Skip to content
Est. MMXXVIVol. VI · № 321RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 318Private Key Compromise

Coinsbuy Cross-Chain Hot-Wallet Drain

Attackers drained roughly $7.9M in USDT and ETH from crypto payment processor Coinsbuy across Tron and Ethereum in a coordinated hot-wallet key compromise.

Date
Victim
Coinsbuy
Chain(s)
Status
Funds Stolen

On August 9, 2026, crypto payment processor Coinsbuy was drained of approximately $7.9 million (reported by some outlets as roughly $8 million) in a coordinated attack that emptied hot wallets on both Tron and Ethereum within about an hour.

What happened

The attacker opened with a tiny 5 USDT test transaction, then moved to drain funds in parallel across two chains:

  • On Tron, eight wallets were emptied of roughly 6.04 million USDT over the course of about an hour.
  • On Ethereum, three wallets were simultaneously drained of 1.89 million USDT and 77 ETH.

On-chain analysts linked the two operations through the cross-chain swap service Bridgers, whose Ethereum payout contract fed directly into the Ethereum swap wallet — tying what looked like separate incidents into a single, coordinated event. Security firm GoPlus Security said the activity was "consistent with hot wallet private key or administrator privilege theft," rather than a smart-contract bug. There was no protocol exploit; the attacker simply controlled the keys.

Aftermath

Roughly $6.3–6.4 million of the haul was routed through the non-custodial swap service FixedFloat, then cycled through multiple exchanges and mixed into Monero (XMR) to obscure the trail. Coinsbuy stated publicly that no client funds were lost, indicating the firm absorbed the shortfall internally, and it offered a $100,000 reward for information leading to the attackers' identification, with an additional bonus for help recovering the stolen assets. As of reporting, the funds had not been recovered.

Why it matters

Coinsbuy is a reminder that the weakest link in a custodial crypto business is rarely the smart contract — it is the operational security around signing keys. Like the AFX Trade bridge key compromise weeks earlier in July 2026 and countless exchange hot-wallet thefts before it, this incident required no clever on-chain trickery: whoever holds the keys holds the funds. The rapid laundering pipeline — FixedFloat, then Monero — mirrors the standard playbook now used across private-key thefts, and shows why speed of detection and pre-arranged exchange freezes matter more than post-hoc forensics. For payment processors that keep large stablecoin balances in online wallets to service withdrawals, the lesson is old but unlearned: minimize hot-wallet balances, enforce hardware-backed multi-party signing, and monitor for the tell-tale small "test" transaction that so often precedes a full drain.

Sources & on-chain evidence

  1. [01]coindesk.comhttps://www.coindesk.com/business/2026/08/10/crypto-exchange-coinsbuy-loses-usd8-million-in-coordinated-two-blockchain-attack
  2. [02]decrypt.cohttps://decrypt.co/375213/hackers-drain-8-million-from-crypto-platform-coinsbuy
  3. [03]crowdfundinsider.comhttps://www.crowdfundinsider.com/2026/08/296116-coinsbuy-crypto-wallets-hit-by-cross-chain-drain-on-ethereum-and-tron-losses-near-8-million/
  4. [04]beincrypto.comhttps://beincrypto.com/coinsbuy-hack-crypto-august/

Related filings