Triple-A has confirmed that unauthorized access to several of its treasury wallets led to the loss of company-owned digital assets, while saying customer funds and core payment activity were not affected. The Singapore-based payments firm said the impact will be absorbed by its own reserves and that services have returned to normal.

Breach disclosed after July 25 incident

In a statement issued Monday, Triple-A said it detected unauthorized access to certain wallets holding its own digital assets on July 25. The company said it responded by placing some services into maintenance mode for about three hours as it moved to secure the affected infrastructure and carry out additional security checks.

According to Triple-A, all services have since been restored. It said transactions and settlements are now being processed normally across all markets.

Company says losses were limited to treasury assets

Triple-A said the incident involved only its treasury assets rather than customer holdings. The company described the financial damage as limited to specific operational accounts and said the losses would be fully covered through its treasury reserves.

It also said it remains well capitalized and is able to meet all of its liabilities despite the breach. The company added that it continues to operate globally at normal service levels.

Client funds described as segregated

Addressing customer exposure, Triple-A said client assets were not put at risk because it does not offer digital asset custody on behalf of users. Instead, it said customer funds are held separately in trust accounts with safeguarding institutions.

Those institutions were not affected by the incident, according to the company. Triple-A said payment operations also remained unaffected throughout the episode.

Investigation under way as losses estimated at $11.8 million

Before the company publicly acknowledged the breach, on-chain investigators had estimated the losses at about $11.8 million. Triple-A did not cite that figure in its statement but confirmed that company-owned digital assets were lost.

The firm said it is working with cybersecurity experts and Singapore police to investigate the incident and trace the stolen assets.

The disclosure adds Triple-A to the list of crypto-linked firms dealing with wallet security incidents, while also underscoring the distinction some payment companies draw between their own treasury management and customer fund safeguarding arrangements. In this case, the company’s position is that the compromise was confined to internal treasury wallets and did not affect client trust accounts or ongoing payment services.

Source: crypto.news