Attack on Coinsbuy: $8 million disappeared in a coordinated TRON and Ethereum hack

The cryptocurrency platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million across the TRON and Ethereum networks on August 9. My analysis of on-chain data, conducted jointly with colleagues from BlockWatchdog, revealed a clear picture of the attacker's actions, who operated methodically and at high speed.
Timeline of the attack: from a test transfer to a mass withdrawal
The attacker began by checking readiness, sending a test transaction of 5 USDT on the TRON network. After confirming success, he withdrew 6.04 million USDT from eight wallets within an hour, with the largest single transfer amounting to about 3.5 million USDT. Simultaneously, three addresses on the Ethereum network were drained, from which 1.89 million USDT and 77 ETH were taken. All funds were converted via 1inch into 981.1 ETH to a wallet created within the same hour.
The key moment was discovering the link between both parts of the attack. Using the cross-chain service Bridgers allowed me to trace how its payout contract on Ethereum directed funds to the swap wallet. The amounts and transaction times matched to the second, clearly indicating a single operation rather than disparate actions.
Money laundering and service responses
About 79% of the stolen assets passed through the exchanger FixedFloat, for which the hacker used approximately 50 one-time addresses. Part of the funds was successfully frozen: ChangeNOW, after a request from Specter Investigations, blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain inactive across five addresses, suggesting possible haste or inexperience on the part of the attacker.
"The strangest thing about this story is the behavior of the Coinsbuy team. Within 24 hours of the attack, they topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. The money is still there. This only makes sense if the team does not believe in a private key leak. An address is a key: no one tops up a hacked wallet with seven-figure sums twice in one night," I emphasize.
The exact attack vector has not yet been established, and no official comments have come from Coinsbuy. Initially, the damage was estimated at $7.9 million, but my detailed tally of individual transactions showed a final amount of $8,073,992. This echoes the recent series of Coldcard hacks, where the damage grew from $38 million to $89 million over several waves of attacks, highlighting the persistent vulnerability of even seemingly secure platforms.
My expert opinion: The replenishment of hacked wallets by the Coinsbuy team is either a gross mistake or a signal that the incident is related to internal access rather than an external breach. In any case, such actions call into question the team's competence and require an immediate public explanation, otherwise trust in the platform will be completely undermined.