Crypto news

11.08.2026
02:57

Attack on Coinsbuy: $8 million stolen in a coordinated operation across TRON and Ethereum networks

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a large-scale hacker attack, resulting in the theft of $8.07 million. The incident occurred on August 9 and affected two of the largest blockchain networks simultaneously — TRON and Ethereum. My analysis of on-chain data shows that the attacker acted according to a clearly calculated plan, indicating a high level of preparation.

Timeline of the attack: from a test transaction to millions

The attack began with a small test transaction of 5 USDT on the TRON network — a typical technique for checking control over a wallet. Within an hour, the attacker withdrew 6.04 million USDT from eight addresses, with the largest single transfer amounting to about 3.5 million USDT. In parallel, three wallets on Ethereum containing 1.89 million USDT and 77 ETH were drained. Notably, the funds were promptly converted into 981.1 ETH through the decentralized protocol 1inch, with the swap wallet created within the same hour.

The connection between the two parts of the attack was established through the use of the cross-chain service Bridgers. Its payout contract on Ethereum directed funds to the swap address, with transaction amounts and times fully matching the hacker's actions. This leaves no doubt that we are dealing with a single coordinated operation.

Money laundering and asset freezing

About 79% of the stolen funds were passed through the exchange FixedFloat using approximately 50 one-time addresses — a classic scheme for obscuring traces. However, some of the assets were frozen: the service ChangeNOW blocked 150 ETH (~$288,000), and another 282 ETH (~$542,000) remain untouched across five addresses. This suggests that the hacker either did not have time to withdraw all funds or plans to use them later.

Strange behavior from the Coinsbuy team

The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team replenished the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. Such behavior is extremely illogical for a hack victim. Experts rightly note: "The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a compromised wallet with seven-figure sums twice in one night."

Initially, the damage was estimated at $7.9 million, but my calculation of individual transactions suggests a more precise figure — $8,073,992. The Coinsbuy incident occurs against the backdrop of a series of major thefts: on July 31, owners of Coldcard hardware wallets had 594.48 BTC (~$38.2 million) stolen, and this amount subsequently grew to 1367 BTC (~$89 million). This indicates an escalation by organized hacker groups, targeting both centralized platforms and individual holders of crypto assets.

My comment: This incident highlights the critical importance of private key security, yet the strange actions of the Coinsbuy team raise more questions than answers. In my practice, cases where a hack victim voluntarily tops up compromised addresses are rare — this could indicate the insider nature of the attack or an attempt to cover up traces of their own mistake. Investors should exercise increased caution when working with platforms that do not provide transparent explanations after such incidents.