Just days after the Coldcard wallet crisis, crypto security is back in the headlines. Wallets linked to crypto payment processor Coinsbuy were drained of more than $7.9 million across the Ethereum and TRON networks on August 9, 2026 β and the attacker moved fast to launder the funds into Monero before they could be fully traced.
β‘ How It Unfolded
| Detail | Info |
|---|---|
| Time of attack | ~13:00 UTC, August 9, 2026 |
| Networks affected | Ethereum and TRON (simultaneously) |
| Amount stolen | $7.9 million+ |
| First detected by | Blockchain monitoring firm Specter |
| Independently confirmed by | PeckShield |
| Amount recovered | A six-figure sum, frozen via ChangeNOW |
π What We Know (and Don’t)
The simultaneous drain across two separate blockchains is the most telling detail β it suggests the attacker had access to multiple systems or private keys tied to Coinsbuy’s infrastructure, rather than exploiting a single-chain vulnerability. Security firm GoPlus said the activity is “consistent with hot wallet private key or administrator privilege theft,” though this remains an assessment rather than a confirmed root cause. Coinsbuy has not published a technical postmortem, and it’s unclear whether the stolen funds belonged to the company or to customers.
π The Monero Laundering Trail
After the initial drain, the attacker routed stolen assets through exchanges β including ChangeNOW, FixedFloat, and BingX β converting portions into Monero (XMR), a privacy coin designed to resist blockchain tracing. ChangeNOW managed to freeze a six-figure portion mid-transfer, but that represents only a small fraction of the total haul; the majority of the $7.9 million appears to have moved beyond immediate recovery.
π οΈ Coinsbuy’s Response
Coinsbuy temporarily suspended deposits and withdrawals across its platform following the incident, restoring both services later the same day. As of publication, the company had not released a detailed incident statement or reimbursement plan.
π― Why This Matters
Coming right on the heels of the Coldcard hardware wallet hack, this incident underscores that crypto’s security challenges span the entire stack β from consumer-facing hardware wallets to backend payment infrastructure. For businesses using crypto payment processors, it’s a reminder to scrutinize how providers manage hot wallet keys and administrator access.
Disclaimer: This article is for informational purposes only and does not constitute security or investment advice. Details of this incident remain under investigation and may be updated as more information becomes available.
]]>








Leave a Reply