Crypto exchange Coinsbuy lost more than $7.9 million after attackers drained wallets across the Ethereum and TRON networks in a coordinated attack that began around 13:00 UTC on August 9, according to on-chain investigators tracking the incident.
The simultaneous activity on two separate blockchains initially raised fears that hot-wallet private keys had been compromised. But Coinsbuy refilled the drained wallets within 24 hours of the attack, a response investigators say suggests the exchange’s core private keys remained secure and that the breach instead involved compromised administrative privileges or a flaw in the operational layer controlling withdrawals.
How the funds moved
Roughly 79% of the stolen assets were funneled through instant-swap service FixedFloat across 50 single-use addresses, a pattern designed to fragment the trail and frustrate tracing efforts. ChangeNOW managed to freeze a six-figure sum before it could be moved further, while roughly $542,000 in ether has yet to move from its original address, according to CoinDesk’s on-chain analysis of the incident. Blockchain researchers have since linked the Ethereum and TRON legs of the attack into a single operation via cross-chain swapper Bridgers.
Investigators say the attacker has begun converting a portion of the stolen funds into Monero, the privacy coin whose shielded ledger makes transactions far harder to trace once a conversion is complete — a common final step for hackers looking to cash out undetected.
Related: Tether Mints Another 1B USDT on Tron, Supply Tops 91 Billion
A vulnerability with a history
Coinsbuy’s infrastructure had already shown cracks a month before the exploit. On July 10, the exchange patched a bug that confirmed outbound transfers without properly verifying deposits received on its own nodes, a flaw that produced overstated balance locks and false insufficient-funds errors for users. That earlier issue doesn’t establish how this week’s attacker got in, but it points to broader complexity — and potential fragility — in how Coinsbuy’s transfer infrastructure is built.
Part of a costly year for exchanges
The Coinsbuy breach adds to what has already been a punishing year for crypto security. TRM Labs recorded 207 separate hacks and roughly $972 million in stolen funds industry-wide during the first half of 2026 alone, led by the $295 million Drift Protocol exploit — the largest single incident of the period. Investigators are now watching Coinsbuy’s on-chain footprint for signs the intrusion is fully contained: stable balances with no new attacker-linked wallets would suggest the exchange has shut the door, while fresh collector addresses would signal the withdrawal path is still exposed.