Crypto news

10.08.2026
19:53

Attack on Coinsbuy: detailed analysis of the $8 million theft in TRON and Ethereum networks

social network hacking

The crypto platform Coinsbuy faced a large-scale coordinated attack, resulting in $8.07 million being withdrawn from the TRON and Ethereum networks on August 9. My analysis of on-chain data, conducted jointly with blockchain researchers, allows us to reconstruct the full picture of the incident.

Timeline and scale of the hack

The attacker acted methodically, starting with a test transaction of 5 USDT on the TRON network. Within an hour, a series of withdrawals followed: 6.04 million USDT was stolen from eight wallets, with the largest single transfer amounting to about 3.5 million USDT. Simultaneously, the hacker drained three addresses on Ethereum, taking 1.89 million USDT and 77 ETH. Notably, all funds were converted into 981.1 ETH through the decentralized protocol 1inch, with the swap wallet created within the same hour, indicating thorough preparation.

Key clue — cross-chain bridge

On-chain analysis revealed a connection between both parts of the attack through the Bridgers service. The payout contract of this cross-chain bridge on Ethereum sent amounts to the swap wallet that matched the attacker's transactions precisely in size and time. This allows us to assert with high confidence that we are dealing with a single operation, not disparate incidents.

Movement of stolen funds

About 79% of the stolen assets passed through the exchange FixedFloat, for which the attacker used approximately 50 one-time addresses — a classic scheme for obscuring traces. Thanks to the prompt appeal by Specter Investigations, the service ChangeNOW froze 150 ETH (~$288,000). Another 282 ETH (~$542,000) remain untouched across five addresses, which may indicate either haste or an intention to use them later.

Anomaly: replenishment of hacked wallets

The most intriguing aspect is the behavior of the Coinsbuy team. Within 24 hours after the attack, 3.93 million USDT was deposited into the affected addresses, with seven transactions matching the stolen amounts to within 0.05%. This is an extremely illogical action, unless the team is confident there is no leak of private keys. As experts rightly note, no one tops up a hacked wallet with seven-figure sums twice in one night — the address here serves as the key to the puzzle.

Initially, the damage was estimated at $7.9 million, but my detailed calculation of individual transactions shows a more accurate figure — $8,073,992. For context: this is comparable to the recent series of attacks on Coldcard owners, where losses reached 1367 BTC (~$89 million), highlighting the systemic vulnerability of the crypto industry to targeted hacks.

My verdict: This incident demonstrates the evolution of hacker tactics — the use of cross-chain bridges and decentralized exchanges for instant money laundering. However, the anomalous replenishment of wallets suggests this may not be just a theft, but an internal key management error or even a staged event. I recommend market participants review their security protocols, especially regarding the storage of large sums on hot wallets.