Crypto Payments Platform Coinsbuy Drained of $7.9 Million in Cross-Chain Wallet Attack

Wallets tied to Coinsbuy, a business-to-business crypto payments processor, were drained of more than $7.9 million in a coordinated attack that hit the Ethereum and TRON networks almost at the same moment on August 9, 2026. On-chain investigators place the first suspicious movement at roughly 13:00 UTC, when a handful of TRON-based wallets and a smaller set on Ethereum began emptying out within the span of about an hour.
The pattern itself was almost clinical. A small test transaction went out first, a common tell that whoever was in control of the wallets was checking that a withdrawal path actually worked before committing to the full drain. What followed was a rapid sweep of stablecoin balances, mostly USDT, alongside a smaller amount of ETH, moving out of roughly a dozen addresses linked to the platform. Security researchers who reviewed the transaction trail, including the pseudonymous on-chain analyst known as Specter, flagged the activity publicly within hours, well before Coinsbuy itself issued any statement.
GoPlus Security, which tracked the funds as they moved, described the withdrawal pattern as consistent with either a compromised hot-wallet private key or unauthorized administrator access to the platform’s infrastructure, though Coinsbuy has not confirmed which scenario applies. What is confirmed is where the money went next: attackers began funneling the stolen assets through swap services and centralized exchanges, including ChangeNOW, FixedFloat and BingX, before converting a large share of it into Monero, the privacy coin whose transaction graph is effectively opaque to outside observers. ChangeNOW says it managed to freeze a six-figure portion of the funds that passed through its platform before conversion, but the bulk of the haul appears to have already slipped past the point where it can realistically be traced or recovered.
Coinsbuy’s own response has been notably fast on the operational side. The company temporarily suspended deposits and withdrawals as soon as the drain was detected, and within roughly 24 hours it had topped its affected wallets back up to within about 0.05% of their pre-attack balances, according to on-chain data reviewed by security researchers. That detail matters: refilling wallets that quickly, out of the company’s own reserves rather than customer funds, suggests Coinsbuy is treating this as a balance-sheet loss it intends to absorb rather than a shortfall it plans to pass on to clients. The firm has also put up a $100,000 reward for information that helps identify the attacker, and deposit and withdrawal services have since resumed.
Coinsbuy is not a household name among retail traders, but that is precisely the point. It processes crypto payments and settlement on behalf of merchants and enterprise clients, meaning an $7.9 million breach there says less about any one exchange’s security posture and more about how deep the exposure runs across the plumbing that keeps crypto payments moving day to day. Infrastructure providers like this rarely get the scrutiny that major exchanges do, right up until something goes wrong.
Crypto assets carry real custody and counterparty risk, and this article is provided for informational purposes only, not as financial or investment advice. Anyone new to how wallets, custody and on-chain security actually work can start with the fundamentals over at coin680’s Bitcoin Academy.
