Coinsbuy Suffers $8M Hack Across Tron and Ethereum
An attacker drained $8.07 million from Coinsbuy wallets on Tron and Ethereum, moving most funds through FixedFloat. Coinsbuy replenished the wallets, suggesting private keys may not be compromised, but the exact attack vector remains unknown.
Quick Take
Attacker drained $8.07M in USDT and ETH from Coinsbuy wallets across Tron and Ethereum.
$6.34M passed through FixedFloat; 282 ETH left untouched across five addresses.
Coinsbuy replenished drained wallets, indicating private keys likely weren’t compromised.
Exact attack vector unknown; no overlap with July’s Triple-A hacker.
Market Impact Analysis
BearishSecurity incident at a crypto exchange raises concerns about platform vulnerabilities.
Speculation Analysis
Key Takeaways
- Attacker drained $8.07M in USDT and ETH from Coinsbuy wallets across Tron and Ethereum.
- $6.34M passed through FixedFloat; 282 ETH left untouched across five addresses.
- Coinsbuy replenished drained wallets, indicating private keys likely weren’t compromised.
- Exact attack vector unknown; no overlap with July’s Triple-A hacker.
What Happened
On August 9, an attacker siphoned $8.07 million from Coinsbuy wallets on Tron and Ethereum. The theft began with a small test transaction on Tron, then rapidly drained 6 million USDT from eight wallets. Simultaneously, 1.89 million USDT and 77 ETH were taken from three Ethereum wallets. The attacker moved most funds through cross-chain services and exchanges, with $6.34 million passing through FixedFloat. Coinsbuy responded within hours by refilling the affected wallets.
The Numbers
The hack netted $8.07M: 6M USDT from Tron, 1.89M USDT and 77 ETH from Ethereum. $6.34M (79%) moved through FixedFloat; another 150 ETH through ChangeNOW. 282 ETH ($542K at the time) sat untouched in five addresses. Coinsbuy returned roughly $3.93M to the same wallets, with deposits matching original amounts within 0.05%.
Why It Happened
The attack vector remains unknown, but blockchain investigator BlockWatchdog suggests the attacker may have breached Coinsbuy’s withdrawal system rather than stealing private keys. Coinsbuy’s decision to refill drained wallets indicates confidence that the keys weren’t compromised. There’s no overlap with previous hackers, and laundering patterns differ from the July 24 Triple-A exploit. The exchange has yet to publicly disclose details.
Broader Impact
The Coinsbuy incident adds to a brutal year for crypto security. DeFi protocols lost over $840 million in the first five months of 2026 alone. With high-profile exploits like AFX Trade ($24M) and Ostium ($18M) recently, the industry faces mounting pressure to tighten security. This event underscores persistent vulnerabilities at centralized exchanges.
What to Watch Next
- Monitor Coinsbuy’s official statement for details on the attack vector and security upgrades.
- Track on-chain movements of remaining stolen funds, especially the untouched ETH.
- Watch for potential regulatory scrutiny or user compensation plans.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.