In brief

  • An attacker drained $8.07 million from Coinsbuy wallets across Tron and Ethereum on August 9.
  • About $6.34 million of the stolen funds passed through FixedFloat, according to BlockWatchdog.
  • Coinsbuy later replenished the drained wallets, suggesting the private keys may not have been compromised.

An attacker drained more than $8 million from crypto platform Coinsbuy across the Tron and Ethereum networks on Sunday before moving most of the stolen funds, according to an analysis by blockchain investigator BlockWatchdog.

In a report posted on X, BlockWatchdog said the attack began on Tron with a 5 USDT test transaction. Minutes later, more than 6 million USDT was drained from eight Coinsbuy wallets. On Ethereum, another 1.89 million USDT and 77 ETH were taken from three wallets.

“On August 9, Coinsbuy identified a security incident that resulted in unauthorized withdrawals from several platform wallets,” Coinsbuy said in a statement shared with Decrypt. “The issue has since been contained, and our team acted immediately to secure the platform and protect our users.”

BlockWatchdog linked the Tron and Ethereum transactions to the same attacker through cross-chain swap service Bridgers. The attacker then moved about $6.34 million, or 79% of the stolen funds, through the FixedFloat cryptocurrency exchange. Another 150 ETH was sent through ChangeNOW.

According to BlockWatchdog, another 282.2 ETH, worth about $542,000 at the time of the attack, remained untouched across five addresses.

Hours after the theft, Coinsbuy replenished the affected wallets, with BlockWatchdog reporting that around $3.93 million was returned to the same 10 addresses, with seven deposits matching the amounts originally stolen to within 0.05%.

“All affected client funds have been fully covered by Coinsbuy from our own reserves, so our users have not experienced any financial losses,” Coinsbuy said. “The platform is back to operating normally, with all services fully available.”

According to BlockWatchdog, the decision to replenish the affected wallets suggests the team did not believe the underlying private keys had been compromised.

“That only makes sense if the team does not believe the private keys leaked,” BlockWatchdog wrote. “An address is a key: nobody tops up a compromised wallet with seven figures twice in one night. Whatever was taken over on 9 August sat above the keys—the withdrawal path that uses them.”

While the exact attack vector is unknown, BlockWatchdog said the attacker may have gained access to Coinsbuy’s withdrawal system.

“Nothing on-chain shows how the withdrawal path was reached—the refill argues against key theft, it does not name what replaced it,” they wrote. “No attribution either: zero address overlap with the Triple-A attacker of 24 July, and a different laundering habit.”

Coinsbuy had not publicly explained how the attacker gained access at the time but said the company is “conducting a thorough investigation to establish exactly what happened.”

“To support the investigation, we are also launching an initiative to catch those responsible for this incident—a $100,000 reward for information that leads to their identification,” Coinsbuy said. “An additional bonus will also be available for any assistance leading to the recovery of the stolen funds.”

The news comes amid a string of major crypto hacks in recent months. DeFi protocols lost more than $840 million to hacks in the first five months of 2026, according to DeFiLlama.

In July, attackers stole $24 million from Arbitrum-based AFX Trade after exploiting a bridge operated by the decentralized exchange. Earlier that month, decentralized exchange Ostium lost $18 million after an attacker compromised an oracle key.

Editor's note: This article was updated after publication to include comment from Coinsbuy.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.