Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

The crypto platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million. The incident occurred on August 9 and affected two of the largest networks at once — TRON and Ethereum. My analysis of on-chain data, conducted jointly with colleagues from BlockWatchdog, allows us to reconstruct the full picture of what happened.
Details of the coordinated theft
The attacker began with a test transaction of 5 USDT on the TRON network, checking the readiness of the infrastructure. Within an hour, 6.04 million USDT was withdrawn from eight wallets, with the largest single transaction amounting to about 3.5 million USDT. Simultaneously, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. These funds were instantly swapped for 981.1 ETH via the decentralized protocol 1inch, with the swap wallet created within the same hour — a clear sign of professional preparation.
A key element linking both parts of the attack was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions precisely in size and timing. This confirms that we are dealing with a single operation, not disparate actions.
Movement of funds and asset freeze
About 79% of the stolen funds passed through the exchanger FixedFloat, for which the attacker used approximately 50 one-time addresses. After an appeal from Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000 at the time of publication). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate an attempt to wait out the period before further laundering.
The attack vector has not yet been established, and Coinsbuy is refraining from official comments. However, my analysis revealed a curious detail: within 24 hours, the platform's team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is highly unusual behavior.
"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.
Initial reports cited losses of $7.9 million, but my tally of individual transactions showed the exact amount — $8,073,992. This incident once again raises questions about the security of centralized platforms, especially against the backdrop of recent thefts from Coldcard owners, where losses have already reached $89 million.
My verdict: the team's replenishment of hacked wallets is either a gross mistake or a subtle hint at insider involvement. In any case, the industry needs stricter security standards, otherwise we will see a repeat of similar scenarios.