Over $8 million was drained from the Coinsbuy crypto platform on August 9, 2026, in a double exploit that hit two blockchain networks simultaneously. The attack began on the Tron network with a test transaction of 5 USDT, as if the perpetrator was ensuring the door was open. Once the path was confirmed secure, the hacker immediately drained over 6 million USDT spread across eight operational wallets belonging to Coinsbuy.
The exploit did not stop at one chain. On the Ethereum network, the attacker maneuvered again to increase their haul, draining 1.89 million USDT along with 77 ETH from three additional wallets. Security analysts from BlockWatchdog quickly traced these cross-network transactions and concluded that the incidents on Tron and Ethereum were driven by the same attacking entity. The perpetrator utilized a cross-chain swap service called Bridgers to link their actions and smooth the outflow of funds without interruption.
Escape Route of the Funds and What Was Left Behind
After the funds were removed from Coinsbuy’s vaults, the hacker split their escape routes to launder the stolen proceeds. Approximately $6.34 million - equivalent to 79% of the total drained funds - was quickly moved through the FixedFloat crypto exchange. On another path, the perpetrator was recorded sending 150 ETH through the ChangeNOW platform.
Although most of the money has changed hands, on-chain tracking shows the perpetrator left a small trace behind. To date, a balance of 282.2 ETH worth approximately $542,000 remains idle and untouched by the attacker, spread across five different wallet addresses.
On the victim’s side, Coinsbuy’s management acted swiftly to prevent panic. They replenished the affected wallets using internal cash reserves, with around $3.93 million returned directly to the ten addresses targeted in the hack. “All affected client funds have been fully covered by Coinsbuy from our own reserves; users have suffered no financial loss,” a representative of the exchange stated. Alongside the recovery of customer funds, Coinsbuy is now offering a $100,000 bounty for anyone who can provide information to identify the perpetrator.
Identifying the System’s Weak Point
To date, the attack vector exploited by the hacker has not been disclosed as the internal investigation is still ongoing. However, BlockWatchdog’s findings provide a strong clue regarding the perpetrator’s modus operandi: the hacker likely gained access to Coinsbuy’s withdrawal system rather than hacking the wallets’ private keys. This conclusion is reinforced by the fact that Coinsbuy continues to use and replenish the exact same wallets after the attack occurred. If the private keys had been leaked, those wallets would have surely been discarded.
BlockWatchdog’s tracking also confirmed that there is no overlap in addresses between this hacker and the perpetrator of the Triple-A crypto platform exploit on July 24, indicating that the incidents are separate.
The Coinsbuy hack adds to a long list of security incidents in 2026. The DeFi sector and crypto platforms continue to be battered by a wave of thefts; over $840 million was lost to hackers in the first five months of this year, followed by an additional $110 million in losses throughout July alone. Amidst deteriorating security trends, many platforms choose to wash their hands or go bankrupt when exploited. Coinsbuy’s decision to cover the full losses from its own reserves stands as an anomaly - proving that for some entities, client trust is worth far more than the lost funds.
Reported by Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




