Wallets linked to crypto payment processor Coinsbuy were drained of roughly $8 million across Ethereum and TRON on August 9, with suspicious transfers beginning around 13:00 UTC. Blockchain investigators connected activity on both networks to the same operation, while security firms initially placed the losses near $7.9 million. The incident affected multiple Coinsbuy-associated wallets across two separate blockchains within a relatively short window.
On-chain analysis identified withdrawals involving USDT and ETH, with later research estimating total losses at approximately $8.07 million. Coinsbuy operates payment-processing and enterprise wallet infrastructure that allows businesses to receive, store, send and exchange digital assets. What remains unclear is whether the drained balances belonged to Coinsbuy itself, its clients or a combination of both.
🚨 Around 13:00 UTC, wallets linked to Coinsbuy were reportedly drained of more than $7.9M across Ethereum and TRON.
h/t: @SpecterAnalyst via his Telegram channel https://t.co/ylCsdcEPCu
The attacker began laundering the stolen funds into Monero (XMR) through exchanges, while… pic.twitter.com/eANix8fQz9
— Dark Web Informer (@DarkWebInformer) August 9, 2026
Stolen Funds Move Through Multiple Services
The attacker quickly began dispersing the proceeds after the drain. PeckShield and CertiK tracked funds through services including FixedFloat, ChangeNOW and BingX, while investigator Specter reported that part of the stolen value was being converted toward Monero. The movement complicated recovery efforts by fragmenting the stolen assets across multiple platforms and eventually into a privacy-focused cryptocurrency.
Later analysis found that a large portion of the proceeds passed through FixedFloat using dozens of short-lived addresses. Specter also reported that ChangeNOW helped freeze a six-figure amount before it could move further, although ChangeNOW had not independently disclosed the exact amount. At least part of the stolen capital appears to have been intercepted, but most of the recovery picture remains unresolved.
Attack Vector Remains Unknown
The cross-chain nature of the incident initially raised the possibility of compromised wallet keys, administrator privileges or another shared infrastructure component. GoPlus Security described the behavior as consistent with hot-wallet private-key or administrative access theft, but Coinsbuy has not confirmed that assessment. There is currently no public evidence establishing exactly how the attacker gained authority to move funds from the affected wallets.
That distinction matters because the available evidence does not point to a vulnerability in Ethereum or TRON themselves. Coinsbuy’s own documentation shows that its enterprise infrastructure manages cryptocurrency wallets and transaction permissions, but no public postmortem has identified which internal system, credential or authorization layer failed. The incident should therefore be treated as a compromise of Coinsbuy-linked infrastructure with an undetermined root cause, not as a blockchain protocol exploit.
Specter reported that deposits and withdrawals were temporarily suspended and later restored, while subsequent on-chain analysis found that Coinsbuy replenished drained wallets within 24 hours. Restoration of services, however, does not establish that every affected balance has been recovered or that clients faced no losses. Until Coinsbuy publishes a technical postmortem and asset breakdown, the financial exposure and precise security failure remain open questions.
