Wallets linked to crypto payment processor Coinsbuy were reportedly drained of more than $7.9 million in digital assets across Ethereum and TRON on August 9, with investigators tracing portions of the stolen funds through several crypto exchanges and toward Monero.
The incident was initially flagged by blockchain investigator Specter, with subsequent monitoring from security firms including PeckShield and CertiK supporting the estimated loss.
- Approximately $7.9 million in crypto was reportedly stolen.
- Stolen funds were traced through ChangeNOW, FixedFloat and BingX.
- ChangeNOW reportedly helped freeze a six-figure amount of the proceeds.
- Part of the stolen assets was reportedly converted toward Monero, making further tracing more difficult.
- Coinsbuy temporarily suspended deposits and withdrawals before reportedly restoring services.
Coinsbuy Wallets Drained Across Ethereum and TRON
Specter identified two Ethereum addresses and one TRON address as destinations for assets taken during the incident.
PeckShield later estimated that wallets associated with Coinsbuy had lost approximately $7.9 million and tracked portions of the stolen funds through multiple exchange services.
CertiK’s security monitoring also reported the incident and identified similar transaction routes.
However, the precise method used to gain access to the wallets has not been publicly established.
The fact that assets were moved across both Ethereum and TRON indicates that the attacker had access capable of transferring funds on multiple networks. It does not, by itself, prove whether private keys, administrator credentials or another component of Coinsbuy’s infrastructure was compromised.
Possible Hot Wallet or Administrator Compromise
GoPlus Security said the activity appeared consistent with the theft of hot-wallet private keys or administrator privileges.
That assessment remains unconfirmed.
Coinsbuy has not publicly released a technical postmortem identifying the root cause of the incident.
The company describes itself as a cryptocurrency payment and infrastructure provider offering services including payment processing, wallet infrastructure and digital-asset management.
Until Coinsbuy publishes additional technical information, claims about the exact attack vector should therefore be treated as preliminary.
Stolen Funds Move Through Exchanges
Following the reported drain, the attacker began moving the stolen assets through several crypto services.
PeckShield identified ChangeNOW, FixedFloat and BingX among platforms that received portions of the proceeds.
Specter also reported that the attacker was converting some of the stolen assets toward Monero, a privacy-focused cryptocurrency designed to provide greater transaction privacy than transparent blockchains such as Ethereum.
Moving stolen funds through exchange services and subsequently converting them into privacy-focused assets can make recovery and attribution substantially more difficult.
ChangeNOW Reportedly Freezes Part of the Funds
One potentially positive development came from ChangeNOW.
Specter reported that the exchange helped freeze a six-figure amount of the stolen funds before they could move further.
The exact amount has not been independently confirmed by ChangeNOW in the public information reviewed for the incident.
The reported freeze demonstrates why rapid blockchain monitoring can be critical following a crypto theft.
Investigators can identify stolen assets while they are still moving through centralized services, potentially allowing exchanges to intervene before the funds are converted or transferred into harder-to-trace assets.
Coinsbuy Temporarily Suspended Transactions
Following the incident, Coinsbuy reportedly paused deposits and withdrawals.
Services were later reported to have resumed several hours afterward.
However, the restoration of services does not necessarily mean the investigation has been completed or that all affected funds have been recovered.
It also remains unclear whether the reported $7.9 million consisted entirely of Coinsbuy’s own assets, customer funds or a combination of both.
The company has not publicly provided a detailed breakdown of potential customer exposure or announced a reimbursement plan.
Another Major Crypto Security Incident
The Coinsbuy incident adds to an already active year for cryptocurrency security breaches.
TRM Labs recorded 207 crypto hacks during the first half of 2026, with approximately $972 million in stolen assets during that period.
The continued frequency of attacks highlights a persistent weakness across the digital-asset industry: even when blockchain networks themselves remain secure, centralized wallets, administrative systems, private keys and operational infrastructure can become major attack vectors.
What Happens Next?
The most important next development will likely be a formal incident report from Coinsbuy.
Such a report could clarify:
- How the attacker gained access
- Which wallets and assets were affected
- Whether customer funds were involved
- The final amount stolen
- How much was frozen or recovered
- Whether Coinsbuy has changed its security architecture
Investigators will also continue monitoring the Ethereum and TRON addresses associated with the theft.
The reported movement toward Monero could make subsequent tracing more difficult, particularly once funds leave transparent blockchain networks.
For now, the confirmed public picture remains limited: Coinsbuy-linked wallets were reportedly drained of approximately $7.9 million, portions of the funds moved through several exchange services, and at least some proceeds may have been frozen.
The exact cause of the breach and the final scale of customer exposure remain unresolved.

