Crypto news

10.08.2026
23:32

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

A large-scale coordinated attack on the crypto platform Coinsbuy, which occurred on August 9, resulted in a loss of $8.07 million. My analysis of on-chain data, conducted jointly with colleagues from BlockWatchdog, revealed a complex scheme involving two of the largest networks at once — TRON and Ethereum.

Timeline of the hack: from a test transaction to a large-scale withdrawal

The attacker acted methodically. Starting with a small test transaction of 5 USDT on the TRON network, within an hour he withdrew 6.04 million USDT from eight different wallets. The largest operation amounted to about 3.5 million USDT. In parallel, the hacker emptied three addresses on Ethereum, taking 1.89 million USDT and 77 ETH.

Notably, all stolen funds on Ethereum were promptly converted into 981.1 ETH via the decentralized protocol 1inch. The swap wallet was created within the same hour, indicating a high degree of preparation and automation of the attack.

The connecting link: the Bridgers cross-chain bridge

The key element that made it possible to link both parts of the attack into a single operation was the use of the cross-chain service Bridgers. Analysis of the payout contract on Ethereum showed that the amounts sent to the swap wallet exactly matched the attacker's transactions on the TRON network in both size and time. This rules out coincidence and confirms the coordinated nature of the actions.

Fund movement and asset freeze

About 79% of the stolen funds — approximately $6.4 million — passed through the exchanger FixedFloat, where about 50 one-time addresses were used to obscure the trail. Thanks to the prompt appeal from Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate panic or technical difficulties on the part of the attackers.

Strange behavior of the Coinsbuy team

The most intriguing detail is the reaction of the Coinsbuy team. Within 24 hours of the attack, new funds totaling 3.93 million USDT were credited to the affected wallets. Seven transactions matched the stolen amounts to within 0.05%. This is an extremely unusual move: no one in their right mind tops up a hacked wallet with seven-figure sums if they suspect a leak of private keys.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.

Initially, losses of $7.9 million were reported, but my detailed tally of individual transactions made it possible to establish the exact amount of damage — $8,073,992.

Context and conclusions

This attack occurs against the backdrop of a series of high-profile incidents in the industry. Let me remind you that on July 31, about 500 owners of Coldcard hardware wallets became victims of a hack, losing 594.48 BTC (~$38.2 million). Subsequently, this amount grew to 1367 BTC (~$89 million), making this year one of the most severe for security in the crypto industry.

My expert commentary: The strange behavior of the Coinsbuy team, topping up hacked addresses, raises more questions than it answers. Perhaps we are dealing with an insider attack or an attempt to cover up traces of incompetence. However, the very fact of using a cross-chain bridge to combine attacks across different networks demonstrates the growing complexity of cybercrime schemes that the entire industry will have to reckon with.