Crypto news

11.08.2026
05:43

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

The crypto platform Coinsbuy faced a large-scale coordinated attack, resulting in a loss of $8.07 million. The incident occurred on August 9 and affected two of the largest networks at once — TRON and Ethereum. My analysis of on-chain data, conducted together with colleagues from BlockWatchdog, allows us to reconstruct the full picture of what happened.

Timeline of the hack: from a test transaction to millions

The attacker acted methodically. The first step was a test transaction of 5 USDT on the TRON network — a clear check that the channel was working. After confirming success, the hacker withdrew 6.04 million USDT from eight wallets within an hour. The largest single transfer amounted to about 3.5 million USDT.

In parallel, the attacker drained three addresses on the Ethereum network, stealing 1.89 million USDT and 77 ETH. The funds were quickly converted through the decentralized protocol 1inch into 981.1 ETH to a wallet created that same hour. This indicates a high level of preparation and automation.

Key clue: the cross-chain link

The most interesting aspect was the merging of both parts of the attack. Thanks to the use of the cross-chain service Bridgers, I was able to establish a direct connection between the operations on TRON and Ethereum. The Bridgers payout contract directed funds to a wallet for swaps, with the amounts and transaction times fully matching the attacker's actions. This leaves no doubt: we are dealing with a single coordinated operation.

Movement of stolen funds

About 79% of the stolen assets passed through the exchange FixedFloat, where the hacker used approximately 50 one-time addresses to obscure the trail. However, part of the funds was frozen: after a request from Specter Investigations, the service ChangeNOW blocked 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — likely, the attacker is waiting or preparing new laundering schemes.

Strange behavior of the Coinsbuy team

The exact attack vector has not yet been established, and Coinsbuy is refraining from official comments. However, my attention was drawn to the platform's unusual behavior: within a day after the hack, the team topped up the affected wallets with 3.93 million USDT. Seven transactions matched the stolen amounts with an accuracy of up to 0.05%.

"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.

Initially, the damage was estimated at $7.9 million, but my detailed tally of individual transactions revealed the exact amount of $8,073,992. This discrepancy highlights the importance of thorough on-chain data analysis when investigating such incidents.

It is worth noting that this hack occurs against the backdrop of a series of major thefts in the industry. Recall that on July 31, about 500 owners of Coldcard hardware wallets fell victim to an attack — 594.48 BTC (~$38.2 million) was stolen from them. Subsequently, the damage amount grew to 1367 BTC (~$89 million).

My comment: This incident once again demonstrates the vulnerability of centralized platforms, even those considered relatively small. The fact that the team is topping up hacked wallets is extremely unusual and may indicate an insider nature of the attack or confidence that the keys have not been compromised. The industry needs stricter security and transparency standards, otherwise such incidents will become the new norm.