Crypto news

10.08.2026
17:52

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a coordinated hacker attack, resulting in the theft of $8.07 million. The incident occurred on August 9, and my colleagues at BlockWatchdog conducted a detailed analysis of on-chain data to reconstruct the events.

Timeline of the hack: from a test transaction to a large-scale withdrawal

The attacker acted methodically. It all began with a test transfer of 5 USDT on the TRON network — a typical tactic to verify control over a wallet. Within an hour, a series of transactions followed: 6.04 million USDT was withdrawn from eight addresses on the TRON blockchain. The largest single transfer amounted to an impressive ~3.5 million USDT.

Simultaneously, the hacker drained three wallets on the Ethereum network, taking 1.89 million USDT and 77 ETH. These funds were quickly converted into 981.1 ETH via the decentralized protocol 1inch — notably, the wallet used for the swaps was created within the same hour, indicating careful preparation.

The cross-chain trail: how researchers linked both attacks

The key evidence of a single operation was the use of the cross-chain service Bridgers. The analysis showed that the payout contract on Ethereum directed funds to the swap wallet in amounts that matched the attacker's transactions precisely in size and timing. This leaves no doubt that we are dealing with one coordinated campaign.

Further tracking revealed that about 79% of the stolen funds passed through the exchange FixedFloat, where the hacker used approximately 50 one-time addresses to obfuscate the trail. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — likely, the attacker is waiting for the right moment to launder them.

Strange behavior from the Coinsbuy team

The most intriguing aspect of this hack is the platform's response. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT — the very same 10 addresses that had been compromised. Seven transactions matched the stolen amounts to within 0.05%. This is an extremely unusual decision.

"The money is still there. This only makes sense if the team does not believe there was a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.

Initially, losses were reported at $7.9 million, but my analysis of individual transactions allows me to establish the exact amount of damage — $8,073,992. Notably, this incident occurs against the backdrop of a series of major thefts in the industry: on July 31, owners of Coldcard hardware wallets had 594.48 BTC (~$38.2 million) stolen, and that amount subsequently grew to 1367 BTC (~$89 million).

My expert assessment: Topping up the hacked wallets is either an act of desperation or a signal that the vulnerability was not technical in nature but rather related to internal processes. In any case, it is time for the industry to rethink its approach to key management — too often we see even major platforms neglecting basic security principles.