Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

The crypto platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million on August 9. My analysis of on-chain data, conducted together with colleagues from BlockWatchdog, revealed a complex two-network scheme that points to a high level of preparation on the part of the attackers.
The attack began with a test transaction of 5 USDT on the TRON network — a classic technique for checking the viability of withdrawal channels. Then, over the course of about an hour, 6.04 million USDT was withdrawn from eight wallets, with the largest single transfer amounting to approximately 3.5 million USDT. In parallel, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH, which were instantly converted through the decentralized protocol 1inch into 981.1 ETH sent to a wallet created within the same hour.
Key clue: the Bridgers cross-chain bridge
The link between the two attacks was the cross-chain service Bridgers. Its payout contract on Ethereum directed amounts to a swap address that matched the attacker's transactions to the exact second and size. This leaves no doubt: both parts of the operation were a single plan.
About 79% of the stolen funds passed through the exchange FixedFloat, for which the attacker used approximately 50 one-time addresses — a standard practice for obfuscating traces. However, not everything has gone smoothly for the hacker: after an appeal from Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000), while another 282 ETH (~$542,000) remain untouched across five addresses.
Strange behavior from the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the same compromised wallets with 3.93 million USDT. Seven transactions matched the stolen amounts with a margin of error of up to 0.05%. This is an unprecedented move.
"The funds are still there. This only makes sense if the team does not believe there was a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.
The initial damage figure cited was $7.9 million, but my detailed tally of individual transactions shows exact losses of $8,073,992. This echoes the recent series of attacks on Coldcard owners, where the damage amount grew from $38 million to $89 million, highlighting the systemic nature of threats in the industry.
My verdict: Topping up the compromised addresses is either a desperate attempt to conceal an internal error or a sign that the attack was carried out through an API vulnerability rather than key compromise. In any case, the incident demonstrates the critical importance of multi-layered security and instant security audits for all platforms dealing with digital assets.