Coinsbuy lost $8 million: anatomy of a coordinated attack on TRON and Ethereum

On August 9, the crypto platform Coinsbuy fell victim to a carefully planned hacking operation, resulting in the theft of $8.07 million. My analysis of on-chain data shows that the attack was coordinated in nature and affected the two largest networks — TRON and Ethereum.
Timeline of the hack: from a test transaction to a large-scale withdrawal
The attacker acted methodically. It all started with a test transaction of 5 USDT on the TRON network — a typical technique for verifying control over a wallet. Then, within about an hour, 6.04 million USDT was withdrawn from eight addresses. The largest single withdrawal amounted to about 3.5 million USDT, indicating a deep understanding of the platform's liquidity structure.
In parallel, the hacker drained three Ethereum addresses, taking 1.89 million USDT and 77 ETH. The funds were instantly converted into 981.1 ETH via 1inch, with the swap wallet created within the same hour — this points to pre-prepared infrastructure.
Cross-chain trail and money laundering
The key element linking both parts of the attack was the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that precisely matched the attacker's transactions in both size and timing. This is no coincidence — we are looking at a single operation designed to bypass standard security measures.
About 79% of the stolen funds passed through the exchange FixedFloat using approximately 50 one-time addresses. Such diversification is a classic practice to hinder tracking. Part of the funds was successfully frozen: ChangeNOW blocked 150 ETH (~$288,000), while 282 ETH (~$542,000) remain untouched across five addresses.
Strange behavior of the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an unprecedented decision. As researchers rightly noted, no one tops up a hacked wallet with seven-figure sums twice in one night unless they are confident there is no leak of private keys.
Initially, the damage was estimated at $7.9 million, but my tally of individual transactions gives an exact figure — $8,073,992. The precise attack vector has yet to be established, and Coinsbuy is refraining from official comments.
My verdict: this attack demonstrates the growing sophistication of cybercrime in the crypto space. The combination of cross-chain tools, one-time addresses, and time-coordinated actions is not a spontaneous hack but the work of professionals. The industry needs to rethink its approaches to key management and real-time monitoring of suspicious activity, otherwise such incidents will become the new norm.