Singapore-based stablecoin payments firm Triple-A has confirmed a major breach. Hackers broke into its treasury wallets and stole $11.8 million in company-owned digital assets. The confirmation came on Monday. It ended nearly three days of guesswork, during which the estimated loss kept climbing, from roughly $9.3 million, to $9.7 million, and eventually to almost $12 million. Throughout that stretch, the company itself stayed quiet.
Triple-A says it first noticed the unauthorized access on 25 July. The breach affected wallets holding its own digital assets, not client funds. In a statement, the company said client money was never at risk. That is because Triple-A does not hold digital assets in custody on behalf of clients. Instead, client funds sit separately in trust accounts with safeguarding institutions. Those accounts were never exposed to the breach.
As a precaution, Triple-A paused some services for about three hours. This gave its team time to secure the affected systems. All services have since returned to normal across every market the company operates in. Triple-A describes the loss as limited to specific operational accounts. It says it can absorb the hit using its own treasury reserves. The company maintains that it remains well capitalized and able to meet its obligations.
CHECK OUT:Stablecoins: The Quiet Shift Building On-Chain Trust
Triple-A is now working with several partners to trace the stolen funds. These include internal and external cybersecurity teams, blockchain forensics specialists, and law enforcement. The Singapore Police Force is also involved in the investigation.
According to on-chain analyst Specter, unusual outflows from Triple-A linked wallets first appeared on 24 and 25 July. Security firm PeckShield picked up the trail soon after. Together, they put the early damage at just over $9.7 million. The funds moved across six blockchain networks, including Ethereum, TRON, Polygon, Arbitrum, Solana and TON.
The attacker followed a pattern that has become common in crypto theft cases this year. First, stolen stablecoins and other liquid assets were swapped quickly on decentralized exchanges. Then, the proceeds were bridged over to Ethereum. Finally, everything was pooled into a single address holding roughly 5,227 ETH.
Investigators noticed something else, too. The funds moved out in batches, not all at once. Meanwhile, deposits into the compromised wallets were never switched off, even as money kept draining out. This suggests whoever managed the wallets did not realize what was happening until well after the theft began.
The fact that client money stayed untouched will come as a relief to merchants on the platform. Still, a tougher question remains unanswered. Triple-A is a Major Payment Institution licensed by Singapore’s Monetary Authority. It also holds authorization in the EU, plus in-principle approval from Dubai’s regulator. Despite that regulatory standing, close to $12 million sat in internet-connected wallets over a single weekend. Nobody caught the theft as it happened.
Triple-A may not be a familiar name to merchants in Lagos, Accra or Nairobi. Even so, it operates in exactly the kind of infrastructure African stablecoin adoption relies on. It belongs to the layer that lets a business accept USDC or USDT and get paid in local currency, without ever touching a crypto exchange directly. That puts it in the same category as the stablecoin-to-fiat rails that Nigerian and other African fintechs increasingly plug into for cross-border settlement.
This is exactly why the incident deserves attention on the continent. It is not because Triple-A has a known African presence. Rather, it is because the vulnerability it exposed is baked into how stablecoin payment rails generally work, no matter who licenses them. Treasury funds sitting in hot wallets, drained faster than anyone noticed, is a structural risk. Strong regulatory approval did not prevent this breach. Neither did a reputable custody setup. What actually protected Triple-A’s clients was simple: their money was never inside the wallets that got hit.
So what should African fintechs building on similar rails take from this? The lesson isn’t to avoid stablecoin infrastructure altogether. Instead, it’s that licensing and custody arrangements lower risk without removing it entirely. Due diligence on any payments partner now needs sharper questions. How much sits in hot wallets versus cold storage? How are client funds legally separated from company treasury? Could reserves absorb a loss this size without disrupting service?