Singapore-based digital payments firm Triple-A said on Monday that it had detected unauthorized access to wallets containing the company’s own digital assets, but stressed that customer funds were not affected and all services had returned to normal.
The incident was identified on July 25, 2026, and has since been contained, Triple-A said in a statement. The company said the affected wallets held its own treasury assets and were separate from client funds.
“Client funds were not affected,” Triple-A said, adding that it does not provide digital asset custody services on behalf of clients. Customer funds are held separately in trust accounts maintained with safeguarding institutions that were not exposed in the incident.
As a precautionary measure, Triple-A temporarily placed certain services into maintenance mode for about three hours while it secured the affected infrastructure and conducted security checks. The company said all services have since been restored, with transactions and settlements processing normally across all markets.
The company said the incident had affected only its own treasury assets and would not impact its ability to meet financial obligations.
“Triple-A remains well capitalized, is able to meet all its liabilities and continues to operate globally at normal service levels,” the company said, adding that the financial impact was limited to specific operational accounts and would be fully absorbed through its treasury reserves.
Triple-A said it was working with internal and external cybersecurity experts, blockchain forensics specialists and relevant authorities, including the Singapore Police Force, to investigate the incident, trace the affected assets and support recovery efforts.
The company did not disclose the value of the affected digital assets or provide details on how the unauthorized access occurred.
Singapore’s Psalion launches $50M fund for next wave of blockchain adoption

