Attack on Coinsbuy: how hackers withdrew $8 million and why the team topped up the hacked wallets

The crypto platform Coinsbuy fell victim to a large-scale coordinated attack, during which attackers siphoned off over $8 million from the TRON and Ethereum networks. The incident occurred on August 9, and my analysis of on-chain data allows me to reconstruct the timeline of the hack down to the minute.
The attack began with a test transaction of 5 USDT on the TRON network — a classic technique to verify control over a wallet. Within an hour, 6.04 million USDT was withdrawn from eight addresses, with the largest single transfer amounting to about 3.5 million USDT. Simultaneously, the hacker drained three wallets on Ethereum, taking 1.89 million USDT and 77 ETH, which were instantly converted into 981.1 ETH via the decentralized protocol 1inch.
The connecting link — a cross-chain bridge
The key evidence of a single operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to a swap wallet that matched the attacker's transactions in size and timing. This indicates that the perpetrator acted through a unified liquidity pool rather than in a fragmented manner.
The money laundering was also professionally organized. About 79% of the stolen assets passed through the exchanger FixedFloat using approximately 50 one-time addresses. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — likely, the hacker is waiting for attention to wane.
Strange behavior by the Coinsbuy team
The most intriguing detail is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the same compromised wallets with 3.93 million USDT. Seven transactions matched the stolen amounts to within 0.05%. This is an unprecedented case: no one sends seven-figure sums to a hacked address twice in one night.
"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the researchers emphasize.
Initial damage estimates stood at $7.9 million, but my tally of individual transactions shows an exact figure of $8,073,992. The Coinsbuy incident occurs against the backdrop of a series of major hacks: I recall that at the end of July, 594.48 BTC (~$38.2 million) was stolen from Coldcard hardware wallet owners, and after subsequent waves of attacks, the total damage rose to 1367 BTC (~$89 million).
My conclusion: topping up hacked wallets is a rare signal. Either the Coinsbuy team is genuinely confident that there is no key compromise and is testing recovery mechanisms, or this is a desperate attempt to create an appearance of control. In any case, investors should be wary: if the platform does not disclose the attack vector, trust in it should be reconsidered.