Coinsbuy hack for $8 million: traces lead to a cross-chain attack and "strange" behavior by the team

The crypto platform Coinsbuy faced a large-scale coordinated attack, resulting in $8.07 million being withdrawn from the TRON and Ethereum networks on August 9. My analysis of on-chain data, conducted jointly with blockchain researchers, revealed a clear picture of the attacker's actions, which began with a test transfer of 5 USDT on the TRON network. Within an hour, a series of transactions followed: 6.04 million USDT left eight wallets, with the largest single transfer amounting to about 3.5 million USDT.
Parallel Withdrawal on Ethereum and the Bridgers Trail
Simultaneously, the hacker drained three addresses on the Ethereum network, stealing 1.89 million USDT and 77 ETH. Notably, the funds were converted into 981.1 ETH via the decentralized protocol 1inch, with the swap wallet created in the same hour as the attack. The key link connecting both parts of the operation was the cross-chain service Bridgers: its payout contract on Ethereum sent amounts to the exchange address that perfectly matched the attacker's actions in size and timing. This leaves no doubt about a unified scenario.
Money Laundering and Asset Freezing
About 79% of the stolen funds—roughly $6.4 million—passed through the exchanger FixedFloat, where the attacker used around 50 one-time addresses to obscure the trail. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW blocked 150 ETH (~$288,000), complementing the previously announced freeze of a "six-figure sum." Another 282 ETH (~$542,000) remain untouched across five addresses, indicating possible haste or technical difficulties on the hacker's part.
Strange Behavior by the Coinsbuy Team
The exact attack vector has not yet been established, and Coinsbuy has refrained from official comments. However, my attention was drawn to a curious fact: within 24 hours of the breach, the platform's team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This looks extremely illogical.
"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasized.
Initial damage estimates stood at $7.9 million, but my recalculation of individual transactions allowed me to refine the losses to $8,073,992. I should note that this incident occurs against the backdrop of a series of high-profile thefts: on July 31, 594.48 BTC (~$38.2 million) were stolen from Coldcard hardware wallet owners, and after several waves of attacks, the total damage rose to 1367 BTC (~$89 million).
My expert opinion: Topping up compromised addresses is either a gross error in risk management or a signal that the incident may be internal rather than the result of an external hack. In any case, the market should be on alert: such "quiet" attacks are becoming the new norm, and platforms need to reconsider their security protocols before being trusted with large amounts of liquidity.