Crypto news

10.08.2026
19:12

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million. The incident occurred on August 9 and affected two of the largest networks at once — TRON and Ethereum. My analysis of on-chain data allows me to reconstruct the full picture of what happened.

Timeline of the attack: from a test transfer to a massive withdrawal

The attacker acted methodically. It all started with a test transaction of 5 USDT on the TRON network — a typical technique for checking that the channel works. An hour later, the main wave followed: 6.04 million USDT was withdrawn from eight wallets. The largest single transfer amounted to about 3.5 million USDT.

In parallel, the hacker emptied three addresses on the Ethereum network, taking 1.89 million USDT and 77 ETH. These funds were quickly converted into 981.1 ETH via the decentralized protocol 1inch. Notably, the wallet for the swaps was created within the same hour — the attacker was clearly operating according to a pre-prepared plan.

Key clue: the cross-chain trail

It was possible to link both parts of the attack together thanks to the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions exactly in size and time. This conclusively proves that we are dealing with a single operation, not two independent hacks.

The subsequent movement of funds is also telling: about 79% of the stolen assets passed through the exchanger FixedFloat using approximately 50 one-time addresses. This is a standard practice for obscuring traces. However, part of the funds was frozen — the service ChangeNOW, after a request from Specter Investigations analysts, blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses.

Strange behavior of the Coinsbuy team

The most intriguing aspect of this case is the platform's own reaction. Coinsbuy has not made any official statements, but within 24 hours of the hack, the team topped up the affected wallets with 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%.

"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.

Initially, losses were reported at $7.9 million, but my tally of the individual transactions shows a more accurate figure — $8,073,992. This incident echoes the recent series of attacks on Coldcard hardware wallet owners, where the total damage reached $89 million.

My expert assessment: Topping up hacked addresses after an attack is an extremely unconventional move. This could indicate that Coinsbuy suspects an insider rather than an external hacker. In that case, the team is trying to lure the attacker out, using the wallets as bait. However, such a strategy is extremely risky — if the keys are truly compromised, that $3.93 million could become the next victim.