Cryptocurrency payment processor Coinsbuy suffered a significant security breach on August 9, 2026, resulting in the loss of over $7.9 million across wallets on the Ethereum and TRON networks. The incident, which occurred around 13:00 UTC, was first flagged by blockchain investigator Specter and later confirmed by multiple security firms including PeckShield, CertiK, and GoPlus.
According to PeckShield, two Ethereum addresses and one TRON address were identified as destinations for the stolen funds. The exact attack vector remains unconfirmed, but GoPlus Security noted that the activity was "consistent with hot wallet private key or administrator privilege theft." Coinsbuy has not yet released a technical postmortem; its last publicly documented software release dates to July 31.
After the drain, the attacker began routing part of the stolen proceeds through exchange services ChangeNOW, FixedFloat, and BingX. Specter reported that the funds were being converted toward the privacy-focused cryptocurrency Monero, a move designed to obscure on-chain tracing. PeckShield traced similar laundering patterns, and CertiK independently relayed the same estimated loss and exchange routes.
In a partial win for investigators, ChangeNOW managed to freeze a six-figure amount before it could move further, according to Specter. The exact frozen sum has not been officially confirmed by ChangeNOW, but the freeze prevented a portion of the assets from disappearing into Monero's opaque ledger.
Coinsbuy temporarily paused deposits and withdrawals following the breach, later restoring services according to reports citing Specter. However, the company has not clarified whether the $7.9 million drain consisted of company-owned assets, client funds, or a combination of both. No customer loss breakdown or reimbursement plan has been made public.
The incident adds to a growing list of crypto security lapses this year. TRM Labs recorded 207 hacks totaling approximately $972 million in stolen value during the first half of 2026, with infrastructure and operational failures accounting for most losses. The attacker’s use of cross-chain movement and Monero laundering mirrors tactics seen in other major thefts, including the January wallet theft where Bitcoin and Litecoin were converted into Monero.
The next critical steps will be a formal incident report from Coinsbuy detailing the attack vector, final loss, and user exposure, as well as any further recoveries by exchanges. Security researchers continue to monitor the identified Ethereum and TRON addresses, though the trail into Monero will make full recovery challenging.