Crypto news

11.08.2026
07:28

Attack on Coinsbuy: how hackers withdrew $8 million in an hour and why the platform replenished the hacked wallets

social network hacking

The crypto platform Coinsbuy faced a large-scale coordinated attack, during which attackers withdrew $8.07 million from the TRON and Ethereum networks. The incident occurred on August 9, and my analysis of on-chain data allows me to reconstruct the full picture of what happened.

Timeline of the attack: from a test transaction to $8 million

The attacker acted methodically. Starting with a test transaction of 5 USDT on the TRON network, he emptied eight wallets within an hour, withdrawing 6.04 million USDT. The largest single transfer amounted to about 3.5 million USDT. Simultaneously, the hacker attacked three addresses on Ethereum, taking 1.89 million USDT and 77 ETH.

Of particular interest is the conversion of funds: through the decentralized protocol 1inch, the stolen assets were exchanged for 981.1 ETH. The wallet for swaps was created within the same hour, indicating thorough preparation.

Cross-chain trail: how both parts of the attack were linked

The key evidence of a single operation was the use of the cross-chain service Bridgers. My analysis shows that the payout contract on Ethereum directed funds to the swap wallet in amounts that matched the attacker's transactions in size and time. This rules out the possibility of a random coincidence.

The further movement of funds confirms the attacker's professionalism: about 79% of the stolen assets passed through the exchanger FixedFloat using approximately 50 one-time addresses. Thanks to the prompt intervention of the ChangeNOW service, 150 ETH (~$288,000) were frozen. Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate an attempt to avoid excessive attention.

Strange behavior of the Coinsbuy team

The most intriguing aspect is the platform's reaction. Within 24 hours of the attack, the team topped up the affected wallets with 3.93 million USDT. Seven transactions matched the stolen amounts to within 0.05%. This is highly unusual: no one in their right mind sends seven-figure sums to compromised addresses unless they are confident in their security.

"The money is still there. This only makes sense if the team does not believe in a leak of private keys. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night," experts emphasize.

Initially, the damage was estimated at $7.9 million, but my tally of individual transactions shows the exact amount — $8,073,992. The precise attack vector has not yet been established, and Coinsbuy refrains from official comments.

This incident fits into a worrying trend: let me remind you that on July 31, hackers stole 594.48 BTC (~$38.2 million) from owners of Coldcard hardware wallets, and then the damage amount grew to 1367 BTC (~$89 million).

My expert assessment: the behavior of the Coinsbuy team is a rare case in hacking practice. Usually, platforms freeze activity and conduct an audit, but here we see the opposite action. This could indicate an internal error rather than an external attack, or an attempt to cover up traces of the incident. Investors should be extremely cautious: such opacity is a red flag that requires immediate clarification from the platform.