On August 9, 2026, crypto payment processor Coinsbuy was drained of approximately $7.9 million (reported by some outlets as roughly $8 million) in a coordinated attack that emptied hot wallets on both Tron and Ethereum within about an hour.
What happened
The attacker opened with a tiny 5 USDT test transaction, then moved to drain funds in parallel across two chains:
- On Tron, eight wallets were emptied of roughly 6.04 million USDT over the course of about an hour.
- On Ethereum, three wallets were simultaneously drained of 1.89 million USDT and 77 ETH.
On-chain analysts linked the two operations through the cross-chain swap service Bridgers, whose Ethereum payout contract fed directly into the Ethereum swap wallet — tying what looked like separate incidents into a single, coordinated event. Security firm GoPlus Security said the activity was "consistent with hot wallet private key or administrator privilege theft," rather than a smart-contract bug. There was no protocol exploit; the attacker simply controlled the keys.
Aftermath
Roughly $6.3–6.4 million of the haul was routed through the non-custodial swap service FixedFloat, then cycled through multiple exchanges and mixed into Monero (XMR) to obscure the trail. Coinsbuy stated publicly that no client funds were lost, indicating the firm absorbed the shortfall internally, and it offered a $100,000 reward for information leading to the attackers' identification, with an additional bonus for help recovering the stolen assets. As of reporting, the funds had not been recovered.
Why it matters
Coinsbuy is a reminder that the weakest link in a custodial crypto business is rarely the smart contract — it is the operational security around signing keys. Like the AFX Trade bridge key compromise weeks earlier in July 2026 and countless exchange hot-wallet thefts before it, this incident required no clever on-chain trickery: whoever holds the keys holds the funds. The rapid laundering pipeline — FixedFloat, then Monero — mirrors the standard playbook now used across private-key thefts, and shows why speed of detection and pre-arranged exchange freezes matter more than post-hoc forensics. For payment processors that keep large stablecoin balances in online wallets to service withdrawals, the lesson is old but unlearned: minimize hot-wallet balances, enforce hardware-backed multi-party signing, and monitor for the tell-tale small "test" transaction that so often precedes a full drain.
Sources & on-chain evidence
- [01]coindesk.comhttps://www.coindesk.com/business/2026/08/10/crypto-exchange-coinsbuy-loses-usd8-million-in-coordinated-two-blockchain-attack
- [02]decrypt.cohttps://decrypt.co/375213/hackers-drain-8-million-from-crypto-platform-coinsbuy
- [03]crowdfundinsider.comhttps://www.crowdfundinsider.com/2026/08/296116-coinsbuy-crypto-wallets-hit-by-cross-chain-drain-on-ethereum-and-tron-losses-near-8-million/
- [04]beincrypto.comhttps://beincrypto.com/coinsbuy-hack-crypto-august/