Crypto news

10.08.2026
13:35

Analysis of the Coinsbuy attack: $8 million stolen in a coordinated cross-chain operation

social network hacking

The crypto platform Coinsbuy fell victim to a meticulously planned attack, resulting in $8.07 million being withdrawn from the TRON and Ethereum networks on August 9. My analysis of on-chain data, conducted jointly with colleagues from BlockWatchdog, allows us to reconstruct the details of this operation.

Timeline and scope of the hack

The attacker acted methodically: first a test transaction of 5 USDT on the TRON network, then within an hour, 6.04 million USDT was withdrawn from eight wallets. The largest single transfer amounted to about 3.5 million USDT. In parallel, the attacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH, which were converted via the decentralized protocol 1inch into 981.1 ETH sent to a wallet created within the same hour.

Key clue — cross-chain link

The decisive evidence that both parts of the attack were a single operation was the use of the cross-chain service Bridgers. The payout contract of this protocol on Ethereum directed funds to a wallet for swaps, with the amounts and transaction times fully matching the hacker's actions. This is a classic pattern of coordinated liquidity withdrawal.

Fund movement and asset freeze

About 79% of the stolen funds (approximately $6.4 million) passed through the exchange FixedFloat, involving around 50 one-time addresses. After the analytical service Specter Investigations filed a request, the platform ChangeNOW blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, indicating possible haste or technical limitations in laundering.

Strange behavior of the Coinsbuy team

The most intriguing aspect is the platform's reaction. Within a day of the attack, the Coinsbuy team topped up the same compromised wallets with 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%. Such actions have no rational explanation unless the team is confident that there was no leak of private keys.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasize.

Initially, the damage was reported as $7.9 million, but my tally of individual transactions shows the exact amount of $8,073,992. The precise attack vector has not yet been established, and no official comments have come from Coinsbuy. This incident once again raises the question of the security of centralized platforms, especially against the backdrop of the recent series of Coldcard hardware wallet hacks, where losses exceeded $89 million.

My conclusion: topping up hacked addresses is either a gross error in risk management or a signal that the attack was internal. In any case, the industry should pay attention to the vulnerabilities of cross-chain bridges, which are becoming hackers' favorite tool for obscuring their tracks.