Crypto news

10.08.2026
15:32

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million. The incident occurred on August 9 and affected two of the largest networks simultaneously — TRON and Ethereum. My analysis of on-chain data allows me to reconstruct the full picture of what happened.

Timeline of the hack: from a test transaction to mass withdrawals

The attacker acted methodically and professionally. The first step was a test transaction of 5 USDT on the TRON network — a classic technique for checking the functionality of withdrawal channels. Just an hour later, the main wave followed: 6.04 million USDT was withdrawn from eight wallets. The largest single transfer amounted to about 3.5 million USDT, indicating the high throughput of the infrastructure used.

In parallel, the hacker drained three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH. The funds were quickly converted into 981.1 ETH via the decentralized protocol 1inch. Notably, the wallet for the swaps was created literally within the same hour — this points to a pre-prepared scenario.

Key clue: the Bridgers cross-chain bridge

The most interesting detail is the connection between both parts of the attack through the Bridgers service. The payout contract of this cross-chain bridge on Ethereum sent amounts to the swap wallet that matched the attacker's transactions exactly in size and time. This leaves no doubt: we are dealing with a single operation, not two independent hacks.

Movement of funds and asset freeze

About 79% of the stolen funds passed through the exchanger FixedFloat, for which the attacker used approximately 50 one-time addresses — a typical practice to hinder tracking. Thanks to the prompt appeal from Specter Investigations, the ChangeNOW service froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate an attempt to wait out the time before further actions.

Strange behavior of the Coinsbuy team

The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is extremely unusual behavior. As researchers rightly note, no one tops up a hacked wallet with seven-figure sums twice in one night unless they are confident in the safety of the private keys.

The exact attack vector has still not been established, and no official comments have come from Coinsbuy. Initially, damages were reported at $7.9 million, but my detailed tally of individual transactions shows losses of $8,073,992.

My verdict: this incident raises serious questions about Coinsbuy's internal security. The behavior of the team, replenishing funds after the hack, hints at a possible insider attack or, more likely, compromised keys followed by an attempt to cover tracks. In the context of recent attacks on Coldcard hardware wallets (losses reached $89 million), it becomes obvious: even platforms with a reputation for reliability are not immune to systemic vulnerabilities. Investors should reconsider their fund storage strategies and strengthen monitoring of on-chain activity.