Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

The cryptocurrency platform Coinsbuy fell victim to a large-scale coordinated attack, during which attackers withdrew $8.07 million across the TRON and Ethereum networks. The incident occurred on August 9, and my analysis of on-chain data allows me to reconstruct the full picture of what happened.
Timeline of the hack: from a test transaction to mass withdrawals
The attack began with a trial transfer of 5 USDT on the TRON network—a typical technique for verifying control over a wallet. After that, within about an hour, the attacker drained eight addresses, withdrawing 6.04 million USDT. The largest operation amounted to approximately 3.5 million USDT. Simultaneously, the hacker targeted three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH, which were converted into 981.1 ETH through the decentralized protocol 1inch.
The key evidence of a single operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum showed transactions matching the attacker's actions in amount and time, linking both parts of the attack into one chain.
Movement of funds and response from services
About 79% of the stolen assets passed through the exchange FixedFloat, where the hacker used approximately 50 one-time addresses to obfuscate the trail. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, indicating possible haste or technical limitations during withdrawal.
Strange behavior by the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to nearly 0.05%. This is an illogical action unless the developers are confident that the keys have not been compromised. As researchers rightly note: "No one tops up a hacked wallet with seven-figure sums twice in one night."
The final damage amounted to $8,073,992, although initial estimates pointed to $7.9 million. The exact attack vector has still not been established, and no official comments have been received from Coinsbuy.
My conclusion: This incident highlights the growing sophistication of cross-chain attacks, where attackers use decentralized protocols to move assets instantly. The strange behavior of the Coinsbuy team warrants a separate investigation—either we are dealing with an internal leak that is being covered up, or unprecedented negligence in risk management. In any case, the market should expect stricter security requirements from partners and regulators.