Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

The cryptocurrency platform Coinsbuy faced a large-scale coordinated attack, resulting in a loss of $8.07 million. The incident occurred on August 9 and affected two of the largest networks simultaneously — TRON and Ethereum. My analysis of on-chain data allows me to reconstruct the timeline of the attacker's actions and identify key details of this operation.
Attack Timeline: From a Test Transaction to a Large-Scale Withdrawal
The attacker began with reconnaissance — executing a test transaction of 5 USDT on the TRON network. Then, within about an hour, 6.04 million USDT was withdrawn from eight wallets. The largest operation amounted to approximately 3.5 million USDT. In parallel, the hacker drained three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH.
Notably, the funds were quickly converted: through the decentralized protocol 1inch, the attacker exchanged the stolen assets for 981.1 ETH, using a wallet created within the same hour. This indicates a high level of preparation and process automation.
Connection Between Networks and Fund Movement
The key element that allowed linking both parts of the attack was the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions in size and timing. This is compelling evidence that we are dealing with a single coordinated operation, not two separate incidents.
About 79% of the stolen funds passed through the exchange FixedFloat, for which approximately 50 one-time addresses were used. Thanks to the prompt response of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, offering hope for their recovery.
Strange Behavior of the Coinsbuy Team
The most intriguing aspect is the platform's reaction. Within a day of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. Such behavior is highly uncharacteristic for hack victims.
"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.
Initially, the damage was estimated at $7.9 million, but my detailed tally of individual transactions shows losses of $8,073,992. The Coinsbuy incident is just part of a worrying trend: recall that at the end of July, owners of Coldcard hardware wallets had 594.48 BTC (~$38.2 million) stolen, an amount that subsequently grew to 1367 BTC (~$89 million).
My comment: The situation with Coinsbuy raises more questions than answers. Voluntarily topping up hacked addresses is either an act of desperation to preserve reputation or a sign that the incident may be internal. In any case, this case underscores the critical importance of private key security and the need for thorough due diligence of counterparties in the DeFi ecosystem.