Crypto news

11.08.2026
07:48

Attack on Coinsbuy: how hackers withdrew $8 million via TRON and Ethereum

social network hacking

My analysis of on-chain data shows that the crypto platform Coinsbuy lost $8.07 million as a result of a sophisticated coordinated attack carried out on August 9 simultaneously on the TRON and Ethereum networks. This is not a random incident, but a carefully planned operation that reveals vulnerabilities in liquidity management on centralized platforms.

Timeline of the hack

The attacker acted methodically. Starting with a test transfer of 5 USDT on the TRON network, he withdrew 6.04 million USDT from eight wallets within an hour. The largest operation amounted to about 3.5 million USDT—this is a classic pattern where the attacker first checks the system's reaction and then delivers a massive strike.

Simultaneously, three addresses on Ethereum were drained, from which 1.89 million USDT and 77 ETH were taken. Notably, the funds were converted into 981.1 ETH through the decentralized aggregator 1inch, with the swap wallet created within the same hour. This indicates a high level of preparation and the use of automated tools for instant liquidity.

Key clue—cross-chain bridge

The link between the two parts of the attack was the cross-chain service Bridgers. Its payout contract on Ethereum sent amounts to the swap wallet that exactly matched the attacker's transactions in size and timing. This is not a coincidence, but a clear sign of a single operation uniting two networks.

Movement of stolen funds

About 79% of the stolen assets passed through the exchanger FixedFloat, where approximately 50 one-time addresses were used—a typical practice for obscuring traces. However, some funds were partially frozen: ChangeNOW, after a request from Specter Investigations, blocked 150 ETH (about $288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, indicating possible haste or inexperience among some group members.

Strange behavior of the Coinsbuy team

The most intriguing moment is the platform's reaction. Within 24 hours of the attack, the team replenished the affected wallets with 3.93 million USDT, with seven transactions matching the stolen amounts to within 0.05%. Experts rightly note: "The money is still there. This only makes sense if the team does not believe in a private key leak. The address is the key: no one tops up a hacked wallet with seven-figure sums twice in one night."

Analyst conclusions

The exact attack vector remains unclear, and Coinsbuy refrains from official comments. However, I see a troubling signal here for the entire industry: if the team itself is not sure about key compromise, this could point to an internal threat or an exploit at the API level. In the context of recent incidents—such as the theft of 1367 BTC from Coldcard owners worth $89 million—it becomes obvious that hackers adapt faster than platforms strengthen their defenses. I recommend that users diversify asset storage and avoid keeping large sums on centralized services without additional security measures.