Coinsbuy Wallets Drained of $7.9 Million Across Ethereum and TRON, Stolen Funds Converted to Monero
Key Takeaways
- •Coinsbuy-linked wallets suffered losses exceeding $7.9 million in a cross-chain drain spanning Ethereum and TRON networks on August 9.
- •The stolen assets were routed through several exchange services and partially converted into Monero, making public tracing significantly more difficult.
- •ChangeNOW froze a six-figure sum before all tracked funds could exit its platform, representing the only publicly disclosed recovery action so far.
- •The Coinsbuy incident follows a separate $9.7 million drain from Triple-A-linked wallets, though no evidence currently connects the two attacks.
- •Cryptocurrency theft activity has surged, with July seeing 30 major hacks removing $210.3 million, a 177.2% increase from the previous month.

Wallets linked to cryptocurrency payments provider Coinsbuy suffered losses exceeding $7.9 million in a cross-chain drain spanning Ethereum and TRON, with the stolen assets subsequently routed through multiple exchange services and partially converted into Monero (XMR).
Onchain investigator Specter identified the suspicious outflows at approximately 13:00 UTC on August 9. In response to the incident, Coinsbuy temporarily suspended both deposits and withdrawals before later restoring full service.
The attack vector has not been publicly identified. Available evidence indicates that the incident involved compromised Coinsbuy-linked wallets rather than any vulnerability in the Ethereum or TRON networks themselves. Routing stolen assets across multiple blockchains complicates recovery, as each network operates under different tracing tools, bridge mechanics, and transaction finality rules.
Stolen Funds Routed Through Exchanges Into Monero
The stolen assets were moved from the affected wallets through several exchange services, with the operator converting a portion of the proceeds into XMR. ChangeNOW, FixedFloat, and BingX were among the platforms identified along the transaction path.
Monero's privacy architecture obscures transaction amounts, sender addresses, and recipients once funds enter the network, making public tracing substantially more difficult after an exchange completes an XMR conversion. This laundering pattern — moving through multiple swap services before reaching a privacy coin — has become a recurring feature in large-scale cryptocurrency thefts, reducing the window in which exchanges can freeze funds before they disappear from public view.
ChangeNOW intervened before all tracked assets could leave its platform, freezing an amount described only as six figures. Coinsbuy has not disclosed the precise recovered balance or how much of the $7.9 million remains traceable.
Coinsbuy's platform provides cryptocurrency payment processing and wallet infrastructure to merchants, exchanges, and other businesses, offering custody, deposits, and automated withdrawals across multiple blockchains. For payment processors serving as intermediaries for merchant settlement and payouts, wallet compromises carry operational risk beyond the immediate loss, as clients depend on continuous transaction availability.
Cross-Chain Drain Follows Triple-A Theft
The Coinsbuy incident comes shortly after a separate $9.7 million drain from Triple-A-linked wallets, which Specter traced across TRON, Ethereum, Polygon, and Arbitrum. In that case, funds were bridged and consolidated into ETH before part of the balance moved through privacy infrastructure.
Both incidents involved funds leaving wallets associated with cryptocurrency payments companies across multiple networks. No evidence currently connects the two attacks or establishes a shared compromise method.
The losses continue a broader trend of elevated cryptocurrency theft. In July, 30 major hacks removed $210.3 million — a 177.2% increase from June.
Coldcard Losses Add to Security Pressure
Wallet security has remained under intense scrutiny following Coldcard-linked Bitcoin thefts that expanded to as much as $132 million. Galaxy Research identified at least 15 suspected attackers targeting seed phrases generated with vulnerable Coldcard firmware, with thousands of addresses implicated in the wider drain.
The Coinsbuy case differs in that no seed-generation, smart-contract, or software vulnerability has been identified. The company's immediate operational disruption has ended, with deposits and withdrawals fully restored.
ChangeNOW's freeze remains the only publicly disclosed recovery action, while the total identified loss stands above $7.9 million. Whether Coinsbuy discloses further detail on the scope of compromised funds, the amount recovered, or any client impact remains an open question for affected merchants and partners.