The ability to access and drain wallets on two different blockchains in quick succession strongly suggests the attacker had compromised private keys or breached Coinsbuy's wallet infrastructure — not a smart contract exploit . On-chain records show the two chains were connected through the cross-chain swapper Bridgers, whose Ethereum payout contract received funds from the TRON side
.
The attacker moved quickly to obscure the trail. Stolen funds were routed through three exchanges — ChangeNOW, FixedFloat, and BingX — and then converted into Monero (XMR), a privacy-focused cryptocurrency that makes forensic tracing significantly harder . This laundering sequence consumed the investigator window that might have enabled a larger freeze
.
On-chain monitoring firm Specter first flagged suspicious outflows and published an alert on its Telegram channel at approximately 13:00 UTC on August 9 . Blockchain security firm PeckShield independently confirmed the breach, tracing the flow of stolen funds and identifying the three exchanges involved
.
Coinsbuy's response included:
ChangeNOW helped freeze a six-figure portion of the stolen assets, though the vast majority of funds had already moved .
The Coinsbuy incident was not an isolated event. By the first half of 2026, crypto security firms were already reporting record numbers of hacks:
North Korea-linked hackers, particularly the Lazarus Group, were responsible for approximately 55% of stolen value, and infrastructure/supply-chain attacks — not smart contract bugs — emerged as the dominant vector . Privileged key misuse alone accounted for roughly $790 million in losses in H1 2026
.
Full-year 2026 losses reached approximately $1.2 billion across 276 incidents, according to REKT's tracking, with the Coldcard hardware wallet breach alone accounting for about 10% of the total .