Crypto exchange Coinsbuy suffered losses exceeding $8 million after attackers exploited its accounts across the TRON and Ethereum blockchains on August 9, according to on-chain transaction records and an investigation into the incident.
The attack began with a small transfer of 5 USDT before rapidly escalating. Within about an hour, the attacker drained approximately $6.04 million in stablecoins from eight wallets on the TRON network. The operation was followed by additional transactions on Ethereum involving around $1.89 million in USDT and 77 ETH from three wallets.
The stolen assets on Ethereum were quickly converted into ETH through the 1inch wallet, making the movement of funds more complex and increasing the number of addresses and services involved in tracing the stolen cryptocurrency.
The attack resulted in more than $8 million in assets being drained across TRON and Ethereum, with investigators subsequently tracing the funds through cross-chain and instant-exchange services.
Investigators Link TRON and Ethereum Transactions
On-chain investigators identified a connection between activity on the two networks through a cross-chain swapping service known as Bridgers. Transaction records indicated that the service used an Ethereum payment contract to send funds directly to an Ethereum swap wallet associated with the attacker.
This link helped investigators connect transactions that initially appeared to involve separate operations on different blockchains. The discovery illustrates how attackers can move assets between networks and services in an effort to complicate investigations and obscure the movement of stolen funds.
The attacker subsequently transferred about 79% of the stolen cryptocurrency through the instant exchange FixedFloat, using roughly 50 different wallets. Investigators also notified ChangeNOW about the stolen funds, resulting in the freezing of a six-figure amount.
Around 282 ETH, valued at approximately $542,000 at the time of the report, remained untouched across five accounts. Investigators continued monitoring those addresses for further movement.
Coinsbuy Replenishes Affected Accounts
Within 24 hours of the attack, Coinsbuy had replenished the affected accounts to within 0.05% of their previous balances. The rapid restoration was viewed as an indication that the attackers may not have obtained the private keys associated with the wallets.
However, the precise attack vector had not been established. Determining how the attackers gained the ability to transfer the funds remains a key part of the investigation, particularly because the movement of assets across multiple wallets and blockchain networks could have involved a vulnerability or compromised access mechanism.
Coinsbuy said its customers had not suffered losses and that the platform remained stable and operational while the investigation continued. The exchange also indicated that it was withholding additional technical information while investigators worked to determine the circumstances of the breach.
Coinsbuy has offered a reward of up to $100,000 for information leading to the identification of those responsible, with an additional reward available if the stolen funds are recovered.
🔴 COINSBUY — $8.07M drained
Coinsbuy refilled the wallets it was robbed from. 12 hours later $3.93M went back into the same ten addresses — seven matched to within 0.05% of each loss. It is still sitting there.
That only makes sense if the team does not believe the private…
— BlockWatchdog (@BlockWatchdog) August 10, 2026
Crypto Security Risks Remain Elevated
The Coinsbuy incident comes amid a broader rise in cryptocurrency security breaches. Blockchain security data has indicated that crypto-related losses reached about $1 billion during the first half of 2026, while the sector recorded its highest number of hacks for a six-month period.
Ethereum and Solana accounted for the largest reported losses among blockchain networks during that period. Ethereum-related attacks resulted in approximately $332 million in losses, while Solana-based incidents accounted for about $326 million.
The causes differed between the two networks. Ethereum losses were largely linked to code exploitation, while attacks involving Solana were associated with compromised keys and signing infrastructure.
The Coinsbuy breach highlights the growing complexity of attacks involving multiple blockchains and financial services. Moving stolen assets through cross-chain systems, decentralized wallets and instant exchanges can create additional challenges for investigators seeking to freeze funds.
For exchanges, the incident also underscores the importance of wallet security, transaction monitoring and rapid coordination with blockchain analytics firms and other crypto service providers. Coinsbuy’s decision to replenish affected accounts and offer a substantial recovery reward indicates that the exchange is seeking to contain the financial and operational impact while the investigation proceeds.
The case remains unresolved, with the method used to gain unauthorized control of the affected wallets still unknown and some stolen funds continuing to sit in monitored addresses.







