Trial transfer for $ 5 – and $ 8 million as it didn’t happen. Hackers robbed Coinbuy crypto platform in an hour

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
362
Reaction score
596
Deposit
0$
The Coinsbuy cryptocurrency platform lost more than $8 million in a few hours, and the attacker almost immediately began to crush the stolen funds and transfer them through dozens of new addresses and exchange services.

The attack began on August 9 with a trial transaction of 5 USDT. Soon, the attacker devastated eight Coinsbuy wallets on the TRON network, from where about 6.04 million USDT were withdrawn in about an hour. Almost simultaneously three wallets in Ethereum, which left another 1.89 million USDT and 77 ETH.

At first, the operations in the two networks looked like separate incidents. Later, the specialists connected the translations through the service of the Bridgers. Funds from TRON passed through the service, and his contract in Ethereum sent the assets directly to the address that the attacker used for further exchange. Such a chain showed that one operator probably managed both parts of the attack.

The stolen cryptocurrency began to move almost immediately. About 79% of the funds went through the FixedFloat exchange service, using about 50 one-time addresses. Such fragmentation complicates the tracking of transfers and reduces the time for which exchanges and other sites can notice suspicious transactions and block assets.
Some of the funds were stopped. The ChangeNOW service has frozen the amount in the six-digit dollar range after it was approached by Specter Investigations specialists. Another 282 ETHs worth approximately $542,000 at the time of the inspection remained at five addresses without movement.

Coinsbuy about a day restored the balances on the affected working wallets to almost the same level. The difference was less than 0.05% of the amount before the attack. The company said it had covered the damage from its own reserves and customers did not lose money.

Quickly replenishing the same wallets may indicate that Coinsbuy does not consider their private keys compromised. If the attacker kept access to the keys, the new funds would again be threatened. Specialists admit that the attacker could gain control over another link of the system, which is responsible for confirming and sending transactions, but the company has not yet confirmed such a version.

Modern cryptocurrency platforms use separate systems to sign operations, automatically confirm translations, delineate access and connect internal services with blockchains. If such a component is compromised, sometimes it is possible to carry out operations from several wallets at once, without stealing each private key separately.

This possibility is indicated by the scale of the attack. In a short period of time, the attacker withdrew funds from 11 wallets in two different networks. Coinsbuy has not yet disclosed the technical cause of the incident and has not disclosed whether credentials, signature systems, automatic transaction processing mechanisms or other internal software have been compromised.

The company claims to have stopped the attack and works as usual. The check continues. The main question is how the attacker was able to simultaneously manage transfers from many wallets. The response will show whether the hacking was limited to a separate infrastructure component or affected a broader fund management mechanism.
 
Top Bottom