Attack on Coinsbuy: $8 million stolen in a coordinated operation across TRON and Ethereum networks

The crypto platform Coinsbuy fell victim to a meticulously planned hacker attack, resulting in the withdrawal of $8.07 million from the TRON and Ethereum networks on August 9. My analysis of on-chain data allows me to reconstruct the timeline of the incident and identify key patterns indicating the attackers' professionalism.
Timeline of the hack: from a test transaction to a mass withdrawal of funds
The attack began with a small test transaction of 5 USDT on the TRON network — a typical step to verify control over a wallet. Within an hour, 6.04 million USDT were withdrawn from eight addresses, with the largest single transfer amounting to about 3.5 million USDT. Simultaneously, the hacker drained three wallets on the Ethereum network, stealing 1.89 million USDT and 77 ETH, which were instantly converted into 981.1 ETH via the decentralized protocol 1inch.
The key evidence of a unified operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum directed funds to an address for swaps, with amounts and timing exactly matching the attacker's transactions. This rules out the possibility of a coincidence and confirms the coordinated nature of the actions.
Money laundering and asset freezing
About 79% of the stolen funds were routed through the exchanger FixedFloat, for which the attacker used approximately 50 one-time addresses. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — likely, the hacker is waiting for the right moment to launder them.
Strange behavior of the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This looks extremely illogical: no one sends seven-figure sums to compromised addresses if they suspect a leak of private keys. Clearly, the team is either confident that there was no key compromise, or is trying to conceal internal issues.
The initial damage estimates of $7.9 million turned out to be understated — my tally of individual transactions shows losses of $8,073,992. The exact attack vector has not yet been established, and Coinsbuy is refraining from official comments.
My verdict: This incident demonstrates the growing sophistication of hacker groups using cross-chain infrastructure to obscure their tracks. However, the strange actions of the Coinsbuy team raise more questions than answers — perhaps we are dealing not with an external attack, but with an insider operation disguised as a hack.