On-chain data shows 5,287 ETH transferred into a single Ethereum address across 12 inbound transfers on July 24 and 25 following unauthorized access to wallets operated by Triple-A, a Singapore-based stablecoin payments firm.

The transfers totaled 5,287.08568411 ETH according to Etherscan records, with the funds flowing into address 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1. Triple-A identified the incident on July 25 and issued a public statement on July 27.

Triple-A stated that unauthorized access affected only its own digital assets, not client funds. The firm does not custody digital assets for clients; client funds are held separately in trust accounts with safeguarding institutions. Triple-A said the financial impact was limited to specific operational accounts and was being fully absorbed from treasury reserves.

The affected wallets were operated by Triple A Technologies Pte. Ltd., the Singapore entity of Triple-A. Other group entities and operations were not affected. Services were placed in maintenance mode for three hours; all services have since been restored and transactions and settlements are processing normally across all markets.

Regulatory Status and Response

The Monetary Authority of Singapore lists Triple A Technologies Pte. Ltd. as a Major Payment Institution authorized for domestic and cross-border transfers, merchant acquisition, and digital payment token services. MAS requires institutions in that license class to comply with customer-money protection requirements.

Triple-A is working with cybersecurity and blockchain-forensics specialists, the Singapore Police Force, and other authorities to trace assets and support recovery. On-chain analyst Specter documented the transfers on public blockchain records.

The exact source of the unauthorized access and the mechanism by which the wallets were compromised have not been disclosed. Triple-A did not identify the source wallets or their original account roles.