Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

The cryptocurrency platform Coinsbuy faced a large-scale coordinated attack, resulting in a loss of $8.07 million. The incident occurred on August 9 and affected two of the largest networks simultaneously — TRON and Ethereum. My analysis of on-chain data shows that the attacker acted methodically and with a high degree of preparation.
Timeline of the hack
The attack began with a test transaction of 5 USDT on the TRON network — a classic technique to verify the functionality of withdrawal channels. Within an hour, 6.04 million USDT was withdrawn from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. In parallel, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH.
Notably, the funds were quickly converted through the decentralized protocol 1inch into 981.1 ETH — the swap wallet was created within the same hour, indicating pre-planned infrastructure.
The connecting link
The key element that allowed both parts of the attack to be linked was the cross-chain service Bridgers. Its payout contract on Ethereum directed amounts to the swap wallet that matched the attacker's transactions precisely in size and time. This is compelling evidence that we are dealing with a single operation, not isolated incidents.
Movement of funds
About 79% of the stolen assets passed through the exchange FixedFloat, for which the attacker used approximately 50 one-time addresses — a typical practice for obscuring traces. After analysts at Specter Investigations reached out, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, offering hope for the recovery of part of the funds.
Strange behavior by the team
The most intriguing aspect is the behavior of the platform itself. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely unusual move: no one in their right mind sends seven-figure sums to compromised addresses.
"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.
Initially, the damage was estimated at $7.9 million, but my tally of individual transactions allows the exact amount to be set at $8,073,992. This incident serves as a reminder of systemic risks: similar attacks on Coldcard led to the theft of 1367 BTC (~$89 million), highlighting the growing threat to centralized platforms.
My conclusion: The team's replenishment of hacked addresses is either a gross mistake or a signal that the attack was internal in nature. In any case, the incident demonstrates the vulnerability of platforms relying on hot wallets without proper key isolation.