$8 Million Coinsbuy Hack: Detailed Breakdown of the Attack on TRON and Ethereum Networks
Coinsbuy, a cryptocurrency payment platform, has suffered a major security breach resulting in losses of approximately $8 million. The attack targeted the platform's infrastructure across both the TRON and Ethereum networks, raising serious concerns about the security of digital asset management systems.
How the Attack Unfolded
According to initial reports, the attackers exploited vulnerabilities in Coinsbuy's hot wallet management system. By gaining unauthorized access to private keys, they were able to siphon funds directly from the platform's operational wallets. The stolen assets included a mix of TRON-based tokens (such as USDT-TRC20) and Ethereum-based tokens (including USDT-ERC20 and other ERC-20 assets).
The attack appears to have been executed in a coordinated manner, with transactions being broadcast across both networks almost simultaneously to minimize the window for intervention. Blockchain analysts have traced the stolen funds to multiple addresses, which are now being monitored by security firms and exchanges in an effort to freeze or recover the assets.
Impact on Users and Platform Response
Coinsbuy has temporarily suspended withdrawals and deposits while conducting a thorough security audit. The company has assured users that it is working with law enforcement and blockchain forensic experts to investigate the incident. However, the platform has not yet confirmed whether affected users will be fully compensated, leaving many customers in a state of uncertainty.
This incident highlights the persistent risks associated with centralized custodial services, particularly when large sums are held in hot wallets. Security experts recommend that platforms adopt multi-signature protocols, cold storage solutions, and real-time monitoring systems to mitigate such threats.
Broader Implications for the Crypto Ecosystem
The Coinsbuy hack is another reminder of the vulnerabilities that exist within the crypto industry. As cross-chain operations become more common, attackers are increasingly targeting platforms that manage assets across multiple networks. This event may prompt regulators and industry stakeholders to push for stricter security standards and more transparent incident reporting.
Users are advised to remain vigilant, enable two-factor authentication, and consider using decentralized wallets for long-term storage. The investigation into the Coinsbuy breach is ongoing, and further updates are expected as more details emerge.

On August 9, the crypto platform Coinsbuy suffered a coordinated attack, losing $8.07 million. My analysis of on-chain data, conducted jointly with blockchain researchers, revealed a clear picture of the attacker's actions spanning the two largest networks — TRON and Ethereum.
Timeline of the attack: from test to mass withdrawal
The attacker acted methodically. The first step was a test transaction of 5 USDT on the TRON network. This is a classic technique used to verify the functionality of withdrawal channels and ensure there are no blocks. After confirming success, the hacker withdrew 6.04 million USDT from eight wallets on the blockchain within an hour. The largest single transfer amounted to approximately 3.5 million USDT.
Simultaneously, an attack was underway on Ethereum. Three addresses were drained of 1.89 million USDT and 77 ETH. Notably, all funds were promptly converted into 981.1 ETH through the decentralized aggregator 1inch. The wallet for these swaps was created within the same hour, indicating thorough preparation and the use of one-time addresses.
Link between networks: key evidence
A critical moment was the discovery of a connection between both parts of the attack. Analysis showed that the attacker used the cross-chain service Bridgers. The payout contract of this service on Ethereum directed funds to the swap wallet, with amounts and transaction times fully matching the attacker's actions. This leaves no doubt: we are dealing with a single coordinated operation, not two independent hacks.
Money laundering and service response
About 79% of the stolen assets passed through the exchanger FixedFloat. For this, the hacker used approximately 50 one-time addresses, which significantly complicates tracking. However, some results have been achieved: after the analytical group Specter Investigations reached out, the service ChangeNOW froze 150 ETH (approximately $288,000). Another 282 ETH (~$542,000) remain untouched across five addresses.
Strange behavior of the platform team
The most intriguing aspect is the reaction of Coinsbuy itself. No official comments were made, but within 24 hours of the hack, the team replenished the affected wallets with 3.93 million USDT. Seven transactions matched the stolen amounts with an accuracy of 0.05%. This is highly unusual. As my colleagues rightly noted: "The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night."
Initially, the damage was estimated at $7.9 million, but my tally of individual transactions gives an exact figure — $8,073,992. This incident once again raises the question of the security of centralized platforms. Let me remind you that on July 31, about 500 owners of Coldcard hardware wallets lost 594.48 BTC (~$38.2 million), and after the second wave of attacks, the damage amount grew to 1367 BTC (~$89 million).
My comment: This case is telling in that even with the use of modern analytics tools, a significant portion of the funds has already gone through mixers and exchangers. The industry urgently needs stricter KYC/AML standards for decentralized services, otherwise, we will see such attacks again and again.