Crypto news

11.08.2026
01:12

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

The cryptocurrency platform Coinsbuy has fallen victim to a coordinated hacker attack affecting the TRON and Ethereum networks. The total damage amounted to $8.07 million, as confirmed by a detailed analysis of blockchain data conducted by my team of researchers. The incident occurred on August 9, and the chronology of the attacker's actions can already be reconstructed.

Timeline of the hack: from a test transaction to a large-scale withdrawal

The attacker began with a trial transfer of 5 USDT on the TRON network to test the functionality of the channels. Then, within about an hour, 6.04 million USDT was withdrawn from eight wallets. The largest single transaction amounted to approximately 3.5 million USDT. In parallel, the hacker drained three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH. These funds were converted into 981.1 ETH through the decentralized protocol 1inch, with the swap wallet created within the same hour.

The key link between the two parts of the attack was the cross-chain service Bridgers. Its payout contract on Ethereum directed funds to the swap address, with transaction amounts and times fully matching the attacker's actions. This allows us to assert with a high degree of confidence that we are dealing with a single operation rather than disparate incidents.

Money laundering and the platform's response

Approximately 79% of the stolen assets were passed through the exchanger FixedFloat, which utilized about 50 one-time addresses. After intervention by analysts at Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, indicating possible difficulties with their liquidation.

Notably, the exact attack vector has not yet been established, and Coinsbuy has refrained from official comments. However, my analysis reveals a strange detail: within 24 hours, the platform's team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.

Initial damage estimates were $7.9 million, but after a thorough tally of individual transactions, the losses were refined to $8,073,992. This incident is yet another reminder that even large platforms are vulnerable. For comparison, on July 31, about 500 owners of Coldcard hardware wallets fell victim to an attack, with 594.48 BTC (~$38.2 million) stolen. This amount subsequently grew to 1082.65 BTC (~$70.2 million), and then reached 1367 BTC (~$89 million).

My comment: Topping up hacked addresses is an extremely unconventional step that may indicate an internal error or an attempt to cover tracks. However, if the team truly does not suspect a key leak, this calls their competence in security matters into question. Investors should be wary: such incidents demonstrate that even "reliable" platforms can fall victim to hackers, and the consequences for users can be irreversible.