Crypto news

10.08.2026
15:47

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

On August 9, the crypto platform Coinsbuy fell victim to a sophisticated coordinated attack, resulting in the theft of assets totaling $8.07 million. My analysis of on-chain data, conducted together with colleagues from BlockWatchdog, allows us to reconstruct the full picture of this incident.

Timeline of the hack: from a test transaction to a large-scale withdrawal

The attack began with a small test transaction of 5 USDT on the TRON network. This is a classic technique used by hackers to verify the functionality of their scripts and the security of withdrawal channels. After confirming success, the attacker withdrew 6.04 million USDT from eight wallets within an hour. The largest single transfer amounted to approximately 3.5 million USDT.

Simultaneously, an attack was carried out on three addresses on the Ethereum network, from which 1.89 million USDT and 77 ETH leaked. Notably, all stolen funds were promptly converted into 981.1 ETH via the decentralized protocol 1inch. The swap wallet was created within the same hour, indicating thorough preparation.

The cross-chain trail: how both parts of the attack were linked

A key moment in the investigation was the hacker's use of the cross-chain service Bridgers. Analysis of the payout contract on Ethereum showed that the amounts sent to the swap wallet matched the attacker's transactions on the TRON network in both size and time. This leaves no doubt that both parts of the operation were part of a single coordinated plan.

The subsequent movement of funds was also well thought out. Approximately 79% of the stolen assets passed through the exchanger FixedFloat, for which the attacker used about 50 one-time addresses. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate that the hacker did not manage to complete the full laundering cycle.

Strange behavior of the Coinsbuy team

The most intriguing aspect of this incident is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team replenished the affected wallets with a total of 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%. This is highly unusual behavior for a hack victim.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a compromised wallet with seven-figure sums twice in one night," — this is a key observation that casts doubt on the version of a simple key compromise.

Initially, the damage was reported as $7.9 million, but my detailed tally of individual transactions established the exact loss amount at $8,073,992. Notably, this incident occurs against the backdrop of a series of major thefts in the industry: recall that on July 31, 594.48 BTC (~$38.2 million) was stolen from owners of Coldcard hardware wallets, and as a result of subsequent waves of attacks, the total damage grew to 1367 BTC (~$89 million).

My verdict: this case demonstrates a worrying trend toward using cross-chain infrastructure to obscure tracks. The fact that the Coinsbuy team continues to replenish compromised addresses points to a possible insider nature of the attack or the presence of a vulnerability that the platform prefers to keep quiet about. Investors should exercise increased caution when working with platforms that do not disclose details of security incidents.