Crypto news

10.08.2026
14:16

Attack on Coinsbuy: 8 million dollars evaporated in TRON and Ethereum networks

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a well-coordinated hacking operation, resulting in $8.07 million being withdrawn from its wallets on the TRON and Ethereum blockchains on August 9. My analysis of on-chain data shows that the attack was carefully planned and executed with a high degree of technical preparation.

Timeline and scale of the hack

The attacker began with a reconnaissance transaction of 5 USDT on the TRON network to test control over the wallets. Just an hour later, the main wave followed: 6.04 million USDT was withdrawn from eight addresses, with the largest single transfer amounting to about 3.5 million USDT. Simultaneously, the hacker drained three addresses on the Ethereum network, taking 1.89 million USDT and 77 ETH. These funds were instantly converted into 981.1 ETH via the decentralized protocol 1inch to a wallet created in the very same hour.

Key evidence of a unified operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent funds to a swap address in amounts that precisely matched the attacking transactions in both time and volume. This links both parts of the attack into a single chain of actions.

Traces and asset freeze

About 79% of the stolen funds passed through the exchanger FixedFloat, for which approximately 50 one-time addresses were used — a classic practice for obscuring traces. However, some assets were frozen: the service ChangeNOW blocked 150 ETH (~$288,000), and another 282 ETH (~$542,000) remain untouched across five addresses, likely awaiting withdrawal.

The most intriguing aspect is the behavior of the Coinsbuy team itself. Within a day of the attack, the platform replenished the same compromised wallets with 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%. This is an extremely unusual move.

"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one replenishes a hacked wallet with seven-figure sums twice in one night," researchers emphasize.

Initial damage estimates stood at $7.9 million, but upon detailed calculation of individual transactions, the final amount reached $8,073,992. The exact attack vector has not yet been established, and no official comments from Coinsbuy have been issued.

For context: this is not the first major theft this season. Recall that on July 31, owners of Coldcard hardware wallets became victims — 594.48 BTC (~$38.2 million) was stolen from them, and this amount subsequently grew to 1367 BTC (~$89 million).

My comment: Replenishing hacked addresses after an attack is either a sign of an internal incident or an extremely risky attempt to restore liquidity. In any case, this case highlights the importance of multi-layered security and rapid response to suspicious activity. The market should monitor further movements on these addresses more closely.