Coinsbuy's $8M Cross-Chain Drain: When Wallets Refill, the Keys Weren't the Problem
An attacker emptied eleven Coinsbuy wallets across Tron and Ethereum in under an hour, then laundered the proceeds through an instant-swap service before the exchange quietly topped the wallets back up — a strong signal the breach sat in withdrawal logic, not key custody.
Key Takeaways
- Coinsbuy lost roughly $8.07M — 6.04M USDT from eight Tron wallets and 1.89M USDT plus 77 ETH from three Ethereum wallets — in under an hour on 9 August 2026.
- Coinsbuy replenished the drained wallets within 24 hours, which points away from stolen private keys and toward a flaw in withdrawal authorization or transaction-signing logic.
- About 79% of the stolen funds moved through instant-swap service FixedFloat across roughly 50 single-use addresses, a laundering pattern built to outrun exchange freeze requests.
- Coinsbuy has not disclosed the root cause, only that 'the vulnerability has been addressed' — leaving other custodians unable to check whether the same class of flaw applies to them.
What happened
On 9 August 2026, an attacker drained eight Tron wallets belonging to crypto platform Coinsbuy of 6.04 million USDT, and three Ethereum wallets of 1.89 million USDT plus 77 ETH — roughly $8.07 million combined — in under an hour. The operation opened with a 5 USDT test transfer before the main withdrawals, a common pattern for confirming a stolen or forged authorization path actually works before committing to the full drain.
Coinsbuy has said the vulnerability behind the theft has been addressed and no client funds were lost, and it refilled the affected wallets to roughly their pre-attack balances within 24 hours. That fast, voluntary top-up is the most telling detail in this incident: it strongly suggests the attacker did not obtain the wallets' private keys, but instead abused something in how withdrawals were authorized or executed.
Two chains, one operation
Blockchain researchers linked the Tron and Ethereum withdrawals into a single coordinated operation via cross-chain swapper Bridgers — the near-simultaneous, near-identical drains on unrelated networks are hard to explain as two independent incidents. That cross-chain coordination is itself a signal worth reading: whatever the attacker compromised gave them reach across both of Coinsbuy's chains at once, which points toward a shared control-plane weakness (an internal withdrawal service, a signing API, an operator credential) rather than a chain-specific bug.
The laundering playbook
Roughly 79% of the stolen funds were routed through the instant-exchange service FixedFloat, spread across about 50 single-use addresses — a structure designed to fragment the trail and get funds converted before compliance teams can act. Even so, ChangeNOW froze a six-figure sum after being contacted, and around $542,000 in ETH across five addresses has not moved. That partial recovery is consistent with what usually happens in these cases: instant-swap services without mandatory KYC give attackers a fast off-ramp, but a subset of counterparties will still cooperate with freeze requests if custodians move quickly.
The open question
Coinsbuy has not disclosed how the withdrawal path was actually accessed. For an incident this size, "the vulnerability has been addressed" without a root-cause statement is a weak signal for anyone else operating similar infrastructure — an API-key leak, a compromised signer, a logic flaw in withdrawal validation, and an insider path all call for different fixes, and only Coinsbuy currently knows which one applies. Coinsbuy also offered a $100,000 bounty for return of the funds, a now-familiar post-hack negotiating tactic that rarely recovers more than a fraction of what was taken.
What operators should take from this
- Wallet balances alone don't prove key security — a fast top-up after a drain is consistent with a workflow/authorization compromise, not a benign event.
- Cross-chain, near-simultaneous withdrawals from otherwise unrelated wallets are a strong indicator that a shared internal system, not a blockchain, was the entry point.
- Test transactions (small, odd-value transfers preceding a large drain) are a detectable precursor pattern worth alerting on before the main withdrawal executes.
- Relationships with instant-swap and exchange compliance teams for rapid freeze requests materially change how much of a stolen sum is recoverable.
Frequently Asked Questions
Were Coinsbuy user funds or private keys stolen?
Coinsbuy says no client suffered a loss, and it refilled the drained wallets within 24 hours to close to their pre-attack balances. That refill is a strong (though not conclusive) sign the attacker abused a withdrawal or authorization flaw rather than obtaining the wallets' private keys directly.
How did the attacker launder the stolen funds?
About 79% of the roughly $8.07 million was routed through the instant-swap service FixedFloat across around 50 single-use addresses. ChangeNOW froze a six-figure portion after being contacted, and roughly $542,000 in ETH has remained unmoved across five addresses.
Has Coinsbuy explained what caused the breach?
No. Coinsbuy has said the vulnerability has been addressed but has not disclosed the specific attack vector, so it isn't yet possible to say whether the root cause was a leaked credential, a compromised signing system, a logic flaw, or something else.
Sources
- 1Coinsbuy exploited for $8 million — Web3 Is Going Great
- 2Hackers Drain $8 Million From Crypto Exchange Across Two Blockchains — Decrypt
- 3Crypto Exchange Coinsbuy Loses $8 Million in Coordinated Two-Blockchain Attack — CoinDesk