Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

On August 9, the crypto platform Coinsbuy fell victim to a coordinated hacker attack affecting the TRON and Ethereum networks. During the incident, attackers managed to withdraw assets worth $8.07 million, and my analysis of on-chain data confirms: this was not a random theft, but a carefully planned operation.
Timeline of the hack: from a test transaction to a large-scale withdrawal
The attacker started small—with a test transfer of 5 USDT on the TRON network. However, within an hour, 6.04 million USDT was withdrawn from eight wallets. The largest single transfer amounted to about 3.5 million USDT, indicating the absence of security triggers or automatic limits on the platform.
Simultaneously, the hacker drained three addresses on the Ethereum network, stealing 1.89 million USDT and 77 ETH. These funds were converted into 981.1 ETH through the decentralized protocol 1inch, with the swap wallet created in the same hour as the attack. Such efficiency points to a high level of preparation.
A key element linking both parts of the attack was the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that precisely matched the attacker's transactions in size and timing. This leaves no doubt that we are dealing with a single operation, not two independent incidents.
Traces lead to exchanges
About 79% of the stolen funds passed through the exchange FixedFloat, for which the attacker used approximately 50 one-time addresses. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000 at the time of publication). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate the hacker is trying to wait it out.
Notably, the exact attack vector has still not been established, and Coinsbuy refrains from official comments. However, my analysis reveals a strange detail: within 24 hours of the hack, the platform's team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%.
"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.
Initial damage estimates were $7.9 million, but a careful tally of individual transactions allowed the exact loss amount to be determined—$8,073,992.
This incident serves as a reminder of a larger problem: on July 31, owners of Coldcard hardware wallets fell victim to an attack, losing 594.48 BTC (~$38.2 million), and the damage later grew to 1367 BTC (~$89 million). Such a series of hacks underscores the vulnerability of even those platforms considered reliable.
My comment: The strange behavior of the Coinsbuy team, topping up hacked wallets, raises more questions than answers. Either this is an attempt to conceal internal negligence, or a signal that the attack was carried out through a vulnerability in a third-party service rather than key compromise. In any case, this incident is yet another reminder that even after an incident, platforms must act transparently, otherwise user trust will be completely undermined.