Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

The crypto platform Coinsbuy faced a large-scale coordinated attack, resulting in a loss of $8.07 million. The incident occurred on August 9 and affected two of the largest networks at once — TRON and Ethereum. My analysis of on-chain data allows me to reconstruct the full picture of what happened.
Timeline of the hack: from a test transaction to mass withdrawals
The attacker acted methodically. It all started with a test transfer of 5 USDT on the TRON network — a classic technique for checking the functionality of channels. Then, within about an hour, 6.04 million USDT was withdrawn from eight wallets. The largest single transfer amounted to about 3.5 million USDT — this indicates well-thought-out logistics designed to avoid raising suspicion from monitoring systems.
In parallel, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. Notably, the funds were quickly swapped for 981.1 ETH via the decentralized protocol 1inch, with the swap wallet created within the same hour. This points to a high level of preparation and process automation.
The cross-chain trail: how both parts of the attack were linked
The key evidence of a single operation was the use of the cross-chain service Bridgers. The payout contract on Ethereum sent amounts to the swap wallet that matched the attacker's transactions precisely in size and time. Such correlation rules out coincidence — this is a classic money laundering scheme through cross-chain bridges.
About 79% of the stolen funds passed through the exchange FixedFloat, involving approximately 50 one-time addresses. This is a typical practice for obscuring traces. Thanks to the prompt intervention of Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses — the attacker may be waiting for the right moment to move them.
Strange behavior from the Coinsbuy team
The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the team topped up the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. This raises questions. As researchers emphasize, no one in their right mind would top up a hacked wallet with seven-figure sums twice in one night, unless the team is confident that the private keys have not been compromised.
Initially, the damage was reported as $7.9 million, but my detailed tally of individual transactions shows the exact figure — $8,073,992. The difference is explained by including all associated fees and intermediate transfers.
"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts noted.
Let me remind you that this is only part of a troubling trend. On July 31, about 500 owners of Coldcard hardware wallets fell victim to an attack, losing 594.48 BTC (~$38.2 million). Subsequently, the damage amount grew to 1082.65 BTC (~$70.2 million), and then to 1367 BTC (~$89 million). This demonstrates that even hardware solutions are not a panacea.
My conclusion: The Coinsbuy incident underscores the critical importance of multi-layered protection for hot wallets. The fact that the team continues to top up compromised addresses either indicates their confidence that there is no key leak, or a serious underestimation of the risks. In any case, the market needs more transparent security protocols and mandatory insurance for user funds.