Crypto platform Coinsbuy lost more than $8 million in an attack across the Tron and Ethereum networks on Aug. 9. Blockchain investigator BlockWatchdog analyzed the incident, which involved unauthorized withdrawals from multiple platform wallets.

The attack began on Tron with a five USDT test transaction. Within minutes, more than 6 million USDT was drained from eight Coinsbuy wallets. On Ethereum, an additional 1.89 million USDT and 77 ETH were taken from three wallets.

BlockWatchdog linked the Tron and Ethereum transactions to a single attacker who used the cross-chain swap service Bridgers to consolidate and move funds between the two chains.

About $6.34 million, or 79 percent of the total stolen funds, was subsequently moved through FixedFloat. Another 150 ETH was sent through ChangeNOW.

Approximately 282.2 ETH, valued at $542,000 at the time of the attack, remained untouched across five addresses controlled by the attacker.

Coinsbuy said the security incident involved unauthorized withdrawals, that the issue was contained and that its team acted to secure the platform.

Hours after the theft, Coinsbuy replenished the affected wallets. BlockWatchdog reported that roughly $3.93 million was returned to the same 10 addresses, with seven of those deposits matching the amounts originally stolen within 0.05 percent.

Coinsbuy said all affected client funds have been fully covered from its own reserves, that users experienced no financial losses and that the platform is operating normally.

BlockWatchdog concluded that the decision to replenish the wallets suggests Coinsbuy did not believe its private keys were compromised, writing that no team tops up a compromised wallet with seven figures twice in one night.

The breach likely targeted the withdrawal path rather than the keys themselves. The exact attack vector remains unknown, as on-chain data does not reveal how the withdrawal path was accessed.

BlockWatchdog found no address overlap with the Triple-A attacker from July 24, suggesting a different actor with distinct laundering habits was responsible.

Coinsbuy has not publicly explained how the attacker gained access. The company said it is conducting an investigation and is offering a $100,000 reward for information leading to the attacker's identification, with an additional bonus available for assistance in recovering the stolen funds.