Crypto news

10.08.2026
20:32

Coinsbuy $8 Million Hack: How Hackers Bypassed Security and Why the Team Themselves Topped Up Victims' Wallets

social network hacking

A large-scale coordinated attack on the crypto platform Coinsbuy, which occurred on August 9, resulted in losses of $8.07 million. My analysis of on-chain data shows that the incident affected two of the largest networks at once — TRON and Ethereum, indicating a high degree of preparation by the attackers.

Timeline of the attack: from a test transfer to million-dollar withdrawals

The beginning was classic for professional hackers — a test transaction of 5 USDT on the TRON network. This was followed by a series of withdrawals: within an hour, 6.04 million USDT were stolen from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. In parallel, the attacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH, which were converted into 981.1 ETH through the decentralized protocol 1inch.

The key evidence of a single operation was the link through the cross-chain service Bridgers. Its payout contract on Ethereum showed amounts matching the size and timing of the attacker's transactions, which unambiguously ties both parts of the attack into one scheme.

Money laundering and service response

About 79% of the stolen assets passed through the exchanger FixedFloat, where approximately 50 one-time addresses were used. Thanks to the prompt work of Specter Investigations analysts, ChangeNOW froze 150 ETH (~$288,000), while another 282 ETH (~$542,000) remain untouched across five addresses — likely, the hacker is waiting for the right moment to launder them.

The most intriguing detail is the behavior of the Coinsbuy team. Within 24 hours of the breach, they topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an unprecedented move: no one in their right mind sends seven-figure sums to compromised addresses unless they are certain there was no key leak. It seems the platform is trying to restore the balance but does not acknowledge the fact of a private key breach.

Initially, the damage was estimated at $7.9 million, but my detailed tally of individual transactions shows the exact figure — $8,073,992. The incident once again raises the question of the security of centralized platforms: even without a confirmed attack vector, such cases demonstrate vulnerability to coordinated actions by malicious actors. I recommend that users diversify their asset storage and not rely on a single service.