Blockchain Security
Hackers Drain $8 Million From Crypto Exchange Across Two Blockchains
According to media reporting by LBank News based on a decrypt.co discovery page, an attacker drained $8.07 million from Coinsbuy wallets across Tron and Ethereum on August 9, while later wallet activity offers clues about how the breach occurred. This incident is currently not officially confirmed.

Overview of the Multi-Chain Incident
According to media reporting by LBank News referencing information from decrypt.co, a security breach on August 9 targeted digital asset platform Coinsbuy across the Tron and Ethereum blockchain networks. Blockchain investigator BlockWatchdog analyzed the transaction flows and reported that the attacker successfully drained approximately $8.07 million in digital assets from multiple platform wallets. This unauthorized activity involved sophisticated movements across different distributed ledgers, drawing immediate attention from security researchers and industry observers monitoring cross-chain transactions.
The reported sequence of events began on the Tron network, where the attacker reportedly initiated a small test transaction of five USDT before executing a much larger extraction. Within minutes of the initial test, more than six million USDT was systematically drained from eight distinct Coinsbuy wallets. Simultaneously, the security breach extended to the Ethereum network, where additional funds totaling 1.89 million USDT and 77 ETH were removed from three separate wallets, bringing the total estimated value of the initial unauthorized outflow to over eight million dollars.
Investigation and Fund Laundering Analysis
Blockchain investigator BlockWatchdog linked the disparate Tron and Ethereum transactions to the same underlying attacker by tracking interactions through the cross-chain swap service Bridgers. Following the extraction, the attacker initiated a complex laundering process to obscure the trail of the stolen capital. Reports indicate that approximately $6.34 million, representing about seventy-nine percent of the total stolen funds, was routed through the FixedFloat cryptocurrency exchange. An additional portion involving one hundred and fifty ether was subsequently channeled through the ChangeNOW service.
Further on-chain analysis conducted by security investigators revealed that not all of the stolen digital assets were immediately processed through mixing or laundering services. According to BlockWatchdog, another 282.2 ETH, which possessed a market value of approximately $542,000 at the precise time of the attack, remained untouched and stationary across five distinct addresses. This remaining reserve of unmovable funds provided investigators with additional data points to track the operational habits and distinct behaviors of the responsible entity compared to historical cyber attacks.
Platform Response and Financial Replenishment
In the wake of the security incident, Coinsbuy issued an official statement confirming that unauthorized withdrawals had affected several platform wallets on August 9. The platform emphasized that the security issue had been contained swiftly and that internal teams acted immediately to secure the infrastructure and protect client assets. Coinsbuy noted that all impacted client funds were fully covered from internal corporate reserves, ensuring that registered users experienced no direct financial losses as a result of the breach.
Hours after the initial theft occurred, Coinsbuy executed a full replenishment of the affected wallet addresses. BlockWatchdog reported that approximately $3.93 million was returned directly to the same ten addresses, with seven specific deposits matching the original stolen amounts to within a margin of 0.05 percent. This rapid capital injection and asset restoration set the incident apart from standard exchange hacks where users often face prolonged lockups or permanent losses before any recovery efforts materialize.
Private Key Status and Attack Vector Analysis
The decision by Coinsbuy to replenish the drained wallets with millions in capital provided critical forensic clues regarding the nature of the breach. BlockWatchdog observed that such a substantial financial top-up only aligns with a scenario where the underlying private keys remain secure and uncompromised. According to their assessment, nobody would logically replenish a structurally compromised wallet with seven-figure sums twice in a single night if the master cryptographic keys had fallen into the control of external malicious actors.
Security analysts concluded that the unauthorized activity likely bypassed the private keys by interacting directly with the platform's higher-level withdrawal routing mechanisms. Although the exact attack vector remained unconfirmed at the time of reporting, investigators noted that the on-chain evidence pointed toward an operational weakness in the withdrawal system rather than a foundational key compromise. Coinsbuy stated that a comprehensive internal investigation is currently underway to determine the exact sequence of events that enabled the extraction.
Broader Security Context and Industry Trends
The security incident involving Coinsbuy occurs against a backdrop of increasing cyber attacks targeting decentralized finance protocols and centralized trading platforms throughout the year. Data compiled by industry trackers indicates that decentralized protocols lost substantial sums exceeding hundreds of millions of dollars during the initial months of 2026. High-profile exploits involving cross-chain bridges and compromised oracle keys have continued to test the resilience of digital asset infrastructure across multiple blockchain networks.
Recent months have witnessed several comparable multi-million-dollar breaches affecting trading venues and bridge operators, reflecting persistent threats from sophisticated attacker groups. Platforms across the ecosystem have responded by enhancing their monitoring frameworks, upgrading multi-signature security arrangements, and offering substantial bounties for actionable intelligence. These industry-wide defensive upgrades demonstrate a concerted effort to mitigate recurring vulnerabilities associated with automated withdrawal pathways and third-party integrations.
Conclusion and Action Plan for Stakeholders
In conclusion, media reporting from LBank News and decrypt.co details an unauthorized extraction of $8.07 million from Coinsbuy across the Tron and Ethereum networks, followed by a full asset replenishment by the platform and an ongoing investigation into the withdrawal system vulnerability. However, these reports and allegations remain not officially confirmed by regulatory authorities or independent cryptographic audits. The affected entity, Coinsbuy, has successfully covered all user balances from internal reserves, meaning that registered users experienced zero financial losses and platform operations have resumed normally. Additionally, Coinsbuy launched a $100,000 reward initiative for information leading to the identification of the attackers and the recovery of stolen funds.
As the next immediate action, platform users and market participants should monitor official Coinsbuy communication channels for verified updates regarding the investigation outcome, while ensuring that personal authentication settings remain secure. Stakeholders must acknowledge that while the financial impact on users has been mitigated by corporate reserves, the exact attack vector remains unconfirmed and subject to further forensic verification. Security teams across other exchanges should evaluate their withdrawal pathways against similar multi-chain vulnerabilities to prevent comparable exploits.
Cexvia conclusion
Conclusion and Next Steps for Platform Stakeholders
Media reports indicate that attackers drained $8.07 million in digital assets from Coinsbuy across multiple blockchain networks before the platform replenished the balances, though these claims remain not officially confirmed.
- Risk meaning
- Security incidents involving multi-chain withdrawal pathways highlight ongoing vulnerabilities in digital asset platforms, where potential unauthorized access to withdrawal systems can lead to substantial financial outflows even if private keys remain uncompromised.
- User action
- Users interacting with platforms that have undergone recent security alerts should monitor official channel updates, review personal account security settings, and maintain heightened vigilance regarding platform announcements.

