5,287 ETH moved to single address after Triple-A breach
On-chain records show 5,287.08568411 ETH consolidated into one Ethereum address after Triple-A reported unauthorized access to wallets holding its own assets.
On-chain records show 5,287.08568411 ETH moved into a single Ethereum address, 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1, across 12 inbound transfers on July 24 and July 25.
Triple-A, a Singapore-based stablecoin payments firm, detected the incident on July 25. In a statement the company wrote, “The incident affected wallets holding our own digital assets and did not impact client funds,” and added it remained able to meet its liabilities. The firm noted client money is held in separate trust accounts with safeguarding institutions and was not exposed.
Certain services were placed in maintenance for about three hours while the company secured affected infrastructure and ran security checks. Triple-A later confirmed all services were restored and that transactions and settlements were processing normally across its markets.
On-chain tracing identified 12 incoming transfers of more than 0.01 ETH each that total 5,287.08568411 ETH. Those public flows document funds consolidated into the cited address but do not reveal when the unauthorized access began, the original source wallets or what assets were in those source accounts before any swaps or bridges.
The company has not confirmed the cited address, disclosed an asset list, provided source wallet identifiers or reported a treasury loss figure.
Triple-A stated the financial impact was limited to specific operational accounts and would be absorbed from treasury reserves. The affected wallets were operated by Triple A Technologies Pte. Ltd., the firm’s Singapore entity; other group entities and operations were unaffected. The firm is working with cybersecurity and blockchain-forensics specialists, the Singapore Police Force and other authorities to trace assets and support recovery.
The Monetary Authority of Singapore lists Triple A Technologies Pte. Ltd. as a Major Payment Institution authorised to provide domestic and cross-border transfers, merchant acquisition and digital payment token services. That licence class requires customer-money protection measures, but the regulator’s directory does not confirm whether those protections were followed in this incident.
The total size of any treasury loss and the method by which the wallets were accessed remain unconfirmed.








