Overview
- Triple‑A, which detected unauthorized access on July 25, said the breach drained roughly $11.8 million of company treasury assets and that services have been restored.
- On‑chain researchers tracked multi‑chain outflows that were swapped and bridged into a single Ethereum address holding about 5,226–5,287 ETH, but no attacker has been identified and no recoveries have been reported.
- The company says customer funds were not affected because client assets are held in segregated trust accounts with safeguarding institutions rather than in Triple‑A's hot wallets.
- Triple‑A has engaged external cybersecurity firms, blockchain forensics specialists and the Singapore Police Force, and says its treasury reserves will absorb the financial hit and it can meet liabilities.
- The incident underscores the operational risk of internet‑connected hot wallets, reinforces on‑chain tracing limits for recovery, and is likely to draw regulatory scrutiny under Singapore's payment rules.