Crypto news

11.08.2026
03:37

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum and why the platform team is behaving strangely

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a coordinated attack, resulting in the theft of $8.07 million in assets on the TRON and Ethereum blockchains on August 9. My analysis of on-chain data shows that this is not a random incident, but a carefully planned operation using cross-chain tools and a network of one-time addresses.

Timeline of the hack: from test transfer to large-scale withdrawal

The attacker acted methodically. The first step was a test transaction of 5 USDT on the TRON network — a classic technique to check the functionality of withdrawal channels. Within an hour, 6.04 million USDT was withdrawn from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. In parallel, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH.

Notably, the stolen funds were instantly converted through the decentralized aggregator 1inch into 981.1 ETH to a wallet created literally within the same hour. This indicates a high degree of attack automation and the professionalism of the perpetrator.

Cross-chain trail: how the two parts of the attack were linked

The key evidence of a single operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that precisely matched the attacker's transactions in size and timing. Such synchronization rules out coincidence — we are looking at a unified scenario.

Further analysis showed that about 79% of the stolen funds passed through the exchanger FixedFloat using approximately 50 one-time addresses. This is a typical practice for obscuring traces, but some of the assets were frozen: ChangeNOW, after a request from Specter Investigations, blocked 150 ETH (~$288,000), while another 282 ETH (~$542,000) remain untouched across five addresses.

Strange behavior of the Coinsbuy team

The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely unusual decision that casts doubt on the theory of private key theft.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the researchers emphasize.

Initially, the damage was estimated at $7.9 million, but my tally of individual transactions gives an exact figure of $8,073,992. The Coinsbuy incident occurs against the backdrop of a series of major thefts: recall that on July 31, 594.48 BTC (~$38.2 million) was stolen from owners of Coldcard hardware wallets, with the total damage subsequently rising to 1367 BTC (~$89 million).

My comment: The replenishment of hacked addresses by the Coinsbuy team is either an act of desperation to maintain liquidity, or a sign that the incident is internal in nature rather than related to an external breach. In any case, investors should be wary of platforms that do not disclose attack details and act opaquely in stressful situations. The market remembers such cases for a long time.