PeckShield traced the $7.9 million through ChangeNOW, FixedFloat and BingX before conversions into Monero closed the paper trail. ChangeNOW froze a six-figure amount.
Wallets linked to crypto payment processor Coinsbuy were drained of more than $7.9 million on Sunday, in a coordinated attack that hit addresses on Ethereum and TRON almost simultaneously around 13:00 UTC. On-chain investigator SpecterAnalyst flagged the outflows on Telegram before the platform paused deposits and withdrawals.
Coinsbuy runs business-facing payment processing, wallet infrastructure and digital asset management for merchants and exchanges. Its own release notes, last updated on July 31, carried no incident notice as of Monday morning. The company later restored deposits and withdrawals, according to Specter's follow-up posts. What has not been disclosed is whether the $7.9 million comprised company funds, client balances, or a mixture; no customer loss breakdown or reimbursement plan has appeared in Coinsbuy's public documentation.
The attack's cross-chain shape gives investigators their strongest lead. Coordinated outflows on Ethereum and TRON in the same minute point to compromised access capable of signing on both networks — either hot-wallet private keys, elevated administrator credentials, or a lower-level infrastructure breach. GoPlus Security called the pattern consistent with hot wallet private key or administrator privilege theft, but stressed that the assessment is not a confirmed root cause. Coinsbuy has not published a technical postmortem. Specter identified two Ethereum addresses and one TRON address as the theft destinations; those wallets are the sole verified anchor investigators have while the rest of the picture stays speculative.
PeckShield traced part of the stolen funds through instant-exchange services ChangeNOW, FixedFloat and BingX before the attacker began converting proceeds into Monero. That routing is now a template. It resembles the laundering pattern from January's hardware wallet theft that moved bitcoin and litecoin through the same corridor into XMR, and echoes the three-bridge sweep in July that took $35 million in six hours before most of it dispersed. Monero remains the exit that on-chain investigators cannot follow once conversion completes.
ChangeNOW appears to have moved fastest. Specter said the exchange helped freeze a six-figure amount before it could move further, though ChangeNOW has not issued its own statement confirming the exact sum in the sources reviewed. A six-figure freeze against a $7.9 million loss is a meaningful signal that some exchange-level intervention still works, and a reminder of how little of the total that recovery represents. The vast majority of the drained funds remain outstanding.
Coinsbuy is not a household name, but its infrastructure sits behind other companies. B2B crypto payment processors are the pipe merchants trust to hold funds between transactions. When one of them loses $7.9 million from what looks like operational key exposure, every merchant relying on the same architecture has to ask whether its own custody assumptions still hold. Coinsbuy's own communication so far has consisted of a service pause and a service restoration, with no incident report attached. That is a thin response for a business whose product is trust.
The case adds to a security year that was already the worst on record. TRM Labs recorded 207 hacks and roughly $972 million stolen in the first half of 2026, with infrastructure and operational failures accounting for most of the loss rather than smart-contract logic bugs. That total does not yet include the last-six-weeks run: Humanity Protocol's $36 million multisig-key breach traced back to an employee laptop backup, the Coldcard random-number-generation flaw now past 1,367 bitcoin drained, and Sunday's Coinsbuy sweep. The composition matters: fewer clever exploits, more compromised keys and misconfigured infrastructure. That points at operator practice as the failure mode, not the primitives underneath.
What comes next is a Coinsbuy incident report, if one arrives, identifying the vector, the affected assets, and the customer exposure. Confirmation from ChangeNOW, FixedFloat, or BingX would clarify how much was frozen and whether more remains recoverable. Until then, the verified picture is limited: three attacker addresses, a $7.9 million loss, a partial freeze, and funds converting into a currency built to be untraceable.