Crypto news

10.08.2026
19:32

Attack on Coinsbuy: analysis of on-chain traces and the team's mysterious behavior

social network hacking

The crypto platform Coinsbuy fell victim to a coordinated attack, resulting in $8.07 million being withdrawn from the TRON and Ethereum networks on August 9. This is not just a routine hack — transaction analysis points to a carefully planned operation using cross-chain tools and convoluted money laundering schemes.

Timeline and Scale of the Hack

The attacker acted methodically. Starting with a test transfer of 5 USDT on the TRON network, he drained eight wallets within an hour, withdrawing 6.04 million USDT. The largest single transfer amounted to about 3.5 million USDT. Simultaneously, the hacker attacked three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH. Notably, all funds were converted into 981.1 ETH through the decentralized aggregator 1inch — the swap wallet was created within the same hour, indicating pre-prepared infrastructure.

Cross-Chain Connection and Laundering Routes

Key evidence of a unified operation was activity through the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions precisely in size and timing. This allowed both parts of the attack to be linked into a single chain.

About 79% of the stolen assets passed through the exchange FixedFloat, where approximately 50 one-time addresses were involved. Part of the funds was frozen: ChangeNOW blocked 150 ETH (~$288,000), and another 282 ETH (~$542,000) remain untouched across five addresses, offering hope for the recovery of some assets.

Strange Behavior by the Coinsbuy Team

The most curious part of this story is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the same affected wallets with 3.93 million USDT. Seven transactions matched the stolen amounts to within 0.05%. This is an extremely unusual move: no one in their right mind sends seven-figure sums to compromised addresses unless the team is confident that there was no private key leak.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," analysts emphasize.

The final damage amounted to $8,073,992, slightly higher than the initial estimates of $7.9 million. The exact attack vector has not yet been determined, and no official comments from Coinsbuy have been issued.

My analysis: The situation looks ambiguous. Either we are dealing with an internal error and an attempt to cover tracks, or an insider attack where the team is trying to regain control. In any case, topping up hacked addresses is a red flag that requires immediate investigation. Against the backdrop of recent thefts from Coldcard owners (over $89 million), this incident underscores that even platforms with a good reputation are not immune to complex multi-step attacks.