Attack on Coinsbuy: how hackers withdrew $8 million from TRON and Ethereum networks

My analysis of on-chain data revealed details of a coordinated attack on the crypto platform Coinsbuy, which resulted in the theft of $8.07 million across the TRON and Ethereum networks on August 9. This is not a series of random incidents, but a carefully planned operation combining multiple blockchains and services.
Timeline and mechanics of the hack
The attacker began with a test transfer of 5 USDT on the TRON network to verify control over the wallets. Within an hour, 6.04 million USDT was withdrawn from eight addresses, with the largest transaction amounting to approximately 3.5 million USDT. Simultaneously, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. The funds were converted into 981.1 ETH through the decentralized aggregator 1inch, with the swap wallet created within the same hour.
A key element linking both parts of the attack was the use of the cross-chain service Bridgers. Its payout contract on Ethereum directed funds to the swap wallet, with amounts and transaction times perfectly matching the attacker's actions. This unequivocally points to a single operation rather than disparate incidents.
Money laundering and fund freezing
Approximately 79% of the stolen assets passed through the exchanger FixedFloat, which used around 50 one-time addresses. After analysts at Specter Investigations reached out, the service ChangeNOW froze 150 ETH (~$288,000 at the time of publication). Another 282 ETH (~$542,000) remain untouched across five addresses, suggesting possible haste or technical difficulties on the hacker's part.
Strange behavior by the Coinsbuy team
The exact attack vector has yet to be determined, and Coinsbuy has not provided official comments. However, what caught my attention is that within 24 hours, the platform's team replenished the affected wallets—3.93 million USDT was deposited to the same 10 addresses. Seven transactions matched the stolen amounts to within 0.05%.
"The money is still there. This only makes sense if the team does not believe there was a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.
Initial reports cited a damage figure of $7.9 million, but my tally of individual transactions shows losses of $8,073,992.
This incident echoes the large-scale thefts from Coldcard owners, when 594.48 BTC (~$38.2 million) was stolen on July 31, with the amount later rising to 1367 BTC (~$89 million).
My conclusion: Topping up hacked addresses is either a gross mistake or a signal that Coinsbuy knows more than it is letting on. In any case, this case underscores the critical importance of key rotation and real-time monitoring of suspicious activity. Without this, even major platforms remain vulnerable.