Attack on Coinsbuy: $8 million stolen in a coordinated operation across TRON and Ethereum networks

The cryptocurrency platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million on August 9. My analysis of on-chain data, conducted jointly with blockchain researchers from BlockWatchdog, revealed a complex scheme that affected two of the largest networks at once — TRON and Ethereum.
Timeline of the attack: from a test transfer to a mass withdrawal of funds
The attacker acted methodically. The attack began with a small test transaction of 5 USDT on the TRON network — a classic technique for checking the functionality of channels. Within an hour, a coordinated withdrawal of funds followed: 6.04 million USDT was taken from eight wallets on the TRON blockchain. The largest single transfer amounted to about 3.5 million USDT.
In parallel, the hacker drained three addresses on the Ethereum network, stealing 1.89 million USDT and 77 ETH. Notably, all funds were promptly converted into 981.1 ETH through the decentralized protocol 1inch, with the swap wallet created literally within the same hour.
Key clue: the Bridgers cross-chain bridge
Analysis of on-chain data allowed me to link both parts of the attack into a single operation. The cross-chain service Bridgers played a decisive role: its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions precisely in size and time. This unequivocally indicates that we are dealing with a single attacker, not multiple independent incidents.
Movement of funds: FixedFloat, ChangeNOW, and frozen assets
About 79% of the stolen funds passed through the exchange FixedFloat, for which approximately 50 one-time addresses were used — a typical practice for obscuring traces. However, some of the assets were frozen: the ChangeNOW service, after a request from Specter Investigations, blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, offering hope for their recovery.
Strange behavior from the Coinsbuy team
The most intriguing aspect is the platform's reaction. No official comments followed, but my observations of on-chain activity revealed something unusual: within 24 hours, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with the funds arriving at the same 10 addresses. Seven transactions matched the stolen amounts to within 0.05%.
"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.
Initially, the damage was reported at $7.9 million, but my detailed tally of individual transactions allowed me to refine the losses to $8,073,992.
This incident occurs against the backdrop of a series of major thefts: on July 31, about 500 owners of Coldcard hardware wallets lost 594.48 BTC (~$38.2 million), and as a result of subsequent waves of attacks, the total damage rose to 1367 BTC (~$89 million).
My expert opinion: The replenishment of hacked wallets by the Coinsbuy team is an extremely unconventional move that may indicate the insider nature of the attack or an attempt to cover up traces of an internal error. In any case, this case highlights the critical importance of private key hygiene and the need for multi-layered protection even for professional platforms.