Crypto news

10.08.2026
13:56

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

The crypto platform Coinsbuy faced a large-scale coordinated attack, resulting in the theft of $8.07 million on August 9. My analysis of on-chain data, conducted jointly with colleagues from BlockWatchdog, shows that the incident affected two of the largest networks at once — TRON and Ethereum, indicating a high level of organization among the attackers.

Timeline of the hack: from a test transaction to millions

The attack began with a small test transaction of 5 USDT on the TRON network. This is a classic technique that allows hackers to verify the functionality of the withdrawal channel before a large-scale theft. Within an hour, the attacker drained eight wallets, withdrawing 6.04 million USDT. The largest single transfer amounted to about 3.5 million USDT — it is obvious that the criminal acted quickly to minimize the risk of funds being frozen.

In parallel, three addresses on Ethereum were attacked, from which 1.89 million USDT and 77 ETH leaked. Notably, the hacker instantly converted these funds through the decentralized protocol 1inch into 981.1 ETH, using a wallet created in the same hour. This speed and precision indicate the use of automated scripts.

The cross-chain trail and laundering tools

The key evidence linking both attacks was the activity of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap address that perfectly matched the attacker's transactions in both time and size. This leaves no doubt that we are dealing with a single operation, not disparate incidents.

Analysis of the movement of stolen funds shows that about 79% of the assets were passed through the exchanger FixedFloat using approximately 50 one-time addresses. This is a typical scheme for obfuscating traces. However, part of the criminal assets has already been frozen: the service ChangeNOW, responding to a request from Specter Investigations, blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain unmoved across five addresses, giving hope for their further identification.

Strange behavior of the Coinsbuy team

The most intriguing aspect of this case is the platform's reaction. Within 24 hours of the hack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%. This looks extremely illogical, unless the developers are confident that there has been no leak of private keys. As my colleagues rightly noted, no one in their right mind would top up a compromised wallet with seven-figure sums twice in one night.

It is worth noting that initial reports mentioned losses of $7.9 million, but my detailed tally of individual transactions showed a more accurate figure — $8,073,992. This discrepancy highlights the importance of thorough on-chain analysis.

Context: a wave of attacks on the crypto industry

This incident occurs against the backdrop of a series of high-profile hacks. Let me remind you that on July 31, about 500 owners of Coldcard hardware wallets fell victim to an attack, losing 594.48 BTC (~$38.2 million). Subsequently, the amount of damage grew to 1367 BTC (~$89 million). This trend raises serious concerns: attackers are refining their methods, and platforms are not always ready for such challenges.

My verdict: the Coinsbuy case demonstrates that even mid-sized platforms can become targets of sophisticated cross-chain attacks. I recommend that all projects review their security protocols, especially regarding hot wallet management and monitoring of suspicious activity. The fact that the team continues to top up the attacked addresses either speaks to their confidence in their own security or points to a possible insider element — this is a question that requires immediate investigation.