Summary

  • A hacker siphoned off $8.07 million from Coinsbuy wallets on the Tron and Ethereum networks on August 9.
  • Approximately $6.34 million of the stolen assets were funneled through FixedFloat, as reported by BlockWatchdog.
  • Coinsbuy subsequently replenished the drained wallets, indicating that the private keys may not have been compromised.

A breach resulted in the theft of over $8 million from the cryptocurrency exchange Coinsbuy, affecting both the Tron and Ethereum blockchains, with most of the stolen funds quickly transferred, according to blockchain investigator BlockWatchdog.

BlockWatchdog detailed in a report shared on X that the attack initiated with a test transaction of 5 USDT on Tron, followed shortly by the draining of over 6 million USDT from eight wallets associated with Coinsbuy. On the Ethereum network, an additional 1.89 million USDT and 77 ETH were extracted from three wallets.

Through the use of the cross-chain swap service Bridgers, BlockWatchdog established a connection between the transactions on Tron and Ethereum, attributing them to the same attacker. The hacker subsequently moved approximately $6.34 million, representing 79% of the total stolen funds, via the FixedFloat cryptocurrency exchange, while another 150 ETH was transferred through ChangeNOW.

Additionally, BlockWatchdog reported that 282.2 ETH, valued at around $542,000 at the time of the incident, remained untouched across five different addresses.

Shortly after the theft, Coinsbuy restored the compromised wallets, with BlockWatchdog noting that approximately $3.93 million was returned to the same ten addresses, with seven of those deposits closely matching the original stolen amounts within a margin of 0.05%. BlockWatchdog commented, “That only makes sense if the team does not believe the private keys leaked. An address is a key: nobody tops up a compromised wallet with seven figures twice in one night. Whatever was taken over on 9 August sat above the keys—the withdrawal path that uses them.”

Though the method of the attack remains unclear, BlockWatchdog suggested that the hacker might have accessed Coinsbuy’s withdrawal system.

“Nothing on-chain shows how the withdrawal path was reached—the refill argues against key theft, it does not name what replaced it,” they stated. “No attribution either: zero address overlap with the Triple-A attacker of 24 July, and a different laundering habit.”

BlockWatchdog found no similarities in address usage with the attacker from the July 24 Triple-A hack and noted that the laundering techniques were different.

At the time of BlockWatchdog's analysis, Coinsbuy had not provided a public explanation regarding how the attacker gained access.

Coinsbuy has not yet responded to inquiries from Decrypt for further comments.

This incident occurs amidst a series of significant hacks targeting the cryptocurrency sector in recent months. DeFi protocols experienced losses exceeding $840 million due to hacks in the first five months of 2026, according to DeFiLlama's reports.

In July, a separate breach saw attackers steal $24 million from the Arbitrum-based AFX Trade after exploiting a bridge tied to the decentralized exchange. Earlier that same month, the decentralized exchange Ostium lost $18 million following an oracle key compromise.

Daily Debrief Newsletter

Stay updated with the latest news, features, podcasts, videos, and more.