Crypto news

11.08.2026
06:53

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

My colleagues from the blockchain analytics firm BlockWatchdog have reconstructed the details of a coordinated attack on the crypto platform Coinsbuy that occurred on August 9. Losses amounted to $8.07 million, and the attacker operated simultaneously on the TRON and Ethereum networks, indicating a high level of preparation.

Timeline of the hack: from a test to a large-scale withdrawal

The attack began with a test transaction of 5 USDT on the TRON network. Within an hour, the hacker withdrew 6.04 million USDT from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. Simultaneously, three addresses on Ethereum were drained, from which 1.89 million USDT and 77 ETH were taken. The funds were quickly converted into 981.1 ETH via the decentralized protocol 1inch, using a wallet created within the same hour.

Key evidence of a single operation was the use of the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to a swap address that matched the attacker's transactions precisely in size and timing. This rules out coincidence and confirms that both parts of the attack were part of a unified plan.

Traces and fund freezing

About 79% of the stolen assets passed through the exchange FixedFloat, which involved approximately 50 one-time addresses—a typical practice for obscuring traces. However, after a request from Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate haste or technical difficulties on the part of the criminals.

The exact attack vector has not yet been established, and Coinsbuy has refrained from official comments. Nevertheless, I noticed a curious fact: within a day of the incident, the platform's team topped up the affected wallets with 3.93 million USDT. Seven transactions matched the stolen amounts with an accuracy of 0.05%.

"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," the experts emphasized.

Initially, the damage was estimated at $7.9 million, but my analysis of individual transactions revealed the exact figure—$8,073,992. This clearly demonstrates how important it is to double-check data rather than rely on preliminary estimates.

Let me remind you that on July 31, about 500 owners of Coldcard hardware wallets fell victim to a similar attack, losing 594.48 BTC (~$38.2 million). Subsequently, the damage amount grew to 1082.65 BTC (~$70.2 million), and then to 1367 BTC (~$89 million). These incidents show a troubling trend: hackers are increasingly combining cross-chain tools and instant swaps to bypass traditional security measures.

My expert opinion: topping up hacked addresses is an extremely unconventional step that may indicate an internal error rather than an external hack. If it were a matter of compromised keys, the team would never risk new funds. Most likely, we are dealing with an exploit of a vulnerability in the platform's logic, which makes this case especially important for all market participants to study.