Coinsbuy Hack of $8 Million: Details of Coordinated Attack on TRON and Ethereum Revealed

The cryptocurrency platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million in assets on the TRON and Ethereum blockchains on August 9. My analysis of on-chain data allows me to reconstruct the timeline and mechanics of this incident, which demonstrates a high level of preparation by the attackers.
Attack Timeline: From Test Transfer to Large-Scale Withdrawal
The attacker began with a reconnaissance transaction — transferring 5 USDT on the TRON network to test the functionality of the channels. Just an hour later, the main phase followed: 6.04 million USDT was withdrawn from eight wallets. The largest single transfer amounted to approximately 3.5 million USDT, indicating a pre-planned distribution of funds to bypass security limits.
In parallel, the attacker drained three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH. These funds were promptly converted via the decentralized protocol 1inch into 981.1 ETH — notably, the wallet for the swaps was created in the same hour as the attack itself. This suggests that the hacker operated according to a pre-prepared scenario, minimizing time gaps between stages.
Cross-Chain Trail: How Both Parts of the Attack Were Linked
The key evidence of a unified operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum directed funds to the swap wallet, with the amounts and transaction times precisely matching the attacker's actions on the TRON network. Such synchronization rules out coincidence — this is a classic example of a cross-network attack with a single command center.
The subsequent movement of funds was also well thought out. Approximately 79% of the stolen assets passed through the exchanger FixedFloat, involving about 50 one-time addresses. This is a typical practice for obscuring traces, but some funds were frozen: the service ChangeNOW, after a request from Specter Investigations analysts, blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate the hacker is waiting for attention to wane.
Strange Behavior by the Coinsbuy Team
The most intriguing aspect of this case is the platform's own reaction. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely unusual move: no one in their right mind would top up compromised addresses with seven-figure sums if there were any suspicion of a private key leak.
"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.
Initial damage estimates stood at $7.9 million, but my detailed tally of individual transactions allowed me to establish the exact amount of $8,073,992. This discrepancy underscores the importance of thorough on-chain data analysis when investigating such incidents.
For context: this hack occurs against the backdrop of a series of major thefts in the industry. Just on July 31, 594.48 BTC (~$38.2 million) was stolen from Coldcard hardware wallet owners, and after subsequent waves of attacks, the total damage rose to 1367 BTC (~$89 million). It is clear that attackers are actively refining their methods, and the industry needs to strengthen security measures, especially in key management and monitoring of suspicious activity.
My conclusion: the Coinsbuy incident is a warning sign for the entire ecosystem. Even platforms with seemingly robust infrastructure are vulnerable to coordinated attacks. I recommend that projects implement a multi-layered security system, including multi-signature, withdrawal limits, and round-the-clock monitoring of anomalous transactions. As for users — diversify asset storage and avoid keeping large sums on exchange wallets.