Crypto news

11.08.2026
02:37

Attack on Coinsbuy: how hackers withdrew $8 million from TRON and Ethereum networks

social network hacking

On August 9, the crypto platform Coinsbuy fell victim to a coordinated attack affecting the TRON and Ethereum blockchains. My analysis of on-chain data shows that the total damage amounted to $8.07 million, with the attacker acting with striking methodicalness, starting with a test transaction of 5 USDT on the TRON network.

Timeline and scale of the hack

Within an hour of the test transfer, the hacker withdrew 6.04 million USDT from eight wallets on the TRON network, with the largest single transaction reaching ~3.5 million USDT. Simultaneously, three addresses on Ethereum were drained, leaking 1.89 million USDT and 77 ETH. Notably, all funds were converted into 981.1 ETH via the decentralized protocol 1inch, using a wallet created within the same hour—this indicates a high degree of preparation.

The key evidence of a single operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum directed funds to an address for swaps, with amounts and timestamps fully matching the attacker's transactions. This links both parts of the attack into a single chain.

Traces and fund freezing

About 79% of the stolen assets passed through the exchange FixedFloat, where the attacker used approximately 50 one-time addresses to obfuscate the trail. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate haste or technical difficulties on the hacker's part.

The most intriguing aspect is the behavior of the Coinsbuy platform itself. Within 24 hours of the attack, the team replenished the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an unprecedented move that calls into question the version of private key compromise.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," researchers emphasize.

Initial damage estimates of $7.9 million turned out to be understated: my tally of individual transactions revealed losses of $8,073,992. Against the backdrop of a recent series of hacks, including the theft of 1367 BTC (~$89 million) from Coldcard owners, this incident highlights the systemic vulnerability of centralized platforms.

My expert opinion: Replenishing hacked addresses after the incident is an extremely unconventional move that may point to an internal error or a staged event. However, regardless of the vector, this case demonstrates the critical importance of multi-layered security and cold storage of assets for any crypto services.