More than $7.9 million was drained from wallets linked to crypto-payments platform Coinsbuy across Ethereum and TRON on Aug. 9, 2026, according to blockchain investigator Specter and security firm PeckShield.
The attacker subsequently moved portions of the stolen assets through exchanges and into Monero (XMR), while Coinsbuy temporarily suspended deposits and withdrawals as it responded to the incident. A six-figure portion of the funds was reportedly frozen with assistance from crypto exchange ChangeNOW.
The incident places the Coinsbuy hack among a growing series of major cryptocurrency security breaches reported in 2026. Recent attacks have continued to demonstrate how quickly stolen digital assets can be transferred across networks, converted through exchanges and routed into privacy-focused cryptocurrencies, complicating recovery efforts.
Coinsbuy operates as a crypto-processing infrastructure provider for businesses, merchants and exchange clients, offering services for receiving, storing, sending, exchanging and accepting digital assets. Its official website says the platform supports security measures including two-factor authentication, address whitelists, access controls, withdrawal approvals and blockchain risk scoring.
Coinsbuy hack hits Ethereum and TRON wallets
The Coinsbuy hack was first flagged through on-chain monitoring after wallets associated with the platform recorded unusual outflows. Reports citing blockchain investigator Specter indicate that the suspicious activity began around 13:00 UTC on Aug. 9, with assets drained across Ethereum and TRON.
More than $7.9 million worth of cryptocurrency was reportedly taken. The precise attack vector has not been publicly established, and there is no detailed technical postmortem from Coinsbuy identifying whether the incident resulted from compromised private keys, an infrastructure vulnerability, credential theft or another form of unauthorized access.
The cross-chain nature of the activity has nevertheless drawn attention. Wallets associated with Coinsbuy were reportedly affected on both Ethereum and TRON, raising questions about how the attacker obtained access to assets operating across separate blockchain environments.
Blockchain monitoring was critical to identifying the transactions because movements on public networks can be observed and followed even after an attacker gains control of funds.
The incident also highlights a limitation of on-chain transparency: while transactions can be visible, tracing does not necessarily mean recovering the assets.
Coinsbuy hack sees stolen funds routed toward Monero
Following the reported theft, the attacker moved quickly to obscure the trail of the stolen assets.
Reports indicate that portions of the cryptocurrency were transferred through exchanges and converted into Monero, a privacy-focused digital asset designed to provide stronger transaction privacy than transparent blockchains such as Ethereum.
The movement toward Monero potentially complicates blockchain-based tracing because investigators can no longer follow transactions through a transparent public ledger in the same way they can with Ethereum or TRON.
That made the speed of the response particularly important. Coinsbuy reportedly worked with ChangeNOW, which helped freeze a six-figure portion of the stolen assets. The amount represents only a fraction of the more than $7.9 million reported stolen, leaving the status of most of the funds unresolved.
Coinsbuy’s response is consistent with security procedures outlined in its own documentation. The company instructs users who suspect an account compromise to change passwords, revoke access permissions and restrict API access before contacting the company.
“Immediately inform your account manager,” — Coinsbuy, in its security guidance for suspected account compromises.
The company also says its systems use multiple layers of protection, including two-factor authentication, access lists, withdrawal approvals and wallet thresholds.
Coinsbuy hack prompts temporary service suspension
In response to the Coinsbuy hack, deposits and withdrawals were reportedly suspended temporarily while the platform assessed the situation. Reports indicate that the services were subsequently restored.
The temporary suspension limited the immediate movement of funds through the platform while investigators and security teams assessed the affected wallets.
Coinsbuy’s published terms acknowledge the possibility of cyberattacks and unauthorized intrusions despite its security measures.
“While we take all reasonable efforts to maintain the integrity and security of the Coinsbuy solution, no system is immune to evolving threats,” — Coinsbuy, in its terms and conditions.
The company’s documentation also says security events can trigger measures including account restrictions, credential resets and API-key revocation when unauthorized activity is suspected.
The platform’s official documentation describes Coinsbuy as a crypto-processing solution that allows businesses to accept, store, send and exchange digital assets. Its security architecture includes 2FA, address whitelisting, role-based access, withdrawal approval mechanisms and AML checks.
Those controls will likely come under scrutiny following the Coinsbuy hack, particularly if investigators determine that access to wallet keys or administrative systems was compromised.
Coinsbuy hack adds to 2026 crypto security concerns
The Coinsbuy hack comes during a year in which cryptocurrency platforms have faced repeated high-value attacks.
Earlier in August, hackers were reported to have stolen more than $100 million in Bitcoin from thousands of wallets affected by a vulnerability involving Coldcard hardware-wallet firmware, according to reporting based on research from Galaxy Research and other security firms. TRM Labs data cited by TechCrunch indicated that more than 200 hacks had targeted cryptocurrency companies during 2026, with losses exceeding $950 million at the time of that report.
The figures illustrate the broader challenge facing crypto infrastructure providers: security threats increasingly involve not only smart-contract vulnerabilities but also wallet management, private-key protection, authentication systems and operational infrastructure.
For Coinsbuy, the immediate priority is determining how the affected wallets were compromised and whether any additional wallets or customer assets remain exposed.
The Coinsbuy hack has so far produced no publicly disclosed technical explanation identifying the precise vulnerability or attacker. Nor has the company publicly detailed the full amount recovered beyond reports of a six-figure freeze involving ChangeNOW.
The Coinsbuy hack therefore remains a developing security incident rather than a fully explained breach. On-chain investigators continue to track the stolen assets, while the platform has resumed services following its temporary suspension.
The Coinsbuy hack also demonstrates the increasingly narrow window available to crypto platforms after a breach: attackers can move assets across multiple blockchains within minutes, while exchanges and blockchain investigators must identify and freeze funds before they disappear into harder-to-trace channels.
For now, the Coinsbuy hack has left more than $7.9 million in reported losses, a portion of which has been frozen, while the whereabouts of the remaining assets and the precise method used to compromise the wallets remain under investigation.