Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Business

Coinsbuy Was Drained on Two Chains at Once and the Trail Ends in Monero

PeckShield traced the $7.9 million through ChangeNOW, FixedFloat and BingX before conversions into Monero closed the paper trail. ChangeNOW froze a six-figure amount.

By Jessica Miles··3 min read
Coinsbuy Was Drained on Two Chains at Once and the Trail Ends in Monero

Key Points

  • PeckShield traced the $7.9 million through ChangeNOW, FixedFloat and BingX before conversions into Monero closed the paper trail.
  • ChangeNOW froze a six-figure amount.

Wallets linked to crypto payment processor Coinsbuy were drained of more than $7.9 million on Sunday, in a coordinated attack that hit addresses on Ethereum and TRON almost simultaneously around 13:00 UTC. On-chain investigator SpecterAnalyst flagged the outflows on Telegram before the platform paused deposits and withdrawals.

Coinsbuy runs business-facing payment processing, wallet infrastructure and digital asset management for merchants and exchanges. Its own release notes, last updated on July 31, carried no incident notice as of Monday morning. The company later restored deposits and withdrawals, according to Specter's follow-up posts. What has not been disclosed is whether the $7.9 million comprised company funds, client balances, or a mixture; no customer loss breakdown or reimbursement plan has appeared in Coinsbuy's public documentation.

Advertisement

728×90

The attack's cross-chain shape gives investigators their strongest lead. Coordinated outflows on Ethereum and TRON in the same minute point to compromised access capable of signing on both networks — either hot-wallet private keys, elevated administrator credentials, or a lower-level infrastructure breach. GoPlus Security called the pattern consistent with hot wallet private key or administrator privilege theft, but stressed that the assessment is not a confirmed root cause. Coinsbuy has not published a technical postmortem. Specter identified two Ethereum addresses and one TRON address as the theft destinations; those wallets are the sole verified anchor investigators have while the rest of the picture stays speculative.

PeckShield traced part of the stolen funds through instant-exchange services ChangeNOW, FixedFloat and BingX before the attacker began converting proceeds into Monero. That routing is now a template. It resembles the laundering pattern from January's hardware wallet theft that moved bitcoin and litecoin through the same corridor into XMR, and echoes the three-bridge sweep in July that took $35 million in six hours before most of it dispersed. Monero remains the exit that on-chain investigators cannot follow once conversion completes.

ChangeNOW appears to have moved fastest. Specter said the exchange helped freeze a six-figure amount before it could move further, though ChangeNOW has not issued its own statement confirming the exact sum in the sources reviewed. A six-figure freeze against a $7.9 million loss is a meaningful signal that some exchange-level intervention still works, and a reminder of how little of the total that recovery represents. The vast majority of the drained funds remain outstanding.

Coinsbuy is not a household name, but its infrastructure sits behind other companies. B2B crypto payment processors are the pipe merchants trust to hold funds between transactions. When one of them loses $7.9 million from what looks like operational key exposure, every merchant relying on the same architecture has to ask whether its own custody assumptions still hold. Coinsbuy's own communication so far has consisted of a service pause and a service restoration, with no incident report attached. That is a thin response for a business whose product is trust.

The case adds to a security year that was already the worst on record. TRM Labs recorded 207 hacks and roughly $972 million stolen in the first half of 2026, with infrastructure and operational failures accounting for most of the loss rather than smart-contract logic bugs. That total does not yet include the last-six-weeks run: Humanity Protocol's $36 million multisig-key breach traced back to an employee laptop backup, the Coldcard random-number-generation flaw now past 1,367 bitcoin drained, and Sunday's Coinsbuy sweep. The composition matters: fewer clever exploits, more compromised keys and misconfigured infrastructure. That points at operator practice as the failure mode, not the primitives underneath.

What comes next is a Coinsbuy incident report, if one arrives, identifying the vector, the affected assets, and the customer exposure. Confirmation from ChangeNOW, FixedFloat, or BingX would clarify how much was frozen and whether more remains recoverable. Until then, the verified picture is limited: three attacker addresses, a $7.9 million loss, a partial freeze, and funds converting into a currency built to be untraceable.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

NEAR Intents Says an Omni Bridge Bug Cost It About $3.8 Million
Markets

The protocol halted services, patched the contract-side flaw and promised to compensate users in full, naming eleven networks whose deposits and withdrawals would stay down for another 12 hours. Investigators who traced the outflows do not agree on where the money went.

·MiningPool Staff
Cboe's 25-Year S&P 500 Options Deal Mentions Tokenized Contracts
Business

The extension gives Cboe the exclusive license to list S&P 500 index options through 2051, a franchise the companies say traded 970.6 million contracts last year. A single permissive sentence adds that the two may also pursue new products like tokenized options, with no product, venue, timetable or filing attached.

·MiningPool Staff
Strategy Put Daily Preferred Dividends to a Shareholder Vote
Business

Total dividends would not change, but STRC's record dates would go from 24 a year to 365 and the other three series from four to 365. Proposal 1 needs a majority of all outstanding common voting power, and the proxy puts Michael Saylor's share of it at 32.9%.

·MiningPool Staff
Buterin Expects Hegotá to Be Ethereum's Last Normal Fork
Tech

Buterin's post puts Ethereum's 2030 target at four to eight second slots and finality in eight to 32 seconds, against 12-second slots and about 13 minutes today. It also has nodes checking a proof instead of re-executing every block.

·MiningPool Staff
Kelp's Developer Is Suing LayerZero Over Advice It Says It Followed
Business

Evercrest Technologies filed in the Supreme Court of British Columbia, alleging LayerZero approved its single-verifier bridge configuration in writing and warned another integrator about the same risk without warning Kelp. The claim adds a defamation count over LayerZero's post-exploit statements and seeks Evercrest's own losses rather than the full $292 million.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.