
Crypto payments platform Coinsbuy suffered a $7.9 million theft on August 9, 2026, in what represents one of the largest crypto hacks reported in recent months. According to blockchain monitoring firm Specter, the attack occurred around 13:00 UTC (21:00 Beijing time) and targeted wallets linked to the platform across both Ethereum and TRON networks. The attacker began with a 5 USDT transaction before draining 8 TRON wallets of 6.04 million USDT in approximately one hour. On Ethereum, three wallets were simultaneously emptied of 1.89 million USDT and 77 ETH, which was swapped to ETH via 1inch through a wallet created the same day. The attackers moved quickly to launder the funds through Monero (XMR) before parts of the haul could be traced or frozen, demonstrating the sophistication of modern crypto theft operations. Blockchain security firm PeckShield has now confirmed this estimate based on on-chain analyst findings, with the stolen assets primarily distributed across TRON and Ethereum networks.
Following the incident, Coinsbuy temporarily paused deposits and withdrawals as a precautionary measure. As reported by Specter, the platform has since resumed services after the initial security breach. The attacker's strategy involved moving stolen assets through exchanges and converting funds into Monero, making the stolen assets more difficult to trace and recover. The relatively quick restoration suggests the immediate threat was contained, though the platform has not yet issued a detailed public breakdown of what caused the suspected wallet compromise. Coinsbuy has confirmed that with assistance from ChangeNOW, it has frozen a six-figure amount of the stolen assets, indicating coordinated efforts to prevent further laundering activities. However, it remains unclear from public disclosures whether the reported $7.9 million consisted entirely of Coinsbuy owned assets, client funds or a combination of both. Within 24 hours, Coinsbuy refilled the drained wallets to within 0.05% of their pre-attack balances, behavior researchers say indicates the team does not believe private keys were compromised.
Following the incident, Coinsbuy temporarily paused deposits and withdrawals as a precautionary measure. As reported by Specter, the platform has since resumed services after the initial security breach. The attacker's strategy involved moving stolen assets through exchanges and converting funds into Monero, making the stolen assets more difficult to trace and recover. The relatively quick restoration suggests the immediate threat was contained, though the platform has not yet issued a detailed public breakdown of what caused the suspected wallet compromise. Coinsbuy has confirmed that with assistance from ChangeNOW, it has frozen a six-figure amount of the stolen assets, indicating coordinated efforts to prevent further laundering activities. However, it remains unclear from public disclosures whether the reported $7.9 million consisted entirely of Coinsbuy owned assets, client funds or a combination of both. Within 24 hours, Coinsbuy refilled the drained wallets to within 0.05% of their pre-attack balances, behavior researchers say indicates the team does not believe private keys were compromised.
Blockchain investigator Specter highlighted specific theft addresses associated with the incident: 0x4d1bEF2Fe998B3E3C4029EF9EA6A0534d95661d3, 0x66790b54B891e2ebdef58a15B969Ff6fb4374b17, and TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR. According to the report, ChangeNOW reportedly froze a six-figure amount linked to the stolen funds, indicating coordinated efforts to prevent further laundering activities. However, this represents only a small fraction of the total $7.9 million reportedly lost, meaning the vast majority of the stolen funds may still be at large. PeckShield reports that part of the stolen funds was traced through exchanges including ChangeNOW, FixedFloat, and BingX, suggesting the attackers used these platforms to swap or transfer the assets during the laundering process. The laundering route resembles patterns seen in other major crypto thefts, with investigators helping freeze about $1.2 million tied to Bo Shen's stolen assets after funds passed through similar services. FixedFloat routed approximately 79% of the stolen funds through instant exchange using roughly 50 single-use addresses, while around 282 ETH (roughly $542,000) across five addresses remains unmoved.
Security firm GoPlus assessed that the activity was 'consistent with hot wallet private key or administrator privilege theft', though this remains an assessment rather than a confirmed root cause. Coinsbuy has not published a technical postmortem in public documentation reviewed on August 10, with its latest visible release notes dated July 31. The cross-network movement suggests the attacker obtained access capable of moving assets on more than one chain, but this does not establish whether private keys, administrator credentials or another part of Coinsbuy's infrastructure was compromised. The precise attack vector has not been established publicly, and security researchers are continuing to trace the listed Ethereum and TRON addresses, though movement into Monero can make later tracing harder once funds leave transparent blockchains. The incident adds to an increasingly costly year for the industry, which had already seen roughly $972 million stolen across the sector through late July, with the cross-platform nature of this attack suggesting the sophistication of modern attack vectors and the need for enhanced platform security measures.
In response to the security breach, Coinsbuy has launched a $100,000 identification bounty for information leading to the identification of those responsible for the unauthorized withdrawals. The Panama-incorporated crypto payments company confirmed that all affected client funds were covered using its reserves, ensuring users have not experienced any financial losses. The company also promised an additional, unspecified bonus for assistance in recovering the stolen assets. Coinsbuy stated it is investigating the incident but will withhold technical details until its findings are complete and independently verified, with no suspect or attack method publicly identified. The company has not disclosed how much of the remaining cryptocurrency has been recovered or frozen, though around 282 ETH (roughly $542,000) across five addresses remains unmoved in the latest reported on-chain review. This fixed identification reward differs from percentage-based vulnerability bounties sometimes offered to exploiters, instead targeting information that could identify those responsible while providing separate recovery assistance.