Attack on Coinsbuy: $8 million disappeared in an hour — detailed analysis

The cryptocurrency platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million on August 9. My analysis of on-chain data shows that the incident affected two of the largest networks simultaneously — TRON and Ethereum, indicating a high level of preparation on the part of the attackers.
Timeline of the hack
The attack began with a test transaction of 5 USDT on the TRON network — a classic sign of checking control over a wallet. Within an hour, the attacker withdrew 6.04 million USDT from eight addresses, with the largest single transfer amounting to about 3.5 million USDT. In parallel, the hacker drained three wallets on Ethereum, stealing 1.89 million USDT and 77 ETH, which were converted into 981.1 ETH through the decentralized protocol 1inch.
The key evidence of a single operation was the use of the cross-chain service Bridgers. My analysis shows that the payout contract on Ethereum directed funds to an address for swaps, with the amounts and timing of transactions fully matching the attacker's actions on the TRON network. This rules out the possibility of two independent hacks.
Movement of stolen funds
About 79% of the stolen assets passed through the exchanger FixedFloat, where approximately 50 one-time addresses were used — a typical scheme for obfuscating traces. After analysts at Specter Investigations reached out, the service ChangeNOW froze 150 ETH (approximately $288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate haste on the part of the criminal or technical difficulties in moving the funds.
Strange behavior by the team
The most intriguing aspect of this incident is Coinsbuy's reaction. Within 24 hours of the attack, the platform's team topped up the same compromised wallets with 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%. This illogical decision suggests that the team does not believe there was a leak of private keys. An address is a key: no one in their right mind would top up a hacked wallet with seven-figure sums twice in one night, unless they know that control over it has not been lost.
Initially, losses were reported at $7.9 million, but my tally of individual transactions shows the exact amount of damage — $8,073,992. This discrepancy is typical for incidents where part of the assets may be locked or in the process of conversion.
My comment: This incident raises serious questions about Coinsbuy's internal security. The fact that the team continues to use compromised addresses points either to an insider attack or to a failure to understand fundamental security principles. Given the growing activity of hackers, who have stolen more than $89 million from Coldcard owners in recent weeks alone, crypto platforms critically need to review their key management protocols and implement a multi-layered system for monitoring suspicious activity.