Coinsbuy Loses $8 Million in Coordinated TRON-Ethereum Attack

Key Points
- Attacker drained $8.07 million from Coinsbuy on August 9 across TRON and Ethereum blockchains within one hour.
- Eight TRON wallets lost 6.04 million USDT while three Ethereum wallets lost 1.89 million USDT and 77 ETH in the same attack.
- Approximately 79% of stolen funds moved through instant exchange FixedFloat using roughly 50 single-use addresses; attack vector remains unknown.
Onchain records show the attacker linked both blockchains through Bridgers, a cross-chain swapper whose Ethereum payout contract sent funds directly into the Ethereum swap wallet, connecting what appeared as separate operations into a unified incident. The wallet used for Ethereum swaps was created the same day as the attack, and funds were swapped to ETH via 1inch.
Approximately 79% of the stolen funds moved through instant exchange FixedFloat using roughly 50 single-use addresses designed to obscure the trail. ChangeNOW separately froze a six-figure sum after being contacted by Specter Investigations. Around 282 ETH, worth roughly $542,000, across five addresses has not moved since the attack.
Read Next

Brent Crude Rises 1.09% to $84.46 Amid Iran-U.S. Strait Deal Uncertainty
10 hours ago

Bitcoin BIP-110 Fork Dies After Mining Just 2 Blocks in 8 Hours
18 hours ago
Coinsbuy refilled the drained wallets within 24 hours to within 0.05% of their pre-attack balances, a response pattern that blockchain researchers say indicates the exchange team does not believe private keys were compromised. However, Coinsbuy has not issued a public statement and has not explained how the attacker accessed the withdrawal path. The attack vector remains unknown.
The incident adds to a costly year for the cryptocurrency industry, which had already seen roughly $972 million stolen across the sector through late July. CoinDesk has emailed Coinsbuy requesting comment.
Related coverage: Brent Crude Rises 1.09% to $84.46 Amid Iran-U.S. Strait Deal Uncertainty
The restoration speed and near-complete recovery suggest Coinsbuy possessed redundant access to the drained wallets, implying the breach was limited to operational systems rather than core cryptographic material. If $8 million represents a single day's operational liquidity held in hot wallets—as the quick restoration suggests—the broader risk to Coinsbuy's customer deposits may be contained, though the unknown attack vector poses ongoing risk across the exchange's infrastructure.
Related Guide: Read our complete guide →
Market Outlook
The unknown attack vector may indicate a vulnerability in Coinsbuy's withdrawal authorization system rather than compromised private keys. If forensic analysis identifies a shared infrastructure flaw affecting other exchanges, additional coordinated attacks across multiple platforms using the same technique could emerge within weeks, potentially totaling tens of millions in aggregate losses before patches are deployed industry-wide.
Sources: CoinDesk and other international news outlets.
Disclaimer: This article was produced with AI assistance based on publicly available news sources. While we strive for accuracy, NewsOracle makes no warranty as to the completeness or accuracy of the information. Errors and omissions may occur. Readers should independently verify all information before acting on it. NewsOracle does not intend to defame any individual or organisation and accepts no liability for any loss or damage arising from reliance on this content. Content is for informational purposes only and does not constitute legal, financial, medical, or professional advice. All rights reserved. Unauthorised reproduction prohibited.
NewsOracle Editorial
The NewsOracle Markets Desk covers stock markets, cryptocurrency, economic policy and breaking financial news from Wall Street and global exchanges.
Latest coverage: Crypto


