Crypto exchange Coinsbuy suffered a $7.9 million loss in a coordinated attack spanning Ethereum and TRON blockchains on August 9, according to on-chain security monitors PeckShield, CertiK, and Specter. The incident was first detected around 13:00 UTC.
Funds were drained from multiple wallets across both chains in the same window. Coinsbuy's services resumed after a six-figure sum was frozen through the ChangeNOW platform, a bridge service used to intercept stolen funds in real time.
The attack vector remains unconfirmed. GoPlus identified the compromise as originating from a hot-wallet key or admin credential breach, but Coinsbuy has not issued an official statement detailing the incident or its cause. The exchange's own disclosure or technical postmortem would clarify whether the attack exploited a protocol flaw, operational weakness, or external access to internal systems.

Coinsbuy is a peer-to-peer and merchant exchange operating primarily in Southeast Asia. The exchange handles fiat on-ramps and off-ramps for retail users and merchants in that region. A loss of this scale represents a material hit to a mid-tier regional operator.
Coordinated multi-chain attacks have increased in frequency since 2023 as attackers target exchanges running parallel hot-wallet infrastructure to maximize extraction in a single coordinated window. The speed of the freeze via ChangeNOW's anti-theft protocol recovered roughly 7-8 percent of the stolen amount in real time, a recovery rate consistent with recent major exchange incidents where bridge providers intercept cross-chain transfers within minutes of detection.
Coinsbuy's resumption of services within hours of the incident indicates the breach did not compromise its broader infrastructure or customer deposit systems, only the specific hot wallets used for liquidity. The absence of a statement from the exchange leaves open questions about whether the incident affected customer funds or only operational reserves.