Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum — detailed analysis

The cryptocurrency platform Coinsbuy faced a large-scale coordinated attack on August 9, resulting in a loss of $8.07 million. My analysis of on-chain data, conducted jointly with blockchain researchers, allows us to reconstruct the full picture of this incident, which affected two of the largest networks — TRON and Ethereum.
Timeline and attack mechanism
The attacker acted methodically and deliberately. It all started with a test transaction of 5 USDT on the TRON network, indicating a preliminary check of control over the wallets. Then, within about an hour, 6.04 million USDT was withdrawn from eight addresses. The largest single transfer amounted to about 3.5 million USDT — this suggests that the attacker had access to several hot wallets of the platform.
In parallel, the hacker drained three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH. Notably, the funds were promptly converted into 981.1 ETH through the decentralized aggregator 1inch, with the swap wallet created in the same hour as the attack itself. This demonstrates a high level of preparation and automation.
The key evidence linking both parts of the attack was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions precisely in size and time. This leaves no doubt: we are dealing with a single operation, not scattered incidents.
Movement of stolen funds
About 79% of the stolen assets passed through the exchanger FixedFloat, for which the attacker used approximately 50 one-time addresses. This is a typical practice for obscuring traces. However, some of the funds were frozen: the service ChangeNOW, after a request from Specter Investigations analysts, blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate haste or technical difficulties on the hacker's part.
Strange behavior of the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely illogical action, unless the team is confident there is no leak of private keys. The money is still on these addresses, which confirms my hypothesis: the administration likely suspects an internal error or compromise at the API level, rather than a complete loss of control over the keys.
"An address is a key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts rightly noted, and I fully share this position.
Initially, the damage amount was cited as $7.9 million, but my detailed tally of individual transactions allowed me to refine the losses to $8,073,992.
My expert conclusion: this incident highlights a systemic security problem in centralized crypto services. Even without a confirmed key leak, attacks of the Coinsbuy level demonstrate infrastructure vulnerability. In light of recent thefts from Coldcard owners (1367 BTC at ~$89 million), we are witnessing a worrying trend: hackers are increasingly combining cross-chain tools and DeFi protocols for instant money laundering. Investors should reconsider their asset storage strategies, favoring hardware wallets with isolated keys.