EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coinsbuy Exchange was attacked by a coordinated wave field-Ethereum attack, and $8 million was stole

2026-08-11 00:33:48
Bookmark

Two chains linked, tens of millions of dollars of assets stolen: Coinsbuy incident reveals new trends in cross-chain attacks

The $8 million Coinsbuy asset theft case that occurred on TRON and Ethereum has become the latest attack to link two blockchain networks through a single trace on the chain. According to relevant reports, forensic analysis has identified the exchange attack as the same perpetrator, and the stolen funds mainly flowed to the unmanaged platform FixedFloat.

The attack occurred in the early hours of August 10, 2026, and the attacker stole assets from wallets operating on both wavefield and Ethereum. On-chain data showed that the attacker quickly dispersed the tokens to a series of intermediate addresses and then transferred them into FixedFloat's redemption contract. The ability to connect two very different blockchains in real time suggests that attackers have a considerable degree of planning capabilities, and such techniques are becoming increasingly common as cross-chain infrastructure develops.

The same mastermind connected two chains in series

The forensic firm tracked the flow of funds and found that the same operating pattern and overlapping address clusters appeared on both networks almost simultaneously. The people behind this asset theft did not rely on a single-chain attack, but instead carried out a coordinated attack: transferring assets between USDT liquidity on the wavefield and Ethereum-based tokens, ultimately converging into a single exit. This coordination suggests that the attacker has a deep understanding of how the two blockchains handle contract interactions and bridging mechanisms.

Bochang and Ethereum remain among the most active blockchains for developers, a point that was highlighted in recent analysis of on-chain development indicators. High activity often means a greater attack surface, especially when exchanges integrate multiple networks but fail to isolate risks. In the Coinsbuy incident, the risk was further amplified because an attacker was able to attack two different user pools simultaneously without triggering an instant cross-chain alert.

FixedFloat: repeatedly become a channel for money laundering

FixedFloat operates as an instant, non-custodial exchange and does not require KYC (Know Your Customer) certification for small conversions. This design has made it repeatedly the recipient of hacker funds because assets can be automatically redeemed without manual approval delays. In the past two years, the service has emerged in the wake of multiple exchange intrusions and has become an ongoing challenge for investigators.

Unlike centralized exchanges that can freeze assets on request, FixedFloat's architecture provides very limited remedies after a transaction is settled. In the Coinsbuy incident, most of the $8 million stolen was processed through the platform before the attack became publicly known, leaving little opportunity to intercept funds. The speed at which the attacker moved assets within hours suggests that the entire operation used pre-programmed scripts and had a clear exit plan.

Attack method remains a mystery, pending

The specific method used to hack Coinsbuy remains unknown. Officials have not confirmed whether the breach involved private key disclosure, smart contract loopholes, evil actions by insiders, or manipulation of hot wallet management within the exchange. Forensic companies can currently only track capital outflows, but cannot determine the point of intrusion.

This information gap is critical because exchanges often fix specific technical vulnerabilities after being attacked, while other weaknesses may still exist. Without knowing how attackers gained initial access, users and platform operators can only guess whether similar attack vectors exist on other networks or services. The wavefield and the Ethereum ecosystem share some cross-chain protocols, so the possibility of exploitations related to bridging has not been ruled out.

Exchange security under question again

Despite years of development in security practices, centralized exchanges continue to suffer millions of dollars in losses. The Coinsbuy incident adds to a series of attacks in 2026 in which attackers took advantage of friction between different blockchain architectures. Regulators in multiple jurisdictions have begun requiring exchanges to provide stricter proof of reserves and real-time wallet monitoring, but enforcement remains uneven.

For Coinsbuy users, the most immediate impact may include the exchange suspending withdrawals to assess losses and cooperate with law enforcement. Recovering some of the funds depends largely on connecting the identity of the attacker to a centralized exit, a task that becomes more difficult when FixedFloat serves as the initial currency mixer. The lack of a clear recovery path puts affected customers at risk, and the reputation of the exchange will depend on its transparency in handling subsequent events.

In addition, the use of two blockchains in a single attributable attack also marks the maturity of hostile operating methods. Attackers have shifted from opportunistic single-chain asset theft to premeditated multi-cyber attack operations that exploit blind spots between ecosystems. For security teams, this increases the cost of monitoring and defense, as obtaining a comprehensive view now requires data on multiple ledgers to be correlated in near real time.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP