Crypto news

11.08.2026
04:47

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum — detailed analysis

social network hacking

On August 9, the crypto platform Coinsbuy suffered a coordinated attack, resulting in attackers withdrawing $8.07 million across the TRON and Ethereum networks. My analysis of on-chain data, conducted jointly with blockchain researchers, allows us to reconstruct the timeline of the incident and identify key anomalies in the project team's behavior.

Attack timeline and technical details

The hack began with a test transaction of 5 USDT on the TRON network — a classic technique for verifying control over a wallet. Within an hour, the attacker withdrew 6.04 million USDT from eight addresses, with the largest single transfer amounting to approximately 3.5 million USDT. Simultaneously, the hacker drained three wallets on Ethereum, stealing 1.89 million USDT and 77 ETH. The funds were instantly converted into 981.1 ETH via the decentralized protocol 1inch, with the swap wallet created in the same hour as the attack itself.

Key evidence of a unified operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap address that exactly matched the attacker's transactions in size and timing. This points to a high level of technical preparation — the hacker clearly planned a money laundering route across multiple networks.

Movement of stolen funds

Approximately 79% of the stolen assets passed through the exchange FixedFloat, which involved about 50 one-time addresses — a typical practice for obfuscating traces. After intervention by Specter Investigations analysts, the service ChangeNOW froze 150 ETH (~$288,000), while another 282 ETH (~$542,000) remain untouched across five addresses. However, the most intriguing detail is the platform's own behavior.

"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.

Anomaly: the platform topped up hacked wallets

Within 24 hours of the attack, the Coinsbuy team transferred 3.93 million USDT to the same 10 addresses that had been compromised. Seven transactions matched the stolen amounts to within 0.05%. This is an extremely illogical step, unless the team is confident that no key leak occurred. Initial reports cited a damage amount of $7.9 million, but my tally of individual transactions yields an exact figure of $8,073,992.

The exact attack vector has not yet been established, and Coinsbuy is refraining from official comments. However, it is worth noting that this incident occurs against the backdrop of a series of major thefts: on July 31, 594.48 BTC (~$38.2 million) was stolen from Coldcard owners, and after subsequent waves of attacks, the damage amount grew to 1367 BTC (~$89 million).

My conclusion: Topping up hacked addresses is either a gross error in risk management or a signal of an internal insider controlling the situation. In any case, the incident demonstrates that even platforms with experience are insufficiently protected against coordinated attacks, and the use of cross-chain bridges is becoming a favorite tool for hackers to conceal their tracks.