Attack on Coinsbuy: detailed analysis of the $8 million theft in TRON and Ethereum networks

My analysis of on-chain data shows that the incident with the crypto platform Coinsbuy on August 9 was a carefully planned operation, not a random hack. The total damage amounted to $8,073,992, exceeding initial estimates of $7.9 million. The attacker acted methodically, starting with a test transfer of 5 USDT on the TRON network, after which they drained eight wallets of 6.04 million USDT within an hour. The largest single withdrawal reached approximately 3.5 million USDT.
Parallel attack on Ethereum and cross-chain trail
Simultaneously, the hacker withdrew 1.89 million USDT and 77 ETH from three addresses on Ethereum. These funds were converted through the decentralized protocol 1inch into 981.1 ETH to a wallet created within the same hour. The key clue is the use of the Bridgers cross-chain bridge: its payout contract on Ethereum transferred amounts to a swap address that matched the attacker's transactions in both timing and volume. This unequivocally links both parts of the attack into a single chain.
Particular attention is drawn to the money laundering route. About 79% of the stolen assets passed through the exchange FixedFloat, which involved approximately 50 one-time addresses. Thanks to the prompt response of the ChangeNOW service, 150 ETH (~$288,000) were frozen, and another 282 ETH (~$542,000) remain untouched across five addresses. This suggests that part of the funds can still be recovered if exchanges continue their cooperation.
Strange behavior of the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the hack, the team topped up the same 10 compromised addresses with 3.93 million USDT. Seven transactions matched the stolen amounts to within 0.05%. Such actions are illogical if private key leakage is assumed. As researchers rightly note, no one sends seven-figure sums to a hacked wallet twice in one night unless they are confident in its security. It is likely that the Coinsbuy team considers the incident an internal error or temporary glitch, rather than key compromise.
The exact attack vector has still not been established, and there are no official comments from the platform. However, this case highlights a growing trend toward sophisticated cross-chain attacks, where attackers use bridges to obscure their tracks. Against the backdrop of recent thefts of $89 million from Coldcard owners, the Coinsbuy incident demonstrates that even platforms with seemingly reliable infrastructure are vulnerable to coordinated actions.
My expert opinion: Topping up the hacked wallets is either an act of desperation or a sign that the incident has an internal nature. In any case, the market needs stricter security standards for cross-chain operations, otherwise we will see new waves of similar attacks.