Crypto news

11.08.2026
00:33

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

On August 9, the crypto platform Coinsbuy fell victim to a carefully coordinated attack affecting two of the largest networks simultaneously — TRON and Ethereum. My analysis of on-chain data shows that the total damage amounted to $8.07 million, confirmed by a detailed breakdown of transactions rather than approximate estimates.

Timeline of the hack: from test transfer to mass withdrawal

The attacker acted methodically, starting with a readiness check — a test transaction of 5 USDT on the TRON network. Within an hour, a series of withdrawals followed: 6.04 million USDT was taken from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. This indicates that the attacker had full control over multiple addresses, ruling out random phishing.

In parallel, the hacker drained three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH. Notably, the funds were quickly converted into 981.1 ETH via the decentralized protocol 1inch — the swap wallet was created in the same hour, pointing to pre-prepared infrastructure.

Key to the puzzle: cross-chain link

My analysis confirms: both parts of the attack are inextricably linked. The use of the cross-chain service Bridgers was a decisive factor — its payout contract on Ethereum sent amounts to the swap address that matched the attacker's transactions precisely in timing and volume. This is not a coincidence but a single operation, demonstrating a high level of technical sophistication.

The money laundering was also well thought out: about 79% of the stolen assets passed through the exchanger FixedFloat, which used approximately 50 one-time addresses. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000), while another 282 ETH (~$542,000) remain untouched across five addresses — possibly the hacker is waiting for attention to wane.

Strange behavior of the Coinsbuy team

The most intriguing part of this story is the platform's response. Within 24 hours of the hack, the Coinsbuy team replenished the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely illogical move, unless the developers are confident that there has been no leak of private keys.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the researchers emphasize.

Initial damage estimates of $7.9 million turned out to be understated — a precise tally of individual transactions revealed losses of $8,073,992. Against the backdrop of the recent theft of 1367 BTC (~$89 million) from Coldcard owners, this attack confirms a troubling trend: attackers are increasingly combining cross-chain tools and decentralized exchanges to cover their tracks.

My expert opinion: the team's replenishment of hacked addresses is either an act of desperation to preserve reputation, or a sign that the incident involves internal collusion rather than an external hack. In any case, investors should be wary of platforms that do not disclose details of an attack for an extended period.