Crypto news

11.08.2026
04:07

Attack on Coinsbuy: $8 million stolen in coordinated cross-chain operation

social network hacking

The cryptocurrency platform Coinsbuy was subjected to a large-scale coordinated attack on August 9, as a result of which the attackers withdrew assets worth over $8 million. My analysis of on-chain data allows me to reconstruct the full picture of this incident, which affected the two largest networks — TRON and Ethereum.

Timeline of the attack and key transactions

The start of the operation was typical of professional hackers — a test transaction of 5 USDT on the TRON network. Within an hour, a series of withdrawals followed from eight wallets totaling 6.04 million USDT, with the largest single transfer amounting to about 3.5 million USDT. In parallel, the attacker drained three addresses on the Ethereum network, taking 1.89 million USDT and 77 ETH. Notably, the funds were instantly converted into 981.1 ETH via the decentralized protocol 1inch — the swap wallet was created within the same hour, indicating thorough preparation.

The key element linking both parts of the attack was the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions with high precision in both time and volume. This is compelling evidence that we are dealing with a single coordinated operation rather than isolated incidents.

Movement of the stolen funds

The analysis shows that about 79% of the stolen assets passed through the exchanger FixedFloat, for which the attacker used approximately 50 one-time addresses. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — likely, the hacker is waiting to avoid tracking.

The most intriguing aspect is the behavior of the platform itself. Within 24 hours of the attack, the Coinsbuy team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely unusual move.

"The money is still there. This only makes sense if the team does not believe in a leak of private keys. An address is a key: no one tops up a hacked wallet with seven-figure sums twice in one night," the researchers emphasize.

The exact attack vector remains unclear, and there are no official comments from Coinsbuy. The initial damage estimate of $7.9 million was revised to $8,073,992 based on a detailed tally of individual transactions.

This incident is yet another reminder of the growing sophistication of attacks in the crypto industry. The use of cross-chain services and instant swaps complicates fund tracking, while the team's replenishment of hacked wallets raises questions about the true nature of the incident. In my practice, such actions often indicate an insider threat or a staged event, but it is premature to draw final conclusions. Against the backdrop of recent thefts from Coldcard owners (1367 BTC worth $89 million), it is clear: the industry is experiencing a wave of professional attacks requiring enhanced security measures at all levels.