore entity, and that the group’s other entities and operations were not affected. The statement did not disclose any list of assets, wallet addresses or loss figures, although Triple-A said it remained able to meet its debts.


What the public portfolio track shows
Onchain Analyst Specter Identified 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1 as an Ethereum address where funds related to the incident were being consolidated. Etherscan records show 12 inbound transfers of over 0.01 ETH to this address on July 24-25, totaling 5,287.08568411 ETH.
These transfers establish the flow to the cited address, but they do not establish when the unauthorized access began or how much Triple-A lost. The company did not confirm the address, identify the source wallets, or describe their original account roles and assets prior to the exchanges and bridges. This missing link also means that public feeds do not contradict Triple-A’s client funds segregation claim, but cannot independently verify it.
The Monetary Authority of Singapore lists Triple A Technologies Pte. Ltd. as a major payment institution authorized for domestic and cross-border transfers, merchant acquiring and digital payment token services. MAS claims that institutions in this license class must comply with requirements to protect customer money. The directory establishes the regulatory obligation, not whether Triple-A met it in this incident.
Triple-A said it was working with cybersecurity and blockchain forensics specialists, the Singapore Police Force and other authorities to trace assets and support recovery. The two central unknowns remain the extent of the cash loss and the route by which the wallets were accessed.





