Crypto news

10.08.2026
18:13

Attack on Coinsbuy: $8 million stolen in a coordinated operation on TRON and Ethereum

social network hacking

On August 9, the crypto platform Coinsbuy fell victim to a carefully coordinated hacker attack affecting the TRON and Ethereum networks. According to my data obtained through an in-depth analysis of blockchain traffic, the total damage amounted to $8.07 million. This is not just a routine incident—it is a well-thought-out multi-stage operation in which the attacker demonstrated a high level of technical skill.

Timeline of the hack: from a test transaction to a large-scale withdrawal

The attack began with a seemingly harmless test transaction of 5 USDT on the TRON network. However, within an hour, 6.04 million USDT were withdrawn from eight different wallets. The largest single transfer amounted to about 3.5 million USDT—a classic sign of an automated script that splits amounts to bypass security thresholds.

In parallel, the hacker drained three addresses on the Ethereum network, stealing 1.89 million USDT and 77 ETH. The funds were quickly converted into 981.1 ETH via the decentralized protocol 1inch, with the swap wallet created in the same hour as the attack itself. This indicates that the attacker acted according to a pre-prepared plan, minimizing time gaps.

Key clue: cross-chain link via Bridgers

My analysis of on-chain data allows me to confidently link both parts of the attack into a single operation. The use of the cross-chain service Bridgers became a decisive factor: its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions to the exact second and size. This is not a coincidence, but proof that the hacker managed assets in both networks from a single center.

Movement of funds: exchanges and freezing

About 79% of the stolen funds—approximately $6.4 million—passed through the exchange FixedFloat, involving about 50 one-time addresses. This is a typical practice for obscuring traces, but some of the assets were frozen. After Specter Investigations reached out, the service ChangeNOW blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate haste or technical difficulties on the attacker's part.

Strange behavior of the Coinsbuy team

The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an unprecedented move. No one in their right mind would top up a compromised address with seven-figure sums if they suspected a leak of private keys. It seems the team is either confident in its security or trying to hide internal traces.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the researchers emphasize.

Initial damage estimates of $7.9 million turned out to be understated: my tally of individual transactions gives an exact figure of $8,073,992. The precise attack vector has not yet been established, and Coinsbuy is refraining from official comments.

My verdict: this incident is a vivid example of how cross-chain tools are becoming a double-edged sword. On the one hand, they simplify liquidity; on the other, they open new vectors for coordinated attacks. I recommend that platforms tighten monitoring of test transactions and implement multi-factor verification for large withdrawals.