Crypto news

10.08.2026
21:52

Coinsbuy Hack of $8 Million: Details of Coordinated Attack on TRON and Ethereum Revealed

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a large-scale hacking operation, resulting in the theft of assets totaling $8.07 million on August 9. My analysis of on-chain data, conducted jointly with blockchain researchers from BlockWatchdog, shows that the attack was carefully coordinated and affected two of the largest networks simultaneously — TRON and Ethereum.

The attacker acted methodically. The first step was a test transaction of 5 USDT on the TRON network — a classic technique to check the functionality of withdrawal channels. Within an hour, 6.04 million USDT was withdrawn from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. In parallel, the hacker drained three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH.

Cross-chain trail: how both attack vectors were linked

A key element of the investigation was the use of the cross-chain service Bridgers. The payout contract of this protocol on Ethereum sent funds to a swap wallet that matched the attacker's transactions in both size and timing. This made it possible to assert with a high degree of confidence that both parts of the attack were a single operation, not the actions of different groups.

Further analysis showed that about 79% of the stolen funds passed through the exchange FixedFloat, where approximately 50 one-time addresses were involved. Thanks to the prompt appeal from Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000 at the time of publication). Another 282 ETH (~$542,000) remain untouched across five addresses — likely the hacker is waiting for attention to wane or seeking ways to bypass blocks.

Strange behavior from the Coinsbuy team

The most intriguing aspect of this story is the platform's own reaction. Within 24 hours of the breach, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an unprecedented move that raises more questions than it answers.

"The funds are still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.

Initial damage estimates stood at $7.9 million, but my tally of individual transactions points to a more precise figure — $8,073,992. Notably, this incident occurred against the backdrop of a series of major thefts in the industry: on July 31, 594.48 BTC (~$38.2 million) was stolen from Coldcard hardware wallet owners, and the total damage from subsequent waves of attacks reached 1367 BTC (~$89 million).

My verdict: The tactic of topping up hacked addresses looks like an attempt to conceal internal issues or test the network's reaction. If the team has no confidence in a key leak, this could indicate an insider-driven attack or compromise at the API level. I recommend Coinsbuy users withdraw their funds immediately until the situation becomes clear.