Attack on Coinsbuy: $8 million leaked through TRON and Ethereum — detailed analysis

The crypto platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million on August 9. My analysis of on-chain data, conducted jointly with experts from BlockWatchdog, revealed a complex scheme that affected two of the largest networks at once — TRON and Ethereum.
Timeline of the hack: from a test transaction to millions
The attacker acted methodically. Starting with a small test transaction of 5 USDT on the TRON network, the attacker withdrew 6.04 million USDT from eight wallets within an hour. The largest operation amounted to about 3.5 million USDT. In parallel, the hacker emptied three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. Notably, the funds were instantly converted into 981.1 ETH via the decentralized protocol 1inch — the swap wallet was created in the same hour, indicating thorough preparation.
Key clue: cross-chain connection
The most interesting part of this attack is the use of the cross-chain service Bridgers. The payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions precisely in size and time. This allowed me to confidently assert: both parts of the attack are a single operation, not two independent incidents.
Fund movement and asset freeze
About 79% of the stolen funds passed through the exchanger FixedFloat, for which approximately 50 one-time addresses were used. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (approximately $288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — likely, the attacker is waiting for the right moment to launder them.
Strange behavior of the Coinsbuy team
The most mysterious aspect is the platform's reaction. The exact attack vector has still not been established, and there are no official comments. However, within 24 hours of the hack, the team replenished the affected wallets with 3.93 million USDT. Seven transactions matched the stolen amounts to within 0.05%. This is an extremely illogical decision that raises certain questions.
"The money is still there. This only makes sense if the team does not believe in a private key leak. An address is a key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.
Initially, the damage was estimated at $7.9 million, but my detailed tally of individual transactions showed the exact amount — $8,073,992. This incident serves as a reminder of the growing threat: earlier, on July 31, about 500 owners of Coldcard hardware wallets lost 594.48 BTC (~$38.2 million), and this amount has grown to 1367 BTC (~$89 million).
My verdict: The attack on Coinsbuy demonstrates the evolution of hacker methods — the use of cross-chain bridges and instant swaps is becoming the standard for large-scale thefts. However, the platform team's replenishment of hacked addresses is an alarming signal that could indicate either an insider threat or an attempt to cover up traces of their own mistake. Investors should reconsider their risks when working with platforms that do not ensure transparency in emergency situations.