An attacker stole more than $8 million from crypto platform Coinsbuy on Sunday, draining funds across the Tron and Ethereum networks before moving most of the assets, according to blockchain investigator BlockWatchdog.
In a report posted on X, BlockWatchdog said the incident started on Tron with a 5 USDT test transaction. Minutes later, more than 6 million USDT was drained from eight Coinsbuy wallets.
On Ethereum, the attacker took another 1.89 million USDT and 77 ETH from three wallets.
BlockWatchdog said it linked the Tron and Ethereum activity to the same attacker through the cross-chain swap service Bridgers. After the theft, about $6.34 million, or 79% of the stolen funds, was moved through the cryptocurrency exchange FixedFloat. Another 150 ETH was sent through ChangeNOW.
The investigator also said 282.2 ETH remained untouched across five addresses. At the time of the attack, those holdings were worth about $542,000.
Refill activity pointed away from a private key leak
Hours after the theft, Coinsbuy replenished the affected wallets. BlockWatchdog said about $3.93 million was sent back to the same 10 addresses, and seven of those deposits matched the original stolen amounts within 0.05%.
“That only makes sense if the team does not believe the private keys leaked,” BlockWatchdog wrote. “An address is a key: nobody tops up a compromised wallet with seven figures twice in one night. Whatever was taken over on 9 August sat above the keys—the withdrawal path that uses them.”
The exact attack vector remains unknown. Still, BlockWatchdog said the attacker may have gained access to Coinsbuy’s withdrawal system.
“Nothing on-chain shows how the withdrawal path was reached—the refill argues against key theft, it does not name what replaced it,” the investigator wrote. “No attribution either: zero address overlap with the Triple-A attacker of 24 July, and a different laundering habit.”
BlockWatchdog said it found no address overlap with the attacker behind the July 24 Triple-A hack and noted a different laundering pattern.
Coinsbuy had not explained the breach
At the time of BlockWatchdog’s analysis, Coinsbuy had not publicly explained how the attacker gained access.
Decrypt reported that Coinsbuy did not immediately respond to its request for comment.
Latest breach adds to a run of crypto hacks
The theft comes during a period of repeated large-scale crypto security incidents. According to DeFiLlama, DeFi protocols lost more than $840 million to hacks in the first five months of 2026.
In July, attackers stole $24 million from Arbitrum-based AFX Trade after exploiting a bridge operated by the decentralized exchange. Earlier that month, decentralized exchange Ostium lost $18 million after an attacker compromised an oracle key.


