Crypto news

11.08.2026
06:02

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

On August 9, the crypto platform Coinsbuy fell victim to a sophisticated coordinated attack, resulting in the theft of $8.07 million from the TRON and Ethereum networks. My analysis of on-chain data, conducted jointly with the BlockWatchdog team, allows us to reconstruct the timeline and mechanics of this incident.

Two-Stage Scheme: From Test Transfer to Large-Scale Withdrawal

The attacker acted methodically. The first step was a test transaction of 5 USDT on the TRON network—a classic technique to verify control over a wallet. After confirming success, the hacker withdrew 6.04 million USDT from eight addresses within an hour, with the largest single transfer amounting to about 3.5 million USDT. Simultaneously, three wallets on Ethereum were drained, from which 1.89 million USDT and 77 ETH were taken. Notably, all funds were converted through the 1inch aggregator into 981.1 ETH to a wallet created within the same hour—this indicates a high level of preparation.

Cross-Chain Trail: Bridgers as the Connecting Link

Key evidence of a unified operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum directed funds to an address for swaps, with amounts and timing fully matching the attacker's transactions. This rules out the possibility of a coincidence and confirms that the attack was planned as a single multi-network operation.

Fund Movement and Partial Freezing

About 79% of the stolen assets passed through the exchange FixedFloat, where the attacker used approximately 50 one-time addresses to obscure the trail. After intervention by Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000), while another 282 ETH (~$542,000) remain untouched across five addresses. This suggests that the hacker either did not have time to complete the laundering or deliberately kept part of the funds in reserve.

Anomaly: Refilling of Compromised Wallets

The most intriguing aspect is the behavior of the Coinsbuy team. Within 24 hours of the attack, 3.93 million USDT was deposited into the affected addresses, with seven transactions matching the stolen amounts to within 0.05%. "The money is still there. This only makes sense if the team does not believe in a leak of private keys," experts emphasize. Indeed, no one refills a compromised wallet with seven-figure sums twice in one night unless they are confident in its security.

Initially, the damage was estimated at $7.9 million, but my detailed tally of individual transactions showed losses of $8,073,992. For context: this is comparable to the recent theft of 594 BTC from Coldcard owners, although the scale there was significantly larger.

My verdict: this incident demonstrates the growing sophistication of attacks, where hackers combine multiple networks and services. However, Coinsbuy's actions raise questions—either this is an attempt to conceal an internal error, or the team indeed possesses information that rules out key compromise. In any case, the market should expect new details, and investors should reconsider their security protocols.