Crypto news

10.08.2026
22:12

Attack on Coinsbuy: $8 million stolen in a coordinated operation across TRON and Ethereum networks

social network hacking

The cryptocurrency platform Coinsbuy faced a large-scale hack, resulting in a loss of $8.07 million. The incident occurred on August 9 and affected two blockchains at once — TRON and Ethereum. My analysis of on-chain data shows that the attack was carefully planned and executed in a short timeframe, indicating a high level of preparedness on the part of the attackers.

Timeline of the hack: from a test transaction to mass withdrawal

The attacker began with a small test transaction of 5 USDT on the TRON network, likely to verify that the chosen route was functional. Within the next hour, 6.04 million USDT was withdrawn from eight wallets. The largest single transfer amounted to about 3.5 million USDT — a classic sign of an automated process rather than manual actions.

In parallel, the hacker drained three addresses on the Ethereum network, taking 1.89 million USDT and 77 ETH. The funds were quickly exchanged for 981.1 ETH via the decentralized protocol 1inch, with the swap wallet created within the same hour. Such synchronization of actions rules out coincidence.

Cross-chain connection and money laundering

A key element of the investigation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum directed funds to the swap wallet, with amounts and timing matching the attacker's transactions to the minute. This made it possible to combine both parts of the attack into a single operation.

The laundering of stolen assets was also well thought out: about 79% of the funds passed through the exchanger FixedFloat using approximately 50 one-time addresses. After intervention by analysts at Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate haste or technical difficulties on the part of the attackers.

Strange behavior by the Coinsbuy team

The most intriguing aspect is the platform's response. Within 24 hours of the attack, the Coinsbuy team topped up the same affected wallets with 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%. This is extremely unusual behavior: no one in their right mind sends funds to an address that has already been compromised.

"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.

Initially, the damage was estimated at $7.9 million, but a detailed tally of transactions showed a final figure of $8,073,992. The exact attack vector has still not been established, and Coinsbuy has not provided official comments.

My comment: This incident raises serious questions about internal security procedures at Coinsbuy. Topping up hacked addresses after an attack is either a gross mistake or a signal that the platform knows more than it is saying. In any case, this case is a reminder that even major platforms are not immune to sophisticated coordinated attacks, and users should diversify their asset storage. Against the backdrop of the recent series of Coldcard hardware wallet hacks, where losses exceeded $89 million, the market is clearly entering a phase of increased hacker group activity.