Attack on Coinsbuy: $8 million withdrawn via TRON and Ethereum — detailed analysis

The cryptocurrency platform Coinsbuy faced a serious incident: on August 9, attackers withdrew assets worth $8.07 million in a coordinated attack that affected two of the largest networks at once — TRON and Ethereum. My analysis of on-chain data shows that this was not a random theft, but a carefully planned operation using advanced methods to bypass standard security measures.
Timeline and attack mechanism
The attacker acted methodically. It all started with a test transaction of 5 USDT on the TRON network — a classic technique for checking the functionality of withdrawal channels. Within an hour, the main wave followed: 6.04 million USDT was withdrawn from eight wallets, with the largest single transfer amounting to about 3.5 million USDT.
In parallel, the hacker drained three addresses on the Ethereum network, taking 1.89 million USDT and 77 ETH. These funds were almost instantly converted into 981.1 ETH through the decentralized protocol 1inch, with the target wallet created within the same hour. The key link was the cross-chain service Bridgers: its payout contract on Ethereum transferred amounts that exactly matched the attacker's TRON transactions in size and time. This convincingly proves that both parts of the attack were a single operation.
Fund movement and asset freeze
About 79% of the stolen funds were passed through the exchange FixedFloat, for which the attacker used approximately 50 one-time addresses. This is a typical trail-obfuscation scheme, but some assets were successfully blocked. The service ChangeNOW, after a request from Specter Investigations analysts, froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain stationary across five addresses, which may indicate an attempt to wait out active tracking.
Strange behavior of the Coinsbuy team
The most intriguing aspect is the platform's response. Within 24 hours of the attack, the Coinsbuy team topped up the same affected wallets with 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%. This is highly unusual: no one in their right mind sends seven-figure sums to compromised addresses. Such behavior makes sense only in one case — if the team is confident that there was no private key leak, and the incident is related to an internal failure or an error in contract logic.
Initially, damages were reported at $7.9 million, but my tally of individual transactions shows the exact figure — $8,073,992. The attack vector has not yet been established, and there are no official comments from Coinsbuy.
This case serves as a reminder of systemic risks: even platforms with a good reputation are vulnerable to cross-chain attacks. The Coinsbuy incident occurs against the backdrop of a series of major thefts — for example, the recent theft of 1367 BTC (~$89 million) from Coldcard hardware wallet owners. The trend is obvious: hackers are increasingly exploiting connections between networks, and the industry needs to rethink its approaches to monitoring cross-network transactions.