Attackers steal more than US$8 million from encryption platform Coinsbuy
According to blockchain investigation agency BlockWatchdog, last Sunday, an attacker stole more than US$8 million from encryption platform Coinsbuy through the Tron and Ethereum networks, and then transferred most of the stolen money.
BlockWatchdog pointed out in a report released by the X platform that the attack began with a 5USDT test transaction on the wavefield network. A few minutes later, more than 6 million USDTs were stolen from Coinsbuy's eight wallets. On the Ethereum network, another 1.89 million USDTs and 77 ETH were stolen from three wallets.
BlockWatchdog uses the cross-chain redemption service Bridgers to link transactions on wavefield and Ethereum to the same attacker. Subsequently, the attackers transferred approximately $6.34 million (79% of the stolen funds) through crypto exchange FixedFloat and another 150 ETH pieces through ChangeNOW.
According to BlockWatchdog, another 282.2 ETH pieces (worth approximately US$542,000 at the time of the attack) remained at five addresses untouched.
Hours after the theft, Coinsbuy replenished the affected wallets. BlockWatchdog reported that approximately $3.93 million was returned to the same 10 addresses, with seven deposits within 0.05% of the original stolen amount.
"It makes sense only if the team believes the private key has not been compromised," BlockWatchdog wrote,"The address is the key: No one will deposit a six-figure amount into a hacked wallet twice in one night." The funds stolen on August 9 were all on the key-the withdrawal path using the key."
Although the exact attack method is unclear, BlockWatchdog said the attacker may have gained access to Coinsbuy's withdrawal system.
"There is no information on the chain that shows how the withdrawal path was breached-the act of recharging negates the assumption that the key was stolen, but does not state what replaced the key," they wrote."There is also no attribution information: zero overlap with the address of the Triple-A attacker on July 24, and different money laundering habits."
BlockWatchdog did not find any addresses that overlapped with the attackers 'addresses in the July 24 Triple-A hack and noted differences in money laundering patterns.
As of the BlockWatchdog analysis, Coinsbuy had not publicly explained how the attacker gained access.
Decrypt previously sent a request for comment to Coinsbuy, but there was no immediate response.
The news comes after a series of major cryptographic hacking attacks in recent months. According to DeFiLlama, in the first five months of 2026, the DeFi protocol lost more than $840 million due to hacking attacks.
In July, attackers used a cross-chain bridge operated by a decentralized exchange to steal $24 million from the Arbitrum-based AFX Trade platform. Earlier that month, decentralized exchange Ostium lost $18 million when attackers hacked oracle keys.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH