Crypto news

10.08.2026
15:17

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum — a detailed analysis

social network hacking

The crypto platform Coinsbuy fell victim to a well-coordinated attack, resulting in the theft of $8.07 million on August 9. The incident affected two of the largest networks simultaneously—TRON and Ethereum—indicating a high level of preparedness on the part of the attackers. My analysis of on-chain data allows me to reconstruct the full picture of what happened.

Timeline and scale of the hack

The attack began with a test transfer of 5 USDT on the TRON network—a typical technique for verifying control over a wallet. Within an hour, the hacker orchestrated the withdrawal of 6.04 million USDT from eight addresses, with the largest single transaction amounting to approximately 3.5 million USDT. In parallel, the attacker drained three wallets on the Ethereum network, taking 1.89 million USDT and 77 ETH. These funds were promptly converted into 981.1 ETH via the decentralized protocol 1inch—the swap wallet was created within the same hour, pointing to pre-planned infrastructure.

Connection between networks and fund routing

A key element linking both parts of the attack was the cross-chain service Bridgers. Its payout contract on Ethereum directed amounts to the swap wallet that matched the attacker's transactions precisely in size and timing. This leaves no doubt: we are dealing with a single operation, not two independent incidents.

The subsequent movement of funds demonstrates an attempt to obfuscate the trail. Approximately 79% of the stolen assets passed through the exchanger FixedFloat, for which around 50 one-time addresses were used. Some funds were successfully frozen: the service ChangeNOW, after a request from Specter Investigations, blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate haste or technical difficulties on the part of the attackers.

Strange behavior by the Coinsbuy team

The most intriguing aspect is the platform's response. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT—the same 10 addresses that had been compromised. Seven of these transactions matched the stolen amounts to within 0.05%. This is an extremely illogical action, unless the team is confident that the private keys were not compromised.

"The funds are still there. This only makes sense if the team does not believe in a private key leak. An address is a key: no one tops up a hacked wallet with seven-figure sums twice in one night."

Damage assessment and context

Initial damage estimates stood at $7.9 million, but my detailed tally of individual transactions allows me to determine the exact amount of $8,073,992. The attack vector has yet to be established, and Coinsbuy is refraining from official comments. This incident fits into a troubling trend: recall that on July 31, around 500 owners of Coldcard hardware wallets fell victim to a hack, losing 594.48 BTC (~$38.2 million), with the damage subsequently rising to 1367 BTC (~$89 million).

My conclusion: the attack on Coinsbuy demonstrates the growing sophistication of cybercriminal schemes in the crypto industry. The use of cross-chain bridges and numerous one-time addresses is no longer just a hack, but a professional operation with elements of financial intelligence. The fact that the team is replenishing hacked wallets raises questions about a possible insider nature of the incident or incompetence on the part of the security team. In any case, this is a serious signal for the entire industry about the need to revise fund storage security protocols.