Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

On August 9, the crypto platform Coinsbuy fell victim to a coordinated attack affecting the TRON and Ethereum networks. Based on my calculations from on-chain data, the total damage amounted to $8.07 million, significantly exceeding initial estimates of $7.9 million.
Timeline of the hack: from a test transaction to mass withdrawal
The attacker acted methodically. Starting with a test transfer of 5 USDT on the TRON network, he withdrew 6.04 million USDT from eight wallets within an hour. The largest single transfer reached ~3.5 million USDT. Simultaneously, three addresses on Ethereum were drained, leaking 1.89 million USDT and 77 ETH. Notably, all funds were converted into 981.1 ETH through the decentralized protocol 1inch, with the swap wallet created in the same hour as the attack.
Key evidence of a unified operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions with precision in both size and timing. This indicates a high level of technical preparation and, likely, prior study of the platform's infrastructure.
Movement of funds and service responses
About 79% of the stolen assets passed through the exchange FixedFloat, involving approximately 50 one-time addresses—a classic scheme for obscuring tracks. However, some funds were frozen: the service ChangeNOW, after a request from Specter Investigations analysts, blocked 150 ETH (~$288,000 at the time of publication). Another 282 ETH (~$542,000) remain untouched across five addresses, offering hope for the recovery of part of the assets.
Strange behavior of the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the team replenished the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. As researchers rightly note, no one tops up a compromised wallet with seven-figure sums twice in one night unless confident there is no leak of private keys. This suggests the incident may be linked to internal processes or a configuration error, rather than direct key compromise.
The attack vector has yet to be established, and no official comments have come from Coinsbuy. However, given that over recent weeks we have witnessed a series of high-profile hacks—from the theft of 594.48 BTC from Coldcard owners to the damage increasing to 1367 BTC (~$89 million)—it is becoming clear that attackers are actively exploiting vulnerabilities in centralized and hardware solutions.
My conclusion: The Coinsbuy incident underscores the critical importance of transparency in communication after a hack. Replenishing compromised addresses without explaining the reasons creates more questions than answers and undermines community trust. Under current conditions, I recommend users diversify their asset storage and closely monitor the on-chain activity of the platforms they use.