Crypto news

11.08.2026
05:02

Attack on Coinsbuy: $8 million stolen across TRON and Ethereum networks — detailed analysis

social network hacking

The cryptocurrency platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million. The incident occurred on August 9 and affected two of the largest networks — TRON and Ethereum. My analysis of on-chain data allows me to reconstruct the chronology and mechanics of this hack.

Attack Timeline: From Test Transaction to Mass Withdrawal

The attacker began with a small test transaction of 5 USDT on the TRON network. This is a classic technique to check the functionality of withdrawal channels. Within an hour, a series of large operations followed: 6.04 million USDT was withdrawn from eight wallets, with the largest transaction reaching ~3.5 million USDT. Simultaneously, the hacker drained three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH.

Notably, the stolen funds on Ethereum were promptly converted through the decentralized protocol 1inch into 981.1 ETH. The swap wallet was created within the same hour, indicating a high level of preparation and automation in the attack.

Cross-Chain Connection and Money Laundering

A key element of the analysis was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that precisely matched the attacker's transactions in size and timing. This allows us to confidently assert that both parts of the attack — on TRON and Ethereum — were part of a single operation.

Approximately 79% of the stolen funds (~$6.4 million) passed through the exchanger FixedFloat, using about 50 one-time addresses. This is a typical scheme for obscuring traces. Thanks to the prompt intervention of the service ChangeNOW, 150 ETH (~$288,000) was frozen. Another 282 ETH (~$542,000) remains untouched across five addresses, which could be either a hacker's mistake or a tactical move.

Strange Behavior of the Coinsbuy Team

The most intriguing aspect is the platform's response. Within 24 hours of the attack, the Coinsbuy team replenished the affected wallets with 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%. This raises serious questions.

"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.

Initially, the damage was reported as $7.9 million, but my tally of individual transactions shows a more precise figure — $8,073,992. This difference is explained by including all associated operations, including fees and intermediate transfers.

I would like to note that this incident fits into an alarming trend of recent weeks: earlier, hackers stole 594.48 BTC (~$38.2 million) from Coldcard hardware wallet owners, and then the damage amount grew to 1367 BTC (~$89 million). It is obvious that attackers are refining their attack methods, using cross-chain bridges and decentralized exchanges to launder funds. Platforms need to reconsider their security protocols, especially in terms of key management and real-time monitoring of suspicious activity.