Analysis of the attack on Coinsbuy: $8 million, cross-chain traces, and strange behavior from the team.

On August 9, the crypto platform Coinsbuy fell victim to a coordinated attack affecting the TRON and Ethereum networks. The total damage amounted to $8.07 million, exceeding initial estimates of $7.9 million. A detailed analysis of transactions, which I conducted based on on-chain data, revealed a complex scheme of actions by the attacker.
Timeline and Scope of the Hack
The attack began with a test transaction of 5 USDT on the TRON network. Within an hour, 6.04 million USDT was withdrawn from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. Simultaneously, the hacker drained three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH. These funds were quickly converted via 1inch into 981.1 ETH to a wallet created within the same hour.
Key evidence of a single operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions in both timing and size. This indicates a high level of preparation and technical awareness on the part of the attacker.
Movement of Funds and Freezes
About 79% of the stolen assets passed through the exchange FixedFloat, using approximately 50 one-time addresses. Thanks to the prompt appeal from Specter Investigations, the service ChangeNOW blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which could indicate either haste or deliberate storage for further operations.
Strange Behavior of the Coinsbuy Team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is illogical for compromised addresses. As experts rightly note, no one refills a compromised wallet with seven-figure sums twice in one night. This could mean the team does not believe in a leak of private keys, and the incident is related to internal processes or an error in smart contract logic.
The exact attack vector has not yet been established, and there are no official comments from Coinsbuy. However, given the scale and technical complexity, this is not a random hack but a targeted operation.
My analysis: Refilling hacked addresses is a rare and risky move that usually indicates the incident is the result of an internal error rather than an external hack. Otherwise, the team would simply have lost even more funds. I recommend market participants closely monitor the situation and avoid hasty conclusions about the causes of the attack until official data emerges.