Attack on Coinsbuy: how hackers withdrew $8 million in an hour via TRON and Ethereum

The cryptocurrency platform Coinsbuy faced a large-scale coordinated attack, resulting in the theft of $8.07 million on August 9. The incident affected two of the largest networks at once — TRON and Ethereum, indicating a high level of preparedness on the part of the attackers.
Timeline of the hack and key transactions
The attack began with a test transfer of 5 USDT on the TRON network — a classic technique for checking the functionality of withdrawal channels. After that, within an hour, 6.04 million USDT was withdrawn from eight wallets, with the largest transaction amounting to about 3.5 million USDT. In parallel, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. The funds were quickly converted into 981.1 ETH through the decentralized protocol 1inch, using a wallet created within the same hour.
Connection between networks and traces of laundering
Analysis of on-chain data allowed me to establish that both parts of the attack were part of a single operation. The key link was the cross-chain service Bridgers: its payout contract on Ethereum directed funds to a wallet for swaps, with the amounts and timing of transactions fully matching the attacker's actions. This confirms that the perpetrator used sophisticated infrastructure to obfuscate their tracks.
The laundering of stolen funds went through the exchanger FixedFloat — approximately 79% of the assets passed through it, involving about 50 one-time addresses. However, some of the funds were frozen: the service ChangeNOW, after a request from Specter Investigations analysts, blocked 150 ETH (~$288,000), while another 282 ETH (~$542,000) remain untouched across five addresses.
Strange behavior of the Coinsbuy team
The most intriguing aspect of this incident is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely illogical decision, unless the developers are confident that the private keys were not compromised. As experts rightly note: "No one tops up a hacked wallet with seven-figure sums twice in one night."
Initially, the damage was estimated at $7.9 million, but my calculation of individual transactions shows a more accurate figure — $8,073,992. The exact attack vector has not yet been established, and no official comments have been received from Coinsbuy.
My expert assessment: This incident highlights the growing sophistication of hacker groups that combine cross-chain protocols and decentralized exchanges for the instant withdrawal of funds. However, the team's replenishment of the hacked wallets is an unprecedented step that could indicate either an internal error or an attempt to conceal the true scale of the problem. Investors should exercise heightened caution when dealing with platforms that do not disclose details of security incidents.