Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

On August 9, the crypto platform Coinsbuy suffered a coordinated attack, resulting in the theft of $8.07 million. My analysis of on-chain data, conducted together with blockchain researchers, revealed a complex scheme affecting the two largest networks — TRON and Ethereum.
Timeline of the attack: from a test transfer to a large-scale withdrawal
The attacker began with a trial transaction of 5 USDT on the TRON network, checking the readiness of the infrastructure. Within an hour, 6.04 million USDT was withdrawn from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. In parallel, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. These funds were promptly converted into 981.1 ETH via the decentralized protocol 1inch, with the swap wallet created within the same hour.
A key element linking both parts of the attack was the use of the cross-chain service Bridgers. Its payout contract on Ethereum directed funds to the swap wallet, with transaction amounts and times fully matching the attacker's actions. This allows us to state with high confidence that we are dealing with a single operation, not scattered incidents.
Movement of funds and service responses
About 79% of the stolen assets passed through the exchange FixedFloat, which involved approximately 50 one-time addresses — a classic practice for obscuring traces. However, thanks to the prompt action of analysts at Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate the attacker is waiting for attention to subside.
The most intriguing aspect was the behavior of the Coinsbuy team itself. Within 24 hours of the attack, the platform topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely unusual move: no one in their right mind sends seven-figure sums to compromised addresses unless confident in their safety.
"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasized.
Initial damage estimates stood at $7.9 million, but my detailed tally of individual transactions showed a final figure of $8,073,992. The exact attack vector has yet to be determined, and no official comments have come from Coinsbuy.
This incident fits into a troubling trend: recall that on July 31, about 500 owners of Coldcard hardware wallets fell victim to an attack, losing 594.48 BTC (~$38.2 million). Later, the damage amount grew to 1367 BTC (~$89 million).
My conclusion: the attack on Coinsbuy demonstrates the growing sophistication of hackers using cross-chain tools to bypass traditional security. The team's decision to top up the hacked addresses raises more questions than answers — perhaps we are dealing with an insider error rather than an external breach. Investors should reconsider their security protocols, especially when working with platforms that use multiple networks.