cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Coinsbuy Hit by $8.07 Million Cross-Chain Attack

Coinsbuy Hit by $8.07 Million Cross-Chain Attack

Van Thanh Le

Van Thanh Le

PublishedAug 10 2026

UpdatedAug 11 2026

hace 5 horas3 minutes read
Coinsbuy Hit by $8.07 Million Cross-Chain Attack

Ethereum and TRON Wallets Drained as Funds Move Through Exchanges

TL;DR

  • Coinsbuy suffered a coordinated Aug. 9 attack across Ethereum and TRON, with the most detailed onchain reconstruction valuing the drain at $8.07 million.
  • The attacker linked activity across both networks through Bridgers and routed most of the stolen funds through FixedFloat.
  • Coinsbuy said the incident was contained, affected amounts were covered from company reserves and clients suffered no loss.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


Coinsbuy suffered a coordinated cross-chain security incident that drained assets from wallets on Ethereum and TRON on Aug. 9, 2026. The most detailed onchain reconstruction valued the loss at about $8.07 million, while PeckShield earlier estimated that Coinsbuy-linked wallets had “likely lost” roughly $7.9 million. The attack vector has not been established, and Coinsbuy later said affected amounts were covered from its own reserves.

Blockchain investigator Specter first flagged suspicious activity beginning at around 13:00 UTC that day. The attack started with a 5 USDT transaction before escalating into withdrawals from multiple wallets across both blockchains. The transaction sequence showed activity on Ethereum and TRON occurring as part of the same broader operation rather than as isolated movements.

Network or Flow Wallets or Addresses Assets and Amounts
TRON drain 8 wallets 6.04 million USDT
Ethereum drain 3 wallets 1.89 million USDT and 77 ETH
Stablecoin total explicitly identified Across both networks 7.93 million USDT
Receiving addresses identified 2 Ethereum addresses and 1 TRON address Stolen Coinsbuy assets

The Ethereum-side activity used a wallet created the same day and involved 1inch. Onchain records connected the two blockchain legs through Bridgers, a cross-chain swapper whose Ethereum payout contract sent funds directly into the Ethereum swap wallet. That connection allowed researchers to tie what appeared to be separate Ethereum and TRON movements to a single coordinated incident.

Investigators said the ability to move assets across separate networks could indicate access to wallet infrastructure or privileged credentials capable of authorizing transactions on multiple blockchains. There is no confirmation that Coinsbuy’s private keys were compromised. Researchers later pointed to the company’s rapid replenishment of the affected wallets as behavior suggesting Coinsbuy did not believe its private keys had been exposed.


We’ve launched the all-new COIN360 Perp DEX, built for traders who move fast!

Trade 130+ assets with up to 100× leverage, enjoy instant order placement and low-slippage swaps, and earn USDC passive yield while climbing the leaderboard. Your trades deserve more than speed — they deserve mastery.


Stolen Funds Split Across Exchanges and New Addresses

The attacker began dividing, swapping and redistributing the stolen assets after the drain. About 79% of the funds moved through FixedFloat using roughly 50 single-use addresses. PeckShield also identified ChangeNOW, FixedFloat and BingX among services that received portions of the stolen assets, while Specter reported that the attacker began converting some of the funds toward privacy-focused cryptocurrency Monero, or XMR.

ChangeNOW froze a six-figure portion of the assets after being contacted by Specter Investigations. ChangeNOW did not confirm a more precise amount. Separately, around 282 ETH worth roughly $542,000 remained unmoved across 5 addresses when the transaction trail was reviewed.

Coinsbuy suspended deposits and withdrawals after the drain and later restored the services, according to Specter. Within 24 hours, the company replenished the affected wallets to within 0.05% of their pre-attack balances. Researchers viewed that action as another indication that Coinsbuy did not consider the underlying private keys compromised, although the mechanism that allowed the unauthorized withdrawals remained unresolved.

Coinsbuy later said the incident had been “contained” and that “all affected amounts have been covered in full by the company from its own reserves.” The company added: “No client has borne any loss. The platform is stable and operating normally. Investigation is underway, and we cannot disclose further technical details at this stage.”

Coinsbuy’s statement clarified its position on the financial impact to customers but did not establish the technical cause of the breach. Earlier information said Coinsbuy had not explained how the attacker obtained authorization to move funds across multiple blockchains, while the company’s later response said its investigation was continuing.

Coinsbuy’s most recent listed software release before the incident was dated July 31 and included changes to administrative tools and withdrawal functionality. The release did not reference the later security incident, and the available information does not establish any connection between those software changes and the attack.

The attack came during a year in which roughly $972 million had already been stolen across the crypto sector through late July 2026. The Coinsbuy incident added another major cross-chain theft while leaving the precise method used to gain transaction authorization under investigation.

Coinsbuy Offers $100K Reward as Investigation Continues

Coinsbuy has now explicitly confirmed that unauthorized withdrawals affected several platform wallets during the Aug. 9 security incident. The company did not confirm or dispute the separately reported $7.9 million loss estimate, leaving the external estimate distinct from Coinsbuy’s own account of the breach.

Coinsbuy said it is investigating the incident and will withhold technical details until the investigation is complete and its findings have been verified. The statement adds a more specific timeline for when the company may release information about the attack mechanism, which remains under investigation.

Coinsbuy also announced a $100,000 reward for information that leads to the identification of those responsible for the breach. The company said an additional bonus is available for information or assistance that helps recover the stolen funds, although it did not give an amount for that separate incentive.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.13.12
© 2017 - 2026 COIN360.com. Todos los derechos reservados.