Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

The crypto platform Coinsbuy faced a large-scale coordinated attack, resulting in $8.07 million being withdrawn from the TRON and Ethereum networks on August 9. My analysis of on-chain data, conducted together with colleagues from BlockWatchdog, allowed me to reconstruct the timeline of the incident and trace the movement of funds.
The attack began with a test transaction of 5 USDT on the TRON network — a classic technique for checking the functionality of withdrawal channels. Then, within about an hour, the attacker drained eight wallets, withdrawing 6.04 million USDT. The largest single transfer amounted to about 3.5 million USDT. In parallel, the hacker attacked three addresses on Ethereum, stealing 1.89 million USDT and 77 ETH.
Cross-chain trail and fund conversion
Of particular interest is the conversion: the stolen assets were exchanged for 981.1 ETH via the decentralized protocol 1inch, with the swap wallet created in the same hour as the attack. The key link connecting both parts of the operation was the cross-chain service Bridgers — its payout contract on Ethereum directed funds to the exchange address, with transaction amounts and times fully matching the attacker's actions. This unequivocally points to a single coordinated operation, not disparate incidents.
The further movement of funds is also telling: about 79% of the stolen assets passed through the exchanger FixedFloat, for which approximately 50 one-time addresses were used — a typical scheme for obfuscating traces. Thanks to the prompt appeal from Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000), while another 282 ETH (~$542,000) remain untouched across five addresses.
Strange behavior of the Coinsbuy team
The exact attack vector has not yet been established, and Coinsbuy is refraining from official statements. However, my attention was drawn to a curious fact: within a day of the incident, the platform's team topped up the same affected wallets with 3.93 million USDT. Seven of these transactions matched the stolen amounts to within 0.05%.
"The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.
Initial damage estimates were $7.9 million, but my detailed tally of individual transactions shows a final amount of $8,073,992. This incident fits into an alarming trend: recall that in late July, about 500 owners fell victim to an attack on Coldcard hardware wallets, losing 594.48 BTC (~$38.2 million), with total damage subsequently growing to 1367 BTC (~$89 million).
My verdict: topping up compromised addresses is either a gross error in risk management or a signal that the incident has a different nature than key compromise. In any case, this case underscores the need for instant fund migration at the slightest suspicion of a hack — hesitation here costs millions.