Coinsbuy's crypto wallets were drained of $8.07 million in a coordinated attack spanning Ethereum and TRON on August 9, with the company covering all losses from its own reserves.

The attack targeted 11 wallets linked through Bridgers, a cross-chain swapper platform: eight on TRON and three on Ethereum. Security firm PeckShield and blockchain investigator Specter Investigations tracked the incident, which occurred around 13:00 UTC. Coinsbuy confirmed the breach and said it would absorb the full loss without affecting customer funds.

Across total value locked, last 90 days
Across total value locked, last 90 days · MSB Intel data desk

Cross-chain attacks have grown more frequent as bridges connecting separate blockchains proliferate. Bridgers allows users to swap tokens across networks, creating potential attack surface. The August 9 incident differed from prior breaches: rather than targeting the bridge protocol itself, attackers compromised the wallet infrastructure of a single platform and used Bridgers as a vector to move stolen funds simultaneously across two chains.

MSB Intel

Coinsbuy is a mid-sized crypto exchange platform. The company's decision to cover losses from reserves rather than seek recovery or insurance is common after public breaches. Absorbing the cost avoids the extended disclosure and regulatory scrutiny that can follow formal insurance claims or user compensation processes.

Wallet drains tied to cross-chain infrastructure have cost the ecosystem more than $1.4 billion since 2021, according to on-chain analysis. Most have targeted bridge protocols directly. This attack used a wallet provider and cross-chain swapper as the exploit vector, targeting operational security rather than bridge code vulnerabilities.

Coinsbuy has not disclosed whether the breach resulted from compromised private keys, insider access, or a vulnerability in how Bridgers integrates with its wallet systems. The company said it is conducting a full security audit and has suspended cross-chain transactions pending review.

The attack executed across two separate blockchains in a single coordinated action. Single-blockchain wallet drains typically occur through phishing or malware. Simultaneous execution across chains required prior access to wallet signing infrastructure or identification of a flaw in how Bridgers routes transactions before the transfers began.