Triple-A stablecoin hack hits treasury assets, estimated loss is $11.8 million
Triple-A said client funds were untouched after a breach, while Cointelegraph cited an onchain estimate of about $11.8 million lost.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
Singapore-based stablecoin payments company Triple-A said a weekend security breach affected its own assets, with the triple-a stablecoin hack temporarily disrupting some services for about three hours. The company did not disclose the value of assets taken, but Cointelegraph cited an estimate from onchain investigator Specter that put the loss at roughly $11.8 million.
Triple-A said the incident occurred on Saturday, July 25, and was contained by the time it issued a public statement on Monday, July 27. The company said services had resumed and that transactions and settlements were being processed normally in all markets.
The breach affected Triple-A’s treasury assets, according to the company. Treasury assets are funds held by a company for its own operations, reserves or balance sheet needs, distinct from customer money held for payment processing or settlement.
Were client funds affected in the Triple-A stablecoin hack?
Triple-A said customer funds were not affected. The company said it does not custody digital assets for clients and that customer money is held separately in trust accounts with safeguarding institutions that were not exposed in the breach.
That separation is significant because custody arrangements determine who controls assets and where losses may fall after a cyber incident. In Triple-A’s account, the compromised infrastructure did not include the safeguarded accounts used for client funds.
Triple-A said it placed some services into maintenance mode for approximately three hours while it secured the affected systems and ran security checks. The company said it remains well capitalized and able to meet its liabilities.
The firm said it is working with internal and external cybersecurity experts, blockchain forensics specialists and authorities, including the Singapore Police Force, to investigate the breach, trace the affected assets and support recovery efforts.
Recent digital asset breaches add pressure on payments firms
The Triple-A incident came during a run of reported attacks on digital asset businesses. Blockchain network WEMIX said on Sunday, July 26, that an attacker had compromised ownership of its WEMIX$ stablecoin and converted it into 30,736 WEMIX and $724,198.27 in USDC stablecoins.
Separately, cryptocurrency wallet SecondFi said last week that it was winding down after an attack that stole $2.4 million from its users.
The incidents underscore the operational demands facing stablecoin and blockchain payment providers as more financial institutions study digital-asset products. In a PYMNTS interview on Monday, Tassat CEO Glen Sussman said banks’ attitudes toward blockchain had shifted after years of reluctance, while cautioning that real-time blockchain settlement systems require substantial work to operate around the clock and connect with older core banking systems.
Sussman said Tassat’s experience running blockchain-based settlement platforms for Signature Bank and Customers Bank showed the burden of keeping 24/7 environments aligned with bank infrastructure built for an earlier era. “People underestimate the work that it takes,” he said.
This story draws on original reporting from PYMNTS.