Attack on Coinsbuy: detailed analysis of the $8 million theft in TRON and Ethereum networks

The cryptocurrency platform Coinsbuy faced a large-scale coordinated attack, resulting in the theft of $8.07 million on August 9. My analysis of on-chain data, conducted together with colleagues from BlockWatchdog, revealed a complex scheme that affected two blockchains at once — TRON and Ethereum.
Timeline and attack mechanism
The attacker acted methodically. It all started with a test transaction of 5 USDT on the TRON network — a classic technique for checking the channel's functionality. Just an hour later, the main wave followed: 6.04 million USDT was withdrawn from eight wallets. The largest single transfer amounted to about 3.5 million USDT, indicating a high level of preparation and access to significant liquidity volumes.
In parallel, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. Notably, the funds were converted into 981.1 ETH through the decentralized protocol 1inch, with the swap wallet created within the same hour. This points to pre-planned infrastructure.
Key clue — cross-chain bridge
The connecting link between the attacks on the two networks was the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions exactly in size and time. This leaves no doubt: both parts of the operation are links in the same chain.
Further analysis showed that about 79% of the stolen funds passed through the exchanger FixedFloat, for which approximately 50 one-time addresses were used. Part of the assets was frozen: ChangeNOW, after an appeal from Specter Investigations, blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — the attacker is likely waiting it out or facing difficulties with liquidation.
Strange behavior from the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, 3.93 million USDT was credited to the affected wallets. Seven transactions matched the stolen amounts to within 0.05%. This is an extremely unusual move: no one in their right mind tops up a compromised address with seven-figure sums.
"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.
Initially, the damage figure cited was $7.9 million, but my tally of individual transactions showed a more accurate number — $8,073,992.
Context and conclusions
This attack is just one episode in a series of high-profile incidents. Recall that on July 31, about 500 owners of Coldcard hardware wallets became victims, with 594.48 BTC (~$38.2 million) stolen. Subsequent waves of attacks increased the damage to 1367 BTC (~$89 million).
My expert opinion: The replenishment of hacked wallets by the Coinsbuy team is either a gross mistake or a signal that the incident is not merely a key theft, but an internal operation. In any case, this case underscores the critical importance of private key hygiene and the need to use multi-signature solutions for storing large sums. The market needs stricter security standards, otherwise we will continue to see such losses.