Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

On August 9, the crypto platform Coinsbuy fell victim to a large-scale coordinated attack, resulting in the theft of $8.07 million. My analysis of on-chain data, conducted jointly with blockchain researchers, revealed a complex scheme that affected two of the largest networks at once — TRON and Ethereum.
Timeline of the hack: from a test transaction to millions
The attack began with a seemingly harmless test transaction of 5 USDT on the TRON network. However, within the next hour, the attacker withdrew 6.04 million USDT from eight different wallets. The largest single transfer amounted to about 3.5 million USDT — a classic sign of an automated script bypassing withdrawal limits.
In parallel, the hacker drained three addresses on the Ethereum network, stealing 1.89 million USDT and 77 ETH. Notably, all funds were instantly converted into 981.1 ETH via the decentralized protocol 1inch, with the swap wallet created in the same hour as the attack itself. This indicates a high level of preparation.
Cross-chain trail and money laundering
A key point in the investigation was the connection between both parts of the attack. I managed to establish that the cross-chain service Bridgers was used: its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions exactly in size and time. This leaves no doubt — we are dealing with a single operation.
As for laundering, about 79% of the stolen funds (~$6.4 million) passed through the exchanger FixedFloat, involving approximately 50 one-time addresses. Thanks to the prompt action of experts from Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — the hacker is likely waiting for the right moment to withdraw.
Strange behavior of the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the Coinsbuy team topped up the same compromised wallets with 3.93 million USDT. Seven transactions matched the stolen amounts to within 0.05%. This is highly illogical for a hack victim.
"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the researchers emphasize.
Initially, the damage was estimated at $7.9 million, but my detailed tally of individual transactions shows the exact figure — $8,073,992. The precise attack vector has not yet been established, and Coinsbuy is refraining from official comments.
My expert assessment: This incident is a vivid example of how cross-chain infrastructure becomes a weak link in security. The fact that the platform is topping up hacked addresses suggests a possible insider job or an error in smart contract logic, rather than a classic key theft. I recommend that Coinsbuy users immediately withdraw their funds and change all trusted addresses. Against the backdrop of recent attacks on Coldcard (with losses rising to $89 million), we are witnessing a worrying trend: hackers are increasingly exploiting trust in centralized and semi-centralized services.