Coinsbuy Says It Covered More Than $8 Million Lost in Weekend Attack Across TRON and Ethereum
Cryptocurrency exchange Coinsbuy says it has covered in full the funds drained in a weekend attack that moved more than $8 million across TRON and Ethereum. For PSPs and crypto payment providers, the detail that matters is not just the size of the loss, but the way the incident appears to have been stitched together across chains using a cross-chain swapper.
- The attack happened on Sunday, Aug. 9, and CoinDesk reported it after reviewing on-chain data with blockchain security researchers. According to that report, the attacker started with a 5 USDT transaction, then siphoned 6.04 million USDT from eight TRON wallets within about an hour.
- At the same time, three Ethereum wallets were emptied of 1.89 million USDT and 77 ETH. CoinDesk said on-chain records linked the TRON and Ethereum activity through cross-chain swapper Bridgers, making what looked like separate operations part of one incident.
- Coinsbuy said it refilled the drained wallets to within 0.05% of their pre-attack balances within 24 hours. Researchers said that suggests the company does not believe private keys were compromised.
- The company told CoinDesk the breaches had been “contained” and that “all affected amounts have been covered in full by the company from its own reserves.” It also said: “No client has borne any loss. The platform is stable and operating normally. Investigation is underway, and we cannot disclose further technical details at this stage.”
- CoinDesk said the incident is the latest in a string of crypto thefts, with about $972 million stolen in the first seven months of the year. Recent cases mentioned in the report include Wemix, which said an attacker compromised ownership of its WEMIX$ stablecoin, SecondFi, which said it would begin winding down after a $2.4 million breach, and a separate attack that stole well over $100 million by exploiting a vulnerability in older firmware used by Coldcard hardware wallets made by Coinkite.
For high-risk payment operators, the practical takeaway is that cross-chain movement is not just a compliance headache; it can also be the path through which a single theft gets disguised as multiple smaller events. When wallets are topped back up within 24 hours, the customer-facing damage may be contained, but the operational question remains the same: how quickly can you see the flow, isolate it, and decide whether your own controls have actually held?
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!