Crypto news

11.08.2026
03:17

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a carefully coordinated attack, resulting in the theft of $8.07 million on August 9. My analysis of on-chain data, conducted jointly with colleagues from BlockWatchdog, revealed a complex scheme that affected two blockchains at once — TRON and Ethereum.

Timeline of the hack: from test to large-scale withdrawal

The attacker acted methodically. The first step was a test transaction of 5 USDT on the TRON network — a clear check of the channel's viability. Just an hour later, the main phase followed: 6.04 million USDT was withdrawn from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. In parallel, the attacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. These funds were instantly converted through the decentralized protocol 1inch into 981.1 ETH, with the receiving wallet created in the same hour, indicating pre-prepared infrastructure.

The cross-chain link: key to the puzzle

At first glance, the attacks on the two networks might have seemed independent, but analysis showed otherwise. The use of the cross-chain service Bridgers became the connecting link: its payout contract on Ethereum transferred amounts to the swap wallet that exactly matched the hacker's transactions in size and time. This leaves no doubt — we are dealing with a single operation, not two separate incidents.

Movement of funds: exchanges and freezes

Approximately 79% of the stolen assets passed through the exchange FixedFloat, where about 50 one-time addresses were used — a classic tactic to obscure tracks. However, part of the stolen funds was successfully blocked: after my appeal to Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, offering hope for their recovery.

Strange behavior of the Coinsbuy team

The most intriguing moment is the platform's reaction. Instead of the expected freezing of all operations, the Coinsbuy team topped up the affected wallets with 3.93 million USDT within 24 hours. Seven of these transactions matched the stolen amounts to within 0.05%. This is an extremely unusual decision. As my colleagues rightly noted: "The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night."

Initially, the damage was estimated at $7.9 million, but my tally of individual transactions showed the exact amount of $8,073,992. Notably, this incident occurs against the backdrop of a series of major thefts: on July 31, Coldcard owners had 594.48 BTC (~$38.2 million) stolen, and the total damage from this wave of attacks reached 1367 BTC (~$89 million).

My verdict: The methodical nature and technical complexity of the attack point to a professional group, not a random hacker. The topping up of hacked addresses by the Coinsbuy team is either a sign of an internal problem or an attempt to cover tracks. I recommend that platform users immediately withdraw their funds and change all keys until an official clarification of the situation is provided.