Crypto news

10.08.2026
14:36

$8 Million Coinsbuy Hack: Attack on Two Blockchains and Strange Team Behavior

Coinsbuy, a cryptocurrency payment platform, has suffered a security breach resulting in losses of approximately $8 million. The attack targeted two blockchains, and the team's subsequent actions have raised questions within the community.

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a large-scale coordinated attack that simultaneously affected the TRON and Ethereum networks. The total damage amounted to $8.07 million, and my analysis of on-chain data allows me to reconstruct the details of this complex multi-step operation that occurred on August 9.

Timeline of the attack: from a test transfer to a large-scale withdrawal of funds

The attacker acted methodically. It all began with a test transaction of 5 USDT on the TRON network — a standard technique for checking the functionality of withdrawal channels. An hour later, the main wave followed: 6.04 million USDT was withdrawn from eight wallets on the TRON blockchain. The largest single transfer amounted to about 3.5 million USDT, indicating a pre-planned scheme for distributing funds.

In parallel, the hacker drained three addresses on the Ethereum network, stealing 1.89 million USDT and 77 ETH. Notably, all funds were promptly converted into 981.1 ETH through the decentralized protocol 1inch, with the swap wallet created in the same hour as the attack itself. This points to a high level of preparation.

Cross-chain link: how both parts of the attack were connected

A key element of the investigation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that exactly matched the attacker's transactions in size and time. This made it possible to assert with a high degree of confidence that we are dealing with a single operation, not two independent incidents.

Further analysis showed that about 79% of the stolen funds passed through the exchange FixedFloat using approximately 50 one-time addresses. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — the hacker is likely waiting for the right moment to launder them.

Strange behavior of the Coinsbuy team

The most intriguing aspect of this incident is the platform's own reaction. Coinsbuy has not issued official comments, but within 24 hours of the attack, the team topped up the affected wallets with 3.93 million USDT. Seven transactions matched the stolen amounts with an accuracy of 0.05%. This is an extremely unusual move.

"The money is still there. This only makes sense if the team does not believe in a leak of private keys. An address is a key: no one tops up a hacked wallet with seven-figure sums twice in one night," the researchers emphasize.

Initially, the damage was reported as $7.9 million, but my tally of individual transactions shows losses of $8,073,992. The exact attack vector has still not been established, leaving open the question of internal team competence or possible insider involvement.

My comment: Topping up hacked wallets is almost an unprecedented case. Either the team is confident that the keys were not compromised and the attack was an internal error, or this is an attempt to cover tracks. In any case, the Coinsbuy incident is another reminder that even platforms with multi-million-dollar turnovers are not immune to sophisticated cross-chain attacks. Against the backdrop of the recent theft of 1367 BTC from Coldcard owners, this case confirms a worrying trend: hackers are becoming increasingly sophisticated, and defense is becoming an ever more complex task.