Just days after the Coldcard wallet crisis, crypto security is back in the headlines. Wallets linked to crypto payment processor Coinsbuy were drained of more than $7.9 million across the Ethereum and TRON networks on August 9, 2026 — with the attacker moving fast to launder the funds into Monero.
⚡ How It Unfolded
| Detail | Info |
|---|---|
| Time of attack | ~13:00 UTC, August 9, 2026 |
| Networks affected | Ethereum and TRON (simultaneously) |
| Amount stolen | $7.9 million+ |
| First detected by | Blockchain monitor Specter; confirmed by PeckShield |
| Amount recovered | A six-figure sum, frozen via ChangeNOW |
🔍 What We Know
The simultaneous drain across two blockchains suggests the attacker had access to multiple systems or private keys tied to Coinsbuy’s infrastructure. Security firm GoPlus said the activity is “consistent with hot wallet private key or administrator privilege theft,” though this remains an assessment, not a confirmed root cause.
🌀 The Laundering Trail
After the drain, the attacker routed funds through exchanges including ChangeNOW, FixedFloat, and BingX, converting portions into Monero — a privacy coin designed to resist blockchain tracing. Coinsbuy temporarily suspended deposits and withdrawals, restoring both services the same day, but has not published a detailed incident statement.
🎯 Why This Matters
Coming right after the Coldcard hardware wallet hack, this is a reminder that crypto’s security risk spans the entire stack — from consumer hardware wallets to backend payment infrastructure.
Disclaimer: This article is for informational purposes only and does not constitute security or investment advice. Details remain under investigation.
]]>
