Crypto news

11.08.2026
06:22

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

On August 9, the crypto platform Coinsbuy was hit by a coordinated attack, resulting in the theft of $8.07 million. My analysis of on-chain data shows that the incident affected two of the largest networks simultaneously — TRON and Ethereum, indicating a high level of preparedness on the part of the attackers.

Timeline of the hack: from a test transaction to a large-scale withdrawal

The attack began with a small test transaction of 5 USDT on the TRON network — a classic technique for checking the functionality of withdrawal channels. Within an hour, 6.04 million USDT was withdrawn from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. In parallel, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. The funds were quickly converted via the decentralized protocol 1inch into 981.1 ETH sent to a wallet created that same hour.

The key evidence of a single operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions precisely in size and timing. This links both parts of the attack into a single chain.

Movement of funds and the platform's response

About 79% of the stolen assets passed through the exchange FixedFloat, where approximately 50 one-time addresses were used — a typical practice for obfuscating traces. After analysts at Specter Investigations reached out, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, offering hope for their recovery.

The most intriguing aspect is the behavior of the Coinsbuy team. Within 24 hours of the attack, the platform topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely unusual move.

"The money is still there. This only makes sense if the team does not believe there was a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.

Initially, the damage was estimated at $7.9 million, but my tally of individual transactions shows losses of $8,073,992. The exact attack vector has not yet been determined, and no official comments have come from Coinsbuy.

This incident serves as a reminder of the growing wave of hacker attacks: on July 31, 594.48 BTC (~$38.2 million) was stolen from Coldcard hardware wallet owners, and following subsequent waves, the total reached 1367 BTC (~$89 million).

My expert opinion: The replenishment of hacked addresses by the Coinsbuy team is either a sign of an internal error or an extremely risky strategy that may indicate the absence of actual key compromise. In any case, investors should exercise heightened caution when dealing with platforms that do not disclose details of security incidents.