Skip to main content
Sign in
Triple-A Payments1 decision on this page

Audit log

Every state-changing event for Triple-A Payments: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-27 12:04:21Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    ZR3RfF4bYpNY…an47nG6Csha256 → base58
    verifying row…
    canonical bytes (18652 B) ▸
    {"actor":"system:backfill","investigation_id":"fe87f302-f93d-4657-9556-cd98ba92bdd3","kind":"publish","page_slug":"triple-a-payments","published_at":"2026-07-27T12:04:21.107Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Triple-A Payments","sections":[{"content":"Triple-A Technologies Pte. Ltd., trading as Triple-A, is a Singapore-based crypto payments gateway founded in 2017 by Eric Barbier, a serial fintech entrepreneur who previously founded cross-border payments platform Thunes. The company incorporated formally in Singapore in 2020 and became the first digital currency payment company to receive a Major Payment Institution (MPI) licence from the Monetary Authority of Singapore (MAS) under the Payment Services Act, authorizing it to provide digital payment token (DPT) services. Beyond Singapore, Triple-A holds a Payment Institution licence from France's ACPR, a Crypto-Asset Service Provider (CASP) licence from France's AMF, a Money Service Business registration with the United States Financial Crimes Enforcement Network (FinCEN), and a Foreign Money Service Business registration with Canada's FINTRAC. The company serves over 1,000 enterprise clients — including Grab, Razer, and Farfetch — across 120 countries from six global offices. In 2023, Triple-A raised a $10 million Series A led by Peak XV Partners with strategic backing from Shorooq Partners, bringing total disclosed funding to $14 million. The company uses Fireblocks as part of its digital asset custody infrastructure.","heading":"Company Overview","severity":"low","sources":[{"credibility":1,"name":"Triple-A: First Digital Currency Payment Company Licensed by MAS","type":"official","url":"https://www.triple-a.io/newsroom/triplea-the-first-digital-currency-payment-company-to-be-licenced-by-mas"},{"credibility":1,"name":"Triple-A raises $10M Series A from Peak XV and Shorooq Partners","type":"official","url":"https://www.triple-a.io/newsroom/triple-a-raises-10m-series-a-from-peak-xv-and-shorooq-partners-to-be-the-most-regulated-payments-institution-for-digital-currency-worldwide"},{"credibility":1,"name":"Triple-A About Us page","type":"official","url":"https://www.triple-a.io/about-us"},{"credibility":1,"name":"TechCrunch: Triple-A gets funding from Peak XV","type":"news_article","url":"https://techcrunch.com/2023/10/24/triple-a/"},{"credibility":2,"name":"Vulcan Post: TripleA receives MAS DPT licence","type":"news_article","url":"https://vulcanpost.com/770555/triplea-mas-license-digital-payment-token-services-singapore/"}]},{"content":"On July 25, 2026, Triple-A confirmed unauthorized access to wallets containing the company's own digital assets. On-chain investigator Specter first flagged anomalous outflows on July 24, 2026, estimating at least $9.3 million had been drained from Triple-A hot wallets and bridged to Ethereum. Blockchain security firm PeckShield subsequently revised the estimate upward to approximately $9.7 million as additional transactions were identified. As of July 27, 2026, The Block reported total losses had climbed to approximately $11.8 million, with on-chain data showing deposits continued to flow into compromised wallets for at least 31 hours after initial detection. The attacker consolidated stolen assets — approximately 5,227 ETH — into a single Ethereum address; the primary consolidation address begins with 0x01F8 but the full address had not been publicly disclosed in verified sources as of the time of this investigation. Affected blockchains include Ethereum, TRON, Polygon, Arbitrum, Solana, and TON, suggesting the attacker gained access to wallet infrastructure controlling keys across multiple networks simultaneously. Security researchers characterized the root cause as a hot-wallet compromise — a failure of key management or access control — rather than a smart-contract vulnerability. Triple-A placed certain services into maintenance mode for approximately three hours on July 25, after which it stated all services were restored. The company stated it is working with internal and external cybersecurity experts, blockchain forensics specialists, and the Singapore Police Force to trace the funds. A discrepancy exists between Triple-A's stated three-hour containment window and on-chain evidence showing continued draining for 31 hours, which had not been publicly explained by the company as of July 27, 2026.","heading":"July 2026 Treasury Wallet Exploit","severity":"critical","sources":[{"credibility":1,"name":"The Block: Triple-A hot wallet losses climb to $11.8 million","type":"news_article","url":"https://www.theblock.co/post/409678/triple-a-hot-wallet-losses-climb-to-11-8-million-as-new-deposits-keep-being-swept-report"},{"credibility":2,"name":"CryptoTimes: Triple-A Hack Losses Reach $11.8M as Deposits Drained for 31 Hours","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/triple-a-hack-losses-reach-11-8m-as-deposits-drained-for-31-hours/"},{"credibility":2,"name":"crypto.news: Triple-A says it can meet all liabilities after treasury wallet exploit","type":"news_article","url":"https://crypto.news/triple-a-says-it-can-meet-all-liabilities-after-treasury-wallet-exploit/"},{"credibility":2,"name":"Crypto Briefing: Triple-A hot wallet losses reach $12M","type":"news_article","url":"https://cryptobriefing.com/triple-a-hot-wallet-12m-security-breach/"},{"credibility":2,"name":"AMBCrypto: Triple-A exploit drains $9.7M across 4 chains","type":"news_article","url":"https://ambcrypto.com/triple-a-exploit-drains-9-7mln-across-4-chains-what-we-know-so-far/"},{"credibility":2,"name":"Bitcoin.com News: Triple-A Hot Wallets Drained of $9.7M — PeckShield","type":"news_article","url":"https://news.bitcoin.com/triple-a-hot-wallet-exploit-9-7-million-peckshield/"},{"credibility":2,"name":"CryptoTimes: Triple-A Hot Wallets Drained of $9.3M (initial report)","type":"news_article","url":"https://www.cryptotimes.io/2026/07/25/triple-a-hot-wallets-drained-of-9-3m-across-tron-ethereum-ton-solana/"},{"credibility":2,"name":"Cryptonomist: Triple-A Treasury Hack","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/27/triple-a-treasury-hack/"}]},{"content":"Triple-A publicly asserted that client funds and payment operations remained unaffected by the July 2026 breach. The company stated that customer assets are held in separate trust accounts under Singapore's Payment Services Regulations, distinct from the company's own treasury wallets that were compromised. Triple-A further stated it is well capitalized and can meet all of its liabilities, indicating it intends to absorb the estimated $11.8 million loss from its own reserves without customer recourse. These claims had not been independently verified by a regulator or auditor as of July 27, 2026. The Monetary Authority of Singapore had not issued a public statement on the incident as of that date.","heading":"Customer Fund Segregation and Company Solvency Claims","severity":"high","sources":[{"credibility":2,"name":"crypto.news: Triple-A says it can meet all liabilities after treasury wallet exploit","type":"news_article","url":"https://crypto.news/triple-a-says-it-can-meet-all-liabilities-after-treasury-wallet-exploit/"},{"credibility":2,"name":"Blockonomi: Singapore's Triple-A Reports $11.8M Cryptocurrency Treasury Breach","type":"news_article","url":"https://blockonomi.com/singapores-triple-a-reports-11-8m-cryptocurrency-treasury-breach"}]},{"content":"The July 2026 incident exposed significant operational security concerns. The multi-chain scope of the exploit — spanning Ethereum, TRON, Polygon, Arbitrum, Solana, and TON simultaneously — indicates the attacker obtained access to centralized wallet infrastructure or key management systems controlling hot wallets across all affected networks, rather than exploiting a vulnerability specific to any individual chain. Security researchers characterized this as a hot-wallet key management or access control failure. An additional concern raised by on-chain data is that new customer deposits continued flowing into compromised wallet addresses for approximately 31 hours after initial detection, suggesting the company's incident response did not immediately halt incoming fund routing to affected addresses. Triple-A uses Fireblocks for custody infrastructure; as of July 27, 2026, neither Fireblocks nor Triple-A had confirmed or denied whether the breach involved a failure in Fireblocks-managed infrastructure. The attack vector had not been publicly disclosed by the company.","heading":"Operational Security Failures","severity":"critical","sources":[{"credibility":1,"name":"The Block: Triple-A hot wallet losses climb to $11.8 million","type":"news_article","url":"https://www.theblock.co/post/409678/triple-a-hot-wallet-losses-climb-to-11-8-million-as-new-deposits-keep-being-swept-report"},{"credibility":2,"name":"Crypto Briefing: Triple-A hot wallet losses reach $12M","type":"news_article","url":"https://cryptobriefing.com/triple-a-hot-wallet-12m-security-breach/"},{"credibility":2,"name":"Blockonomi: Triple-A Crypto Payment Provider Hit by $9.7M Multi-Blockchain Security Breach","type":"news_article","url":"https://blockonomi.com/triple-a-crypto-payment-provider-hit-by-9-7m-multi-blockchain-security-breach"}]},{"content":"Triple-A stated it is coordinating with the Singapore Police Force as part of its incident response. As a MAS-licensed Major Payment Institution, Triple-A is subject to regulatory reporting obligations under Singapore's Payment Services Act for material security incidents. The MAS had not issued a public statement or disclosed any regulatory action related to the breach as of July 27, 2026. Triple-A also holds regulated status in France (ACPR and AMF), the United States (FinCEN), and Canada (FINTRAC); none of these regulators had publicly commented on the incident as of the investigation date.","heading":"Regulatory and Law Enforcement Response","severity":"medium","sources":[{"credibility":2,"name":"crypto.news: Triple-A says it can meet all liabilities after treasury wallet exploit","type":"news_article","url":"https://crypto.news/triple-a-says-it-can-meet-all-liabilities-after-treasury-wallet-exploit/"},{"credibility":1,"name":"MAS: Licensing for Payment Service Providers","type":"regulatory","url":"https://www.mas.gov.sg/regulation/payments/licensing-for-payment-service-providers"}]},{"content":"Prior to the July 2026 incident, Triple-A had not been associated with any publicly reported regulatory enforcement actions, fraud allegations, or prior security breaches. The company had cultivated a reputation as one of the more rigorously licensed crypto payment processors globally, with MAS licensure frequently cited as a trust signal. It had attracted backing from established venture firms including Peak XV Partners (formerly Sequoia Capital India) and held partnerships with companies including Crypto.com. No court filings, SEC or CFTC actions, or OFAC designations related to Triple-A were identified in research conducted for this investigation.","heading":"Prior History and Reputation","severity":"low","sources":[{"credibility":1,"name":"Triple-A raises $10M Series A from Peak XV and Shorooq Partners","type":"official","url":"https://www.triple-a.io/newsroom/triple-a-raises-10m-series-a-from-peak-xv-and-shorooq-partners-to-be-the-most-regulated-payments-institution-for-digital-currency-worldwide"},{"credibility":2,"name":"Crypto.com and Triple-A Partner to Enable Direct Crypto Payments","type":"official","url":"https://crypto.com/us/company-news/cryptocom-and-triple-a-partner-to-enable-direct-crypto-payments"}]}],"sources_used":[{"credibility":1,"name":"The Block: Triple-A hot wallet losses climb to $11.8 million","type":"news_article","url":"https://www.theblock.co/post/409678/triple-a-hot-wallet-losses-climb-to-11-8-million-as-new-deposits-keep-being-swept-report"},{"credibility":2,"name":"crypto.news: Triple-A says it can meet all liabilities after treasury wallet exploit","type":"news_article","url":"https://crypto.news/triple-a-says-it-can-meet-all-liabilities-after-treasury-wallet-exploit/"},{"credibility":2,"name":"Cryptonomist: Triple-A Treasury Hack","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/27/triple-a-treasury-hack/"},{"credibility":2,"name":"Crypto Briefing: Triple-A hot wallet losses reach $12M","type":"news_article","url":"https://cryptobriefing.com/triple-a-hot-wallet-12m-security-breach/"},{"credibility":2,"name":"CryptoTimes: Triple-A Hack Losses Reach $11.8M as Deposits Drained for 31 Hours","type":"news_article","url":"https://www.cryptotimes.io/2026/07/27/triple-a-hack-losses-reach-11-8m-as-deposits-drained-for-31-hours/"},{"credibility":2,"name":"CryptoTimes: Triple-A Hot Wallets Drained of $9.3M (initial report)","type":"news_article","url":"https://www.cryptotimes.io/2026/07/25/triple-a-hot-wallets-drained-of-9-3m-across-tron-ethereum-ton-solana/"},{"credibility":2,"name":"AMBCrypto: Triple-A exploit drains $9.7M across 4 chains","type":"news_article","url":"https://ambcrypto.com/triple-a-exploit-drains-9-7mln-across-4-chains-what-we-know-so-far/"},{"credibility":2,"name":"Bitcoin.com News: Triple-A Hot Wallets Drained of $9.7M — PeckShield","type":"news_article","url":"https://news.bitcoin.com/triple-a-hot-wallet-exploit-9-7-million-peckshield/"},{"credibility":2,"name":"Blockonomi: Singapore's Triple-A Reports $11.8M Cryptocurrency Treasury Breach","type":"news_article","url":"https://blockonomi.com/singapores-triple-a-reports-11-8m-cryptocurrency-treasury-breach"},{"credibility":2,"name":"Blockonomi: Triple-A Crypto Payment Provider Hit by $9.7M Multi-Blockchain Security Breach","type":"news_article","url":"https://blockonomi.com/triple-a-crypto-payment-provider-hit-by-9-7m-multi-blockchain-security-breach"},{"credibility":2,"name":"beInCrypto: Triple-A exploit $9M wallet drain","type":"news_article","url":"https://beincrypto.com/triple-a-exploit-9m-wallet-drain/"},{"credibility":1,"name":"Triple-A: First Digital Currency Payment Company Licensed by MAS","type":"official","url":"https://www.triple-a.io/newsroom/triplea-the-first-digital-currency-payment-company-to-be-licenced-by-mas"},{"credibility":1,"name":"Triple-A raises $10M Series A from Peak XV and Shorooq Partners","type":"official","url":"https://www.triple-a.io/newsroom/triple-a-raises-10m-series-a-from-peak-xv-and-shorooq-partners-to-be-the-most-regulated-payments-institution-for-digital-currency-worldwide"},{"credibility":1,"name":"Triple-A About Us page","type":"official","url":"https://www.triple-a.io/about-us"},{"credibility":1,"name":"TechCrunch: Triple-A gets funding from Peak XV","type":"news_article","url":"https://techcrunch.com/2023/10/24/triple-a/"},{"credibility":1,"name":"MAS: Licensing for Payment Service Providers","type":"regulatory","url":"https://www.mas.gov.sg/regulation/payments/licensing-for-payment-service-providers"},{"credibility":2,"name":"Vulcan Post: TripleA receives MAS DPT licence","type":"news_article","url":"https://vulcanpost.com/770555/triplea-mas-license-digital-payment-token-services-singapore/"},{"credibility":2,"name":"Crypto.com and Triple-A Partnership Announcement","type":"official","url":"https://crypto.com/us/company-news/cryptocom-and-triple-a-partner-to-enable-direct-crypto-payments"}],"summary":"Triple-A (Triple-A Technologies Pte. Ltd.) is a Singapore-headquartered crypto payment gateway founded by Eric Barbier and licensed by the Monetary Authority of Singapore (MAS) as a Major Payment Institution. On July 25, 2026, the company confirmed unauthorized access to its treasury hot wallets, with on-chain investigators estimating losses of approximately $11.8 million across six blockchains; the company stated that customer funds were unaffected and that it can meet all liabilities. The incident remained unresolved as of July 27, 2026, with no attacker identified and no funds recovered.","timeline":[{"date":"2017-01-01","event":"Triple-A founded by Eric Barbier in Singapore.","source":"Triple-A official about page","source_url":"https://www.triple-a.io/about-us"},{"date":"2021-01-01","event":"Triple-A becomes the first digital currency payment company to receive a Major Payment Institution licence from the Monetary Authority of Singapore under the Payment Services Act.","source":"Triple-A official newsroom","source_url":"https://www.triple-a.io/newsroom/triplea-the-first-digital-currency-payment-company-to-be-licenced-by-mas"},{"date":"2022-06-01","event":"Triple-A raises $4 million in seed funding from investors including 1982 Ventures, Razer, and Sequoia Capital.","source":"Crunchbase / various reporting","source_url":"https://www.crunchbase.com/organization/triplea"},{"date":"2023-10-24","event":"Triple-A announces $10 million Series A led by Peak XV Partners, bringing total disclosed funding to $14 million.","source":"TechCrunch","source_url":"https://techcrunch.com/2023/10/24/triple-a/"},{"date":"2024-11-01","event":"Triple-A announces partnership with Crypto.com enabling merchants to accept crypto without volatility exposure.","source":"Crypto.com official news","source_url":"https://crypto.com/us/company-news/cryptocom-and-triple-a-partner-to-enable-direct-crypto-payments"},{"date":"2026-07-24","event":"On-chain investigator Specter first flags anomalous outflows from Triple-A hot wallets across multiple blockchains, estimating approximately $9.3 million drained.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/25/triple-a-hot-wallets-drained-of-9-3m-across-tron-ethereum-ton-solana/"},{"date":"2026-07-25","event":"Triple-A confirms unauthorized access to company-owned treasury wallets; places services into maintenance for approximately three hours before restoring operations. PeckShield revises loss estimate to $9.7 million. Stolen assets consolidated to approximately 5,227 ETH at a single Ethereum address.","source":"crypto.news / CryptoTimes / AMBCrypto","source_url":"https://crypto.news/triple-a-says-it-can-meet-all-liabilities-after-treasury-wallet-exploit/"},{"date":"2026-07-27","event":"The Block reports total losses have climbed to $11.8 million, with on-chain data showing new deposits continued to be drained for 31 hours after initial detection. Triple-A states it can meet all liabilities and that Singapore Police Force is engaged. Incident remains unresolved with no attacker identified.","source":"The Block / CryptoTimes","source_url":"https://www.theblock.co/post/409678/triple-a-hot-wallet-losses-climb-to-11-8-million-as-new-deposits-keep-being-swept-report"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision d7f05ffd-6a1b-4e89-b60c-42a0e2302624
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.