Coinsbuy Suffers Significant $7.9M Drain Across Ethereum and TRON

Coinsbuy Suffers Significant $7.9M Drain Across Ethereum and TRON
Table of Contents

TL;DR:

  • Coinsbuy suffered a drain of over $7.9 million distributed across wallets on Ethereum and TRON.
  • The attacker began converting the stolen funds into Monero, a privacy cryptocurrency that makes on-chain tracing significantly more difficult.
  • ChangeNOW managed to freeze a six-figure portion before the funds were moved, though the exact amount was not officially confirmed.

The crypto payment processor Coinsbuy fell victim to an attack that drained over $7.9 million from its wallets on Ethereum and TRON on August 9, 2026, at around 13:00 UTC. The blockchain investigator known as Specter was the first to detect the suspicious activity, while security firm PeckShield later estimated the losses and identified ChangeNOW, FixedFloat, and BingX as services that received portions of the stolen funds.

Investigators identified two addresses on Ethereum and one on TRON linked to the receipt of the stolen assets. The attacker’s ability to drain funds across two networks simultaneously suggests they may have accessed wallet infrastructure or privileged credentials with authorization to execute transactions across multiple blockchains. However, there is no confirmation that Coinsbuy’s private keys were compromised.

The Money Trail: from Ethereum and TRON to Monero

The stolen assets included ETH and USDT. Before being converted, they were split across multiple wallets and sent through various services. The operations follow a pattern designed to hinder fund tracking. The attacker subsequently began to convert the assets into Monero, a privacy cryptocurrency that makes tracing considerably more difficult once funds leave transparent blockchains like Ethereum and TRON. ChangeNOW reported having frozen a six-figure portion of the total before it continued moving, though the exact amount was not confirmed.

Coinsbuy exploit

Coinsbuy: Questions That Remain Unanswered

According to Specter, Coinsbuy suspended deposits and withdrawals following the incident and later restored services, yet the platform has not published a technical report or forensic analysis of the attack. The most recent software version recorded by the company dates to July 31 and introduces changes to administrative tools and withdrawal functionality, but makes no reference to the incident.

Coinsbuy has also not clarified whether the $7.9 million corresponds to company funds, customer funds, or a combination of both, nor has it announced a reimbursement plan or explained how the attacker obtained authorization to move assets across multiple blockchains.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews