Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

The crypto platform Coinsbuy fell victim to a coordinated attack, resulting in attackers withdrawing $8.07 million from the TRON and Ethereum networks. The incident occurred on August 9, and my analysis of on-chain data allows me to reconstruct the full picture of what happened.
Timeline of the hack: from a test transaction to a large-scale withdrawal
The attacker acted methodically. The first step was a test transaction of 5 USDT on the TRON network — a typical technique for verifying control over a wallet. Then, within about an hour, 6.04 million USDT was withdrawn from eight addresses on the TRON blockchain, with the largest single transfer amounting to approximately 3.5 million USDT. Simultaneously, the hacker drained three wallets on Ethereum, stealing 1.89 million USDT and 77 ETH.
Of particular interest is the conversion of funds: through the decentralized aggregator 1inch, the stolen assets were exchanged for 981.1 ETH. The swap wallet was created in the same hour as the attack, indicating thorough preparation.
The cross-chain trail: how both parts of the attack were linked
Key evidence of a single operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that exactly matched the attacker's transactions in size and timing. This rules out the possibility of two independent hacks.
The subsequent movement of funds is also telling: about 79% of the stolen assets passed through the exchange FixedFloat, for which the attacker used approximately 50 one-time addresses — a classic money trail obfuscation scheme. However, not everything went smoothly: after analysts at Specter Investigations reached out, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, suggesting possible haste or technical difficulties on the hacker's part.
Strange behavior from the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, sending funds to the same 10 addresses. Seven transactions matched the stolen amounts to within 0.05%. "The money is still there. This only makes sense if the team does not believe there was a private key leak. The address is the key: no one tops up a compromised wallet with seven-figure sums twice in one night," analysts emphasize.
Initially, the damage was reported as $7.9 million, but my tally of individual transactions yields a more precise figure — $8,073,992. The exact attack vector has yet to be determined, and no official comments have been issued by Coinsbuy.
My comment: Topping up compromised wallets is an extremely unconventional step that could point to an internal insider threat or an attempt to conceal security flaws. However, if the team is genuinely confident in the safety of the keys, this could be part of a complex fund recovery operation. In any case, the incident serves as another reminder: even platforms with multi-million-dollar turnovers are not immune to targeted attacks, and the speed of response from services like ChangeNOW can be a decisive factor in minimizing losses.