Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin Chain SAFU CryptoTax DeFAI AGI Claude Me Claude Skill Claude Design Claude Cowork
Independent Media
Not affiliated with any project
Crypto Security, From Defense to Incident Response
safu-bible.com
LATEST
A 5 USDT Test Transfer, an $8 Million Drain an Hour Later: Inside the Coinsbuy Cross-Chain Exchange Hack  ·  Only 0.1% of People Can Spot a Deepfake, Research Finds: A Fake "Elon Musk" Crypto Ad Drained an 82-Year-Old's Life Savings  ·  Four Months Undetected: Plug In One Infected USB Drive, and Every Address You Copy Gets Silently Swapped  ·  Private Key, Seed Phrase, Wallet Address: The Three Terms Everyone Confuses — and Who's Allowed to See What  ·  Address Poisoning: The Scam That Doesn't Need Your Signature — Just Your Copy-Paste Habit  ·  What Is Blind Signing: The Moment You Hit Confirm, Your Hardware Wallet Has No Idea What It's Signing
news

A 5 USDT Test Transfer, an $8 Million Drain an Hour Later: Inside the Coinsbuy Cross-Chain Exchange Hack

30-Second Version · For the impatient
A five-cent test transfer bought the attacker two blockchains drained within the hour — Coinsbuy shows how much patience beats any single exploit.

Full Explanation +
01 · Why did this happen?

How is the Coinsbuy incident fundamentally different from past exchange hot-wallet hacks?

Most past exchange hacks (Bybit, for instance) centered on a single compromised signing interface or a single hot wallet, with the attack concentrated on one chain and executed as one large withdrawal. What sets Coinsbuy apart is the cross-chain synchronization: the attacker hit Tron and Ethereum — two unrelated blockchains — within roughly the same hour, which means either the attacker had access spanning both systems, or the exchange's key management and monitoring were themselves centralized across chains in a way that let one compromise cascade.

That's why multiple analysts have emphasized the overlapping time window rather than the dollar amount — the loss itself isn't remarkable against 2026's string of eight-figure hacks, but the degree of coordination in the attack method is exactly what security teams should be studying.

02 · What is the mechanism?

Why do KYC-free swap services like FixedFloat keep showing up as the go-to laundering channel?

FixedFloat is a non-custodial, no-registration instant swap service designed to let users quickly exchange between chains or assets without leaving an identity trail. That convenience for ordinary users is exactly what makes it attractive to attackers — once stolen funds pass through a swap on a platform like this, tracing them further becomes significantly harder, because the platform itself retains no KYC data linking the transaction to a real identity.

In the Coinsbuy incident, roughly $6.34 million — over 70% of the total loss — passed through FixedFloat. That proportion isn't a coincidence; it reflects that KYC-free swap services have become a near-standard laundering step attackers build into their playbook, which is exactly why regulatory pressure keeps concentrating on these platforms even though they weren't themselves hacked, only used outside their intended purpose.

03 · How does it affect me?

How should readers interpret the exchange's later disclosure that it "refilled the gap within 24 hours"?

This carries two separate layers of meaning. The reassuring layer: Coinsbuy chose to cover the loss from its own reserves rather than freezing withdrawals or passing the loss onto user balances — a practice that has become the industry norm since Bybit set the standard for crisis response in 2025, signaling that the exchange had enough balance-sheet resilience to absorb the hit, at least for now.

The layer worth watching, though: refilling quickly is not the same as explaining clearly. As of this writing, Coinsbuy has not disclosed exactly how the attacker gained withdrawal capability — whether private keys leaked, or withdrawal permissions or an admin account were abused remains unresolved. A fast refill solves users' immediate liquidity concern, but it doesn't mean the underlying security gap has actually been accounted for — the two shouldn't be conflated.

04 · What should I do?

As an ordinary user, what should I concretely change after seeing a cross-chain, synchronized withdrawal attack like this?

The most actionable change is to reassess whether the assets you're leaving on an exchange are limited to what you actually need for active trading right now. Coinsbuy's incident shows that even if your assets are technically spread across multiple chains an exchange supports, that spread doesn't give you real risk isolation if the exchange's own key management or monitoring is centralized — what determines your risk is the exchange's internal architecture, not the surface-level fact of "multi-chain support."

Second, you can add "does this exchange publish proof-of-reserves, and how transparent is its incident-response track record" to your criteria for choosing an exchange, rather than just fees or trading pairs. Coinsbuy was relatively transparent in its statement and follow-up actions (public bounty, fast refill), but the attack vector itself remains undisclosed — that kind of partial transparency is exactly the detail worth probing when you're comparing exchanges.

Full Content +

On August 9, 2026, crypto exchange Coinsbuy suffered coordinated unauthorized withdrawals on both the Tron and Ethereum blockchains within roughly the same hour, losing more than $8 million combined. What makes this incident worth studying isn't the dollar figure — it's a rounding error compared to Bybit's $1.5 billion loss in February 2025 — but the fact that the attacker executed a complete "test, drain, launder" playbook in under an hour, a pattern that has direct implications for how exchanges design their incident response plans.

How It Started: A Five-Cent Test Transaction

According to blockchain intelligence firm BlockWatchdog, the attacker opened with a single 5 USDT transfer on Tron. This wasn't a mistake — it's a classic reconnaissance move used to confirm that a compromised key or session credential actually works before committing to a full withdrawal. Once that tiny transaction cleared, eight Coinsbuy-linked Tron wallets were drained of roughly 6.04 million USDT within minutes. Almost simultaneously, three Ethereum wallets were emptied of about 1.89 million USDT plus 77 ETH. The near-total overlap in timing across two unrelated blockchains is itself the strongest signal here — this wasn't two coincidental breaches, it was one coordinated operation.

How the Funds Were Laundered: A Cross-Chain Swap as the Connective Tissue

Investigators later linked the Tron and Ethereum withdrawals through Bridgers, a cross-chain swap service whose payout contract forwarded the Ethereum-side funds directly into a wallet the attacker had created that same day — a detail suggesting pre-planning rather than opportunism. BlockWatchdog further traced roughly $6.34 million of the stolen funds through FixedFloat, a non-custodial swap service that has become a favored laundering rail precisely because it requires no identity verification. Multiple outlets reported that additional funds passed through ChangeNOW and BingX; ChangeNOW froze a six-figure sum, and roughly $542,000 in ETH has reportedly not moved since the attack.

Coinsbuy's Response: Replenished Within 24 Hours

Coinsbuy issued a statement the same day, saying it had "identified a security incident that resulted in unauthorized withdrawals from several platform wallets" and stating that no client bore any loss — meaning the exchange chose to cover the shortfall from its own reserves rather than socialize the loss across user balances, a response pattern that mirrors how Bybit handled its own record-breaking hack in February 2025. Multiple reports confirmed Coinsbuy refilled the affected wallets to within roughly 0.05% of their pre-attack balances within 24 hours, and the exchange publicly offered a $100,000 reward for information leading to the attacker's identification or fund recovery.

Notably, this rapid 24-hour replenishment has led some reporting to speculate that the attacker may not have obtained the private keys themselves, but instead exploited some other access path — such as withdrawal permissions or an administrative privilege. Other analysts, however, point to the near-simultaneous impact across two chains as a sign that hot-wallet key management or monitoring may have been centralized in ways that let a single compromise cascade. Coinsbuy has not yet publicly detailed the exact attack vector, and that remains the open question in this incident as of this writing.

Not an Isolated Incident — A Snapshot of a 2026 Pattern

Coinsbuy's breach landed in the middle of an already rough year for crypto security — tracking firms put July 2026's industry-wide hacking losses at more than $200 million, the second-worst month of the year behind only April's peak. What should worry security teams most isn't the size of this particular loss, but the pattern: test transaction, rapid coordinated drain, immediate cross-chain laundering — a sequence fast enough that manual freeze requests arrive too late by design. That's why more exchanges are beginning to treat "small test transfer followed by a large withdrawal" itself as a trigger for automated freezes, rather than waiting for a human reviewer to sign off.

What This Means for Your Money

If you hold assets on a centralized exchange, Coinsbuy's incident is a reminder of two things. First, wallets being split across multiple blockchains doesn't automatically mean your risk is actually diversified — if key management or monitoring systems are themselves centralized, a single compromise can hit wallets on several chains at once, which is a separate question from whether you can find that exchange's proof of reserves. Second, an exchange "covering the gap from its own reserves" after the fact sounds reassuring, but it isn't something you can verify in advance. What you can actually check is whether an exchange routinely publishes proof-of-reserves data, how transparent its settlement practices are, and how fast and forthcoming its track record has been in past incidents. Keeping only what you're actively trading on any single exchange remains the most concrete risk-management step available to you right now.

Sources: Crypto hackers drained $8 million from Coinsbuy using a clever cross-chain trick (CoinDesk), Hackers Drain $8 Million From Crypto Exchange Across Two Blockchains (Decrypt), Coinsbuy Hack Latest in $972 Million Crypto Theft Spree (PYMNTS)
Ask a Question
Please enter at least 10 characters
Related Articles
Every Exchange Promises a Safety Net — Few Have Actually Been Hack-Tested: Binance's SAFU Fund in 2019
incident-analysis · Aug 22
When an Exchange Goes Bankrupt, Is Your Crypto Yours or Theirs? The Answer Was in the Terms You Clicked "Agree" On
fundamentals · Aug 27
$1.5 Billion, One Tampered Signing Interface: Why Multisig Couldn't Stop Crypto's Biggest Heist
incident-analysis · Aug 26
If You're Reading This, You Might Be Getting Hacked Right Now: What to Do in the First Hour
incident-analysis · Aug 19
Related News
More Related Topics