Someone drained Triple-A’s treasury wallets across seven blockchains starting Saturday, July 25, and the Singapore stablecoin payments firm didn’t say a word publicly until Monday.

By then, onchain investigator Specter had already pegged the damage at $11.8 million, with funds still moving through Ethereum, TRON, Polygon, Arbitrum, Solana and TON as new deposits kept getting swept.

Triple-A’s line is that client funds were never at risk because it doesn’t custody customer assets. Those sit in trust accounts with separate safeguarding institutions. What got hit was the company’s own treasury, and Triple-A says it’s well capitalized enough to absorb the loss and meet its liabilities without touching client balances.

That distinction matters, but it’s doing a lot of work. The gap between the first onchain alert and the company’s public confirmation is the kind of detail regulators and counterparties remember longer than the dollar figure. Singapore doesn’t have a breach-notification clock as rigid as GDPR’s 72 hours, but institutional partners increasingly write their own into vendor contracts.

Triple-A isn’t isolated. WEMIX disclosed an owner-key compromise on Sunday that let an attacker convert its WEMIX$ stablecoin into 30,736 WEMIX and roughly $724,000 in USDC before bridges got frozen. SecondFi wound down entirely last week after losing $2.4 million. Three treasury-side hits in one stretch, all hot-wallet or key-management failures, not user-side exploits.

Triple-A says the Singapore Police Force is now involved. Worth watching whether the final loss number climbs again before this one’s closed.

— Rebecca Lauren