Enterprise crypto payment processor Coinsbuy lost more than $7.9 million when wallets on Ethereum and TRON were drained on Aug. 9. The attacker converted stolen assets into Monero to obscure the trail, with only a six-figure portion frozen so far.
Enterprise crypto payment processor Coinsbuy lost more than $7.9 million when wallets on Ethereum and TRON were drained on Aug. 9. The attacker converted stolen assets into Monero to obscure the trail, with only a six-figure portion frozen so far.

Coinsbuy lost more than $7.9 million on Aug. 9 when wallets on Ethereum and TRON were drained in its first publicly known hack since 2019.
On-chain monitoring firm Specter flagged the suspicious outflows, identifying two Ethereum wallets and one TRON wallet that received the bulk of the stolen funds, according to data shared by the firm.
The attacker routed portions of the stolen crypto through exchanges and converted them into Monero (XMR), whose shielded ledger resists blockchain forensics. Coinsbuy partnered with non-custodial exchange ChangeNOW to freeze a six-figure sum before full liquidation. The platform temporarily suspended deposits and withdrawals, restoring services shortly after.
The breach shows how quickly attackers can launder stolen crypto once privacy coins enter the picture. Specter and its partners continue tracing the remaining funds, though the Monero conversion may close the recovery window within hours.
The attack unfolded around 13:00 UTC (21:00 Beijing time) on Aug. 9, with funds systematically drained across both networks simultaneously, suggesting either compromised private keys or a vulnerability in Coinsbuy's multi-chain wallet infrastructure. The identified theft addresses include two Ethereum wallets and one TRON wallet.
Coinsbuy operates as a digital asset processing platform for enterprise and merchant clients rather than retail traders. The platform has operated in this space since roughly 2019, largely flying under the radar of the broader crypto community. The breach marks the first publicly known security incident for the platform.
Current investigations suggest the breach was an isolated incident rather than evidence of a deeper systemic vulnerability within Coinsbuy's infrastructure. The platform has not yet issued a detailed public breakdown of what caused the suspected wallet compromise or what security changes have been made since.
According to Specter's Telegram post, the monitoring firm tracked the fund movements in near real time as the attacker moved assets through intermediary exchanges before the Monero conversion. This kind of rapid on-chain surveillance is increasingly central to crypto incident response, since laundering routes through privacy coins can close a recovery window within hours.
Whether more of the $7.9 million can be recovered will depend on how quickly cooperating platforms can flag and freeze suspicious deposits. The incident highlights the growing risk facing enterprise crypto payment platforms, which hold significant assets across multiple chains and may lack the security infrastructure of larger exchanges. As privacy coins like Monero become more common in laundering routes, the window for fund recovery continues to narrow. Cross-platform cooperation between monitoring firms and exchanges has become a key tool in limiting damage from crypto hacks, even when full recovery isn't possible.
This article is for informational purposes only and does not constitute investment advice.