
BlockWatchdog traced the attack to a single actor. Coinsbuy refilled wallets hours later, suggesting keys not compromised. The hack follows $840M in DeFi losses since Jan.
Alpha Score of 47 reflects weak overall profile with weak momentum, weak value, strong quality, moderate sentiment.
An attacker stole more than $8 million from crypto platform Coinsbuy on Sunday, draining wallets on Tron and Ethereum before moving most of the funds through exchange services, according to blockchain investigator BlockWatchdog.
BlockWatchdog posted an analysis on X showing the attack began on Tron with a 5 USDT test transaction. Minutes later, over 6 million USDT was taken from eight Coinsbuy wallets. On Ethereum, another 1.89 million USDT and 77 ETH were stolen from three wallets.
The investigator linked the Tron and Ethereum transactions to the same attacker through cross-chain swap service Bridgers. The attacker then moved about $6.34 million, or 79% of the stolen funds, through FixedFloat. Another 150 ETH was sent through ChangeNOW.
According to BlockWatchdog, 282.2 ETH worth roughly $542,000 at the time remained untouched across five addresses.
Hours after the theft, Coinsbuy replenished the affected wallets. BlockWatchdog reported that around $3.93 million was returned to the same 10 addresses, with seven deposits matching the stolen amounts to within 0.05%.
“That only makes sense if the team does not believe the private keys leaked,” BlockWatchdog wrote. “An address is a key: nobody tops up a compromised wallet with seven figures twice in one night. Whatever was taken over on 9 August sat above the keys–the withdrawal path that uses them.”
The exact attack vector remains unknown. BlockWatchdog said the attacker may have gained access to Coinsbuy’s withdrawal system. “Nothing on-chain shows how the withdrawal path was reached–the refill argues against key theft, it does not name what replaced it,” they wrote. “No attribution either: zero address overlap with the Triple-A attacker of 24 July, and a different laundering habit.”
BlockWatchdog found no address overlap with the attacker behind the July 24 Triple-A hack and noted different laundering patterns.
Coinsbuy had not publicly explained how the attacker gained access at the time of BlockWatchdog’s analysis. The company did not immediately respond to a request for comment.
The hack is the latest in a series of crypto exploits in 2026. DeFi protocols lost more than $840 million to hacks in the first five months of the year, according to DeFiLlama. In July, attackers stole $24 million from Arbitrum-based AFX Trade after exploiting a bridge operated by the decentralized exchange. Earlier that month, decentralized exchange Ostium lost $18 million after an attacker compromised an oracle key.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.