The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
Business & Venture

Coinsbuy Loses $7.9 Million in Cross-Chain Attack as Stolen Funds Race to Monero, Six Figures Frozen

The drain was flagged by on-chain analyst Specter at about 13:00 UTC on Aug. 9, according to reports citing blockchain transactions.

Coinsbuy Loses $7.9 Million in Cross-Chain Attack as Stolen Funds Race to Monero, Six Figures Frozen

Coinsbuy-linked wallets were drained of about $7.9 million across Ethereum and TRON, with the attacker moving stolen assets towards Monero before an exchange froze a six-figure portion of the funds.

Key Takeaways
  • Coinsbuy-linked wallets were drained of about $7.9 million across Ethereum and TRON, with the attacker moving stolen assets towards Monero before an exchange froze a six-figure portion of the funds.
  • The drain was flagged by on-chain analyst Specter at about 13:00 UTC on Aug. 9, according to reports citing blockchain transactions.
  • Coinsbuy has restored its services, but the full amount recovered remains unclear.
Listen to this article
READY

The drain was flagged by on-chain analyst Specter at about 13:00 UTC on Aug. 9, according to reports citing blockchain transactions. Coinsbuy temporarily halted deposits and withdrawals after the incident and later restored services.

Ethereum And TRON Wallets Drained

Coinsbuy is a cryptocurrency payment platform that provides wallet and transaction infrastructure for businesses and other digital-asset users. The reported attack affected wallets linked to the platform across both Ethereum and TRON.

Blockchain monitors identified large transfers from the affected addresses after the drain was detected. The transactions show where the funds moved, but they do not establish how the attacker gained access.

The wallets reported in connection with the incident include two Ethereum addresses and a TRON address. Security researchers have not publicly confirmed whether private keys, credentials, API access or another mechanism was involved.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

Stolen Funds Move Toward Monero

The attacker began routing portions of the stolen cryptocurrency through exchanges, with some funds eventually moved towards Monero, known by its ticker XMR.

Monero is designed to provide greater transaction privacy than transparent networks such as Ethereum. Moving stolen assets into XMR can therefore make conventional blockchain tracing more difficult.

Reports have also identified transfers involving ChangeNOW, FixedFloat and BingX. The full path of the funds remains unclear.

Exchange Freezes Six-Figure Amount

ChangeNOW reportedly froze a six-figure portion of the assets after the suspicious transfers were identified.

The amount frozen represents only part of the estimated $7.9 million drain. The exact sum has not been publicly disclosed in the reports reviewed.

The freeze came while the stolen funds were still moving between wallets and exchanges. That gave investigators and service providers an opportunity to identify and restrict at least some of the assets.

Coinsbuy Suspends Deposits And Withdrawals

Coinsbuy temporarily suspended deposits and withdrawals after the incident as it responded to the reported wallet drain.

The company’s platform supports cryptocurrency payments and transfers across multiple digital assets. Its published security information includes controls such as two-factor authentication, address whitelisting and withdrawal limits.

Services were later restored, according to reports. Coinsbuy has not publicly released a detailed technical post-mortem explaining the source of the compromise.

Attack Method Remains Unknown

No public investigation has established how the attacker obtained control of the affected wallets.

Possible explanations include compromised private keys, stolen credentials, API access or another form of unauthorized access. None has been confirmed publicly.

That distinction is important because the available blockchain evidence establishes the movement of funds, not the technical cause of the breach.

Blockchain Investigators Track The Money

The reported theft has remained visible through public blockchain transactions, allowing researchers to identify the affected addresses and follow subsequent transfers.

Specter‘s initial alert helped draw attention to the drain. PeckShield and other blockchain security monitors later amplified information about the stolen funds and their movement across networks.

The reported route into Monero has become a key part of the investigation because XMR’s privacy features can limit the usefulness of conventional transaction tracing.

Coinsbuy has restored its services, but the full amount recovered remains unclear. The technical cause of the wallet compromise has also not been disclosed.

The reported theft therefore leaves two central questions unresolved: how the attacker gained access and how much of the estimated $7.9 million can ultimately be recovered.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What is the Coinsbuy cross-chain attack?

The Coinsbuy attack is a $7.9 million cryptocurrency theft targeting the Ethereum and TRON wallet architecture of the payment provider. Specter identified the drain at 13:00 UTC on August 9 across three specific digital addresses. This breach forces the platform to audit its private key management and API security protocols to identify the entry point.
02

Why does this matter for the payment industry?

Institutional trust in cross-chain payment rails decreases when large-scale providers suffer multi-million dollar exfiltrations of business capital. PeckShield notes that the theft disrupts liquidity for Coinsbuy corporate clients who rely on stable Ethereum and TRON transfers. Recurring infrastructure compromises suggest that centralized gateways remain the primary vulnerability in the decentralized finance stack.
03

How did the attacker move the stolen Coinsbuy funds?

The perpetrator utilized high-velocity transfers to route exfiltrated assets through BingX and FixedFloat before attempting to exit via Monero. ChangeNOW successfully intercepted a portion of the flow, freezing a six-figure amount during the transition process. This racing dynamic between hackers and exchanges highlights the necessity for real-time automated asset blacklisting across all trading venues.
04

What are the risks of funds entering the Monero network?

Monero uses ring signatures and stealth addresses to provide absolute transactional privacy, making stolen assets nearly impossible to trace on-chain. Investigators confirmed that the attacker prioritized XMR as the final destination for the $7.9 million in stolen ETH and USDT. The loss of public ledger visibility creates a permanent hurdle for federal law enforcement and private forensic teams.
05

How will Coinsbuy secure its wallet infrastructure?

Coinsbuy intends to implement enhanced two-factor authentication and address whitelisting to harden its Ethereum and TRON payment gateways. The company restored services on August 10 but has yet to release a public technical post-mortem regarding the compromise. Professional standards for payment providers now mandate air-gapped storage for large corporate balances to prevent catastrophic network-wide drains.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.